“Audit every customer's firewall firmware version today and prioritize patching Fortinet and Palo Alto boxes before end of business.”
Microsoft 365 West US Azure Outage Resolved — SharePoint, OneDrive, Teams Hit (July 23)
Starting at approximately 14:44 UTC on 23 July 2026, customers experienced intermittent connectivity failures, increased latency, and difficulty accessing Azure services in the West US region. SharePoint accounted for 78% of complaints, with OneDrive access intermittent and Teams showing degraded chat functionality including images not loading. The outage was resolved by the evening of July 23; admins should review incident MO1437424 in the Microsoft 365 Admin Center for post-incident details.
Read more →Windows 11 July 28 Preview Update KB5101684 — No CVEs But Critical Preview for August Patch Tuesday
Microsoft's July 28, 2026 preview update (KB5101684) carries 42 fixes but zero CVEs, meaning nothing is immediately urgent. However, one fix corrects a bug where internal file shares were incorrectly treated as downloaded from the internet (a MotW/zone-identifier issue), which is relevant to organisations managing shared drives. MSPs should review KB5101684 now as it provides a four-week preview of changes that become mandatory in the 11 August security update.
Read more →CVE-2026-58052: 7-Zip MotW/SmartScreen Bypass Under Active Exploitation in the Wild
CVE-2026-58052 affects 7-Zip for Windows through version 26.01, allowing an attacker to defeat SmartScreen/Mark-of-the-Web warnings and spoof file content — a classic initial-access primitive. Empirical Security's telemetry shows confirmed in-the-wild exploitation as recently as 25 July 2026, placing it in the 98th percentile of all scored CVEs despite low EPSS scores. Workaround: update 7-Zip to the latest release; note that 7-Zip publishes fixes in release notes rather than formal advisories, so it is likely outside standard patch-management scope for many clients.
Read more →Fortinet Leads 2026 Firewall CVE Count — 8+ Unauthenticated Vulns, Several Under Active Exploitation
A mid-2026 analysis of vendor advisories and CISA KEV entries confirms Fortinet has disclosed the most unauthenticated vulnerabilities of any firewall vendor in 2026, with eight or more across its portfolio including a January 2026 FortiCloud authentication bypass (CISA KEV added 28 January) affecting FortiGate, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb. Patches are available in FortiOS 7.4.11 and later. MSPs managing Fortinet estates should audit firmware versions immediately; over 10,000 vulnerable Fortinet instances remain internet-exposed according to Shadowserver scans.
Read more →Cisco & Palo Alto Exploited Before Defenders in 2026 — Patched Firewalls Not Necessarily Clean
A mid-2026 analysis of firewall vendor CVE disclosures found that both Cisco and Palo Alto Networks had flaws discovered by attackers before defenders this cycle, and Cisco devices demonstrated persistence of attacker footholds even after patching. Palo Alto had the most dangerous exploited flaws within the firewall OS itself across 2026 advisories. MSPs managing these platforms should perform post-patch compromise assessments, not just apply updates.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.