“Inventory every Fortinet device in your portfolio today and confirm patch status for CVE-2024-55591 and CVE-2025-24472 before touching anything else.”
Microsoft 365 Patch Tuesday Fixes 98 Office CVEs and 30 SharePoint Vulns — Broad Enterprise Exposure
The August 2026 Patch Tuesday security updates resolve 98 vulnerabilities across Office/Office 2016 and 30 in SharePoint Server, reflecting the same underlying flaws delivered through two different servicing models — meaning both current Office and legacy Office 2016 deployments require attention. SharePoint and Exchange fixes carry outsized risk given their network-facing nature, with SharePoint accounting for a large patch surface this month. Validate and deploy Office and SharePoint patches in your patch cycle this week.
Read more →Azure Outage Also Blocked Windows 11 & Microsoft Store Update Downloads
The same 23 July Azure routing incident disrupted the Windows Update and Microsoft Update services, preventing clients from downloading Windows 11 and Microsoft Store app updates. Microsoft confirmed the additional impact after the main M365 incident was resolved, noting some Azure products required extra recovery time. No workaround was available; Microsoft restored services by restoring the affected network routes.
Read more →CVE-2026-62832: Windows User Profile Service EoP Publicly Disclosed Before Patch
CVE-2026-62832 (CVSS 7.8) in the Windows User Profile Service was publicly disclosed prior to Microsoft issuing a fix, meaning exploit mechanics are already in the open and accelerate the risk window. A local attacker with credentials for one account can run a crafted application to load another user's registry hive and escalate to Administrator. Patch immediately as part of August Patch Tuesday; treat as near-critical given public disclosure.
Read more →Gunra Ransomware Group Actively Exploiting Fortinet Auth-Bypass Flaws CVE-2024-55591 and CVE-2025-24472
A joint FBI/CISA/NSA/South Korean advisory has exposed the Gunra ransomware group (rebranded from Conti) actively exploiting Fortinet authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472 to gain initial access — in one case tampering with VDI authentication files to fully neutralise MFA. The group operates as a ransomware-as-a-service model targeting organisations globally. If these Fortinet patches have not been applied, treat as emergency; verify authentication file integrity on all FortiGate/FortiProxy devices.
Read more →GTIA ChannelCon 2026: Channel Leaders Push AI Standards and Growing MSP Responsibility
GTIA's ChannelCon 2026 three-day event (held early August) highlighted that the channel's leading nonprofit is leaning into the idea that GTIA members should be setting standards for AI adoption, as MSP responsibilities continue to grow alongside partner trust and community expectations. The event underscored that partnerships and trust are becoming increasingly critical for MSPs navigating an AI-transformed service landscape. MSPs should review GTIA's emerging AI guidance frameworks as baseline standards for client advisory work.
Read more →August 2026 Patch Tuesday Largest in Years — AU MSPs Face Heavy Patch Validation Workload This Week
With 421 CVEs (some sources counting up to 751 when including re-issued advisories) across Windows, Office, SharePoint, Exchange, Azure, and Developer Tools, the August 2026 Patch Tuesday is one of the heaviest monthly releases on record — well above the trailing 12-month average. Australian MSPs with SMB client bases should prioritise CVE-2026-68820 (KEV deadline 25 August) and CVE-2026-62832 for emergency deployment, then schedule the remaining Windows and Office patches within two weeks. Phased rollouts with staging rings remain the recommended approach to avoid breaking changes.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.