MSP Weekly
This week's news, matched to the services you sell. Select your offerings below to see where you sell the fix.
Issue: Week of 10 August 2026 · Last updated: 12 August 2026 00:47 UTC · Subscribe (RSS)
This week's standard client maintenance window
The KEV / critical set every client should patch on their normal cadence — package it as one scheduled window across the portfolio. This week's must-patch list → · why this sells →
My service offerings
Check the services you provide. We'll flag and float this week's items your services fix. Saved on this device only; no account needed.
Where your offerings are the answer this week
- VulnerabilityKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)▲ Your offering
Check client inventories for self-hosted Metabase instances and patch CVE-2026-72898 to 0.51.5+ immediately; cloud Metabase tenants are unaffected.
- VulnerabilityKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)▲ Your offering
Inventory every client FortiOS/FortiGate instance, map versions against Fortinet’s fixed builds, and schedule upgrades under the KEV window. Flag any appliance already known compromised or left on unsupported builds.
- VulnerabilityNew critical CVE: CVE-2026-50522 — Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a▲ Your offering
Inventory every client running on-prem SharePoint Server (any edition); prioritize patching CVE-2026-56164 and the other actively exploited CVEs across all tenants before addressing lower-severity SharePoint CVEs in this batch.
- VulnerabilityKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)▲ Your offering
Scan all client environments for Langflow deployments — it's often spun up ad hoc for AI prototyping and easy to miss in asset inventories — and patch or take exposed instances offline first.
Scan client stacks for Erlang/OTP and coordinate updates to the fixed versions cited in AV26-750 and the linked erlang/otp advisories.
Check which clients run Red Hat Advanced Cluster Management for Kubernetes 2 and schedule the AV26-803 updates promptly.
Inventory which clients run on-prem SharePoint Server versus SharePoint Online — only the former needs emergency action for CVE-2026-58644. Push the other three exploited CVEs (2026-56155, 2026-56164, 2026-48561) across the fleet this week; the rest of the 1164 can wait for standard rollout.
- VulnerabilityOpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber▲ Your offering
Track client adoption of Daybreak Red; advise only mature clients with explicit red-team needs, and watch for policy or compliance implications around reduced guardrails.
- VulnerabilityGunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks▲ Your offering
Audit all managed Fortinet firewalls, VPNs, and Schneider Electric devices for the listed vulnerabilities and ensure MFA is enforced on management interfaces. Gunra is using these exact flaws plus Conti-derived ransomware against critical-infrastructure clients.
- VulnerabilityKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)▲ Your offering
Inventory every client with Cisco Secure Firewall Management Center; prioritize CVE-2026-20316—hard-coded credentials, unauthenticated remote access, actively exploited, now KEV. Patch or mitigate per Cisco, then check for unexpected logins on affected FMC instances.
- VulnerabilityKEV: CVE-2026-46817 — Oracle E-Business Suite (Oracle E-Business Suite Improper Privilege Management Vulnerability)▲ Your offering
Inventory all client instances of Oracle E-Business Suite, flag any with Oracle Payments exposed to the network, and push the patch as emergency change — this is unauthenticated network exploitation, not a low-priority ticket.
For your client sectors
This week’s stories across all client sectors — pick your sectors in the header above to focus on the industries you serve.
- Leak-site claim: Orova lists Ganzhou Xinye Craft Co., Ltd.Ganzhou Xinye Craft Co., Ltd.
- Leak-site claim: Panzer lists Xpress TechXpress Tech
- Leak-site claim: qilin lists G.M.A.G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L
- Leak-site claim: payload lists B&B HydraulikB&B Hydraulik
- Leak-site claim: payload lists Stücheli ArchitektenStücheli Architekten
- Leak-site claim: payload lists Baya TechnologiesBaya Technologies
- Leak-site claim: krybit lists www.apsanet.com.arwww.apsanet.com.ar
- Leak-site claim: qilin lists Service Evaluation ConceptsService Evaluation Concepts
- Leak-site claim: qilin lists tommer constructiontommer construction
- Leak-site claim: direwolf lists LeafwellLeafwell
- Leak-site claim: aurora lists FREYWILLEFREYWILLE
How we write these. Every item names the control that fixes it and the service you offer to deliver it. We never flag a threat without its fix; revenue is a bonus, not the pitch.