“Immediately identify which clients run SonicWall SMA 1000, Fortinet firewalls, or ADFS, then prioritize patching or workarounds for those three before end of business.”
Windows 11 KB5101684 July 28 Preview: No CVEs But Fixes Internal File Share Internet-Zone Bug
Microsoft's July 28 preview update (KB5101684) carries no security vulnerabilities but includes a notable fix that stopped internal file shares from being incorrectly treated as downloaded from the Internet, which could affect line-of-business applications. This preview is a four-week early warning of what becomes mandatory in the August 11 security update. MSPs should review and test the fix in lab environments ahead of the August Patch Tuesday rollout.
Read more →CVE-2026-56155: ADFS Elevation of Privilege Actively Exploited in the Wild
The only Windows vulnerability from July 2026 Patch Tuesday already confirmed as exploited in the wild is CVE-2026-56155, a high-risk Elevation of Privilege flaw in Active Directory Federation Services (ADFS) that allows an attacker to gain administrator rights. Affected versions include Windows Server 2012 through 2025 and older Windows 10 builds (1607 and 1809). Workaround: Apply July 2026 Patch Tuesday updates immediately; review ADFS exposure and consider temporarily limiting external ADFS endpoints.
Read more →SonicWall SMA 1000 Zero-Days CVE-2026-15409 & CVE-2026-15410 Actively Exploited
SonicWall published a security advisory on July 14, 2026, detailing two critical zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) in the SMA 1000 Series remote access appliances, with exploitation confirmed in the wild. These vulnerabilities allow remote unauthenticated attackers to compromise the appliance and are described as a severe risk for organisations using legacy SMA 1000 hardware. Workaround: Apply SonicWall's patches immediately; consider disabling internet-facing SMA 1000 management interfaces until patched.
Read more →Fortinet Leads 2026 Firewall Vulnerability Count With 8+ Unauthenticated CVEs — Several Actively Exploited
Fortinet has disclosed the highest number of unauthenticated vulnerabilities of any firewall vendor in 2026, with eight or more across its portfolio and a notable 27-CVE advisory wave in April. Several of these flaws are under active exploitation, and a FortiOS patch bypass for a symbolic link persistence mechanism has been added to the CISA KEV catalog. Workaround: MSPs managing Fortinet devices should review FortiGuard PSIRT advisories and apply all available firmware updates; treat any unauthenticated internet-facing Fortinet CVE as a same-week emergency.
Read more →Microsoft AI-Assisted Vulnerability Discovery Driving Record Patch Volumes — 751 CVEs in July Alone
Microsoft's internal adoption of AI for vulnerability discovery is directly contributing to the record-breaking patch volumes seen in mid-2026, with July 2026 shipping 751 CVEs and the prior month also setting a record. Industry analysts note this trend is expected to continue, raising questions about whether traditional CVE tracking and monthly patch cadences remain practical at this scale. MSPs should review their patch prioritisation frameworks and consider risk-based approaches focused on KEV-confirmed exploitation rather than raw CVE counts.
Read more →2026 Australian Census Scheduled for 11 August — MSPs Supporting ABS or Government Clients Should Prepare
The 2026 Australian Census is scheduled to take place on 11 August 2026, conducted by the Australian Bureau of Statistics, representing a major national data collection event. MSPs with government, public sector, or ABS-adjacent clients should be aware of potential elevated network and service demands around this date. Ensure any planned maintenance or patching windows do not conflict with Census night operations.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.