<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Cyber Resilience — MSP Weekly</title><link>https://security-resilience.ai/msp-briefing.html</link><description>This week's exploited vulnerabilities, framed as the services that fix them, for MSPs. Each item names the offerings that prevent, detect, respond to, or recover from it.</description><lastBuildDate>Wed, 12 Aug 2026 13:40:34 +0000</lastBuildDate><item><title>KEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-46c34dcdddec.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-46c34dcdddec.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Check client inventories for self-hosted Metabase instances and patch CVE-2026-72898 to 0.51.5+ immediately; cloud Metabase tenants are unaffected.

Offerings that address it — Prevent: Vulnerability Management, Firewall, WAF, SASE/SSE, End-user elevation · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-20230, CVE-2026-20349, CVE-2026-68820, CVE-2026-72898</description></item><item><title>KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-1e730c30c2b8.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-1e730c30c2b8.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Inventory every client FortiOS/FortiGate instance, map versions against Fortinet’s fixed builds, and schedule upgrades under the KEV window. Flag any appliance already known compromised or left on unsupported builds.

Offerings that address it — Prevent: Firewall, SASE/SSE, MFA, SSO, WAF, Vulnerability Management, End-user elevation · Detect: SASE/SSE, Managed XDR, WAF, Vulnerability Management · Respond: Managed XDR

CVEs: CVE-2025-68686, CVE-2026-16812, CVE-2026-18577</description></item><item><title>New critical CVE: CVE-2026-50522 — Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a</title><link>https://security-resilience.ai/news/story/sr-0b0b6e5ca3e7.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-0b0b6e5ca3e7.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Inventory every client running on-prem SharePoint Server (any edition); prioritize patching CVE-2026-56164 and the other actively exploited CVEs across all tenants before addressing lower-severity SharePoint CVEs in this batch.

Offerings that address it — Prevent: MFA, Firewall, SASE/SSE, Gateway, IEP (M365 email protection), End-user elevation, Vulnerability Management, WAF, Help Desk validation, SSO · Detect: Managed XDR, SASE/SSE, Gateway, IEP (M365 email protection) · Respond: Managed XDR

CVEs: CVE-2025-40602, CVE-2026-15409, CVE-2026-15410, CVE-2026-32201, CVE-2026-45659, CVE-2026-50522</description></item><item><title>Cisco security advisory (AV26-807)</title><link>https://security-resilience.ai/news/story/sr-0c39cc026a41.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-0c39cc026a41.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Multiple ASA and FTD versions are under active exploitation per Cisco advisory AV26-807. Review every client stack running these firewalls, apply patches or mitigations, and confirm internet exposure is minimized.

Offerings that address it — Prevent: End-user elevation, Vulnerability Management · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-20349</description></item><item><title>KEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-1cd21886308f.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-1cd21886308f.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Scan all client environments for Langflow deployments — it's often spun up ad hoc for AI prototyping and easy to miss in asset inventories — and patch or take exposed instances offline first.

Offerings that address it — Prevent: End-user elevation, Vulnerability Management, Firewall, WAF, SASE/SSE, Third-party · Detect: Managed XDR, Vulnerability Management, SASE/SSE · Respond: Managed XDR

CVEs: CVE-2021-27137, CVE-2026-0770, CVE-2026-60137, CVE-2026-63030, CVE-2026-63077, CVE-2026-9198</description></item><item><title>Patch bundle: July 2026 Security Updates — 1164 CVEs, 3 exploited</title><link>https://security-resilience.ai/news/story/sr-da751a93d0a8.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-da751a93d0a8.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Inventory which clients run on-prem SharePoint Server versus SharePoint Online — only the former needs emergency action for CVE-2026-58644. Push the other three exploited CVEs (2026-56155, 2026-56164, 2026-48561) across the fleet this week; the rest of the 1164 can wait for standard rollout.

Offerings that address it — Prevent: SASE/SSE, WAF, Gateway, MFA, Firewall, Vulnerability Management, End-user elevation, IEP (M365 email protection), Training, Phishing simulation, Help Desk validation, SSO · Detect: SASE/SSE, WAF, Managed XDR, Gateway, IEP (M365 email protection), AI security · Respond: Managed XDR, IEP (M365 email protection)

CVEs: CVE-2026-41106, CVE-2026-42990, CVE-2026-45499, CVE-2026-48561, CVE-2026-49172, CVE-2026-50522</description></item><item><title>KEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-ce0e7ef98629.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-ce0e7ef98629.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Inventory every client with Cisco Secure Firewall Management Center; prioritize CVE-2026-20316—hard-coded credentials, unauthenticated remote access, actively exploited, now KEV. Patch or mitigate per Cisco, then check for unexpected logins on affected FMC instances.

Offerings that address it — Prevent: MFA, End-user elevation, Help Desk validation, SSO, SASE/SSE, Firewall, Vulnerability Management · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-20316</description></item><item><title>KEV: CVE-2026-46817 — Oracle E-Business Suite (Oracle E-Business Suite Improper Privilege Management Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-8a73ba0fe222.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-8a73ba0fe222.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Inventory all client instances of Oracle E-Business Suite, flag any with Oracle Payments exposed to the network, and push the patch as emergency change — this is unauthenticated network exploitation, not a low-priority ticket.

Offerings that address it — Prevent: MFA, SSO, Firewall, SASE/SSE, Vulnerability Management, End-user elevation, Help Desk validation, WAF · Detect: Managed XDR, SASE/SSE, Vulnerability Management · Respond: Managed XDR · Recover: Entra ID backup, M365 backup

CVEs: CVE-2023-4346, CVE-2026-25089, CVE-2026-35263, CVE-2026-35292, CVE-2026-35301, CVE-2026-35307</description></item><item><title>KEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-78bd02e91239.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-78bd02e91239.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Inventory clients with on-prem Arista VeloCloud Orchestrator; this is unauthenticated command injection under active exploitation with a KEV deadline. Patch immediately and review orchestrator hosts and managed Edges for signs of compromise.

Offerings that address it — Prevent: Vulnerability Management, WAF, Firewall, SASE/SSE, End-user elevation · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-16812</description></item><item><title>Tenable security advisory (AV26-724)</title><link>https://security-resilience.ai/news/story/sr-2caf5d5031f1.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-2caf5d5031f1.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Flag any client running self-hosted Tenable Security Center (6.6.0–6.8.0) and push the patch across the fleet; cloud-hosted Tenable.io/Tenable.sc-as-a-service clients aren't exposed.

Offerings that address it — Prevent: MFA, SSO, SASE/SSE, Firewall, Vulnerability Management, WAF, End-user elevation · Detect: Managed XDR, SASE/SSE · Respond: Managed XDR

CVEs: CVE-2026-16232, CVE-2026-50522</description></item><item><title>Two new high severity WordPress vulnerabilities, patch immediately!</title><link>https://security-resilience.ai/news/story/sr-9ab4fec5233a.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-9ab4fec5233a.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Roll WordPress core updates (7.0.2/6.9.5/6.8.6) to all client sites this week and check web logs for exploitation attempts on CVE-2026-60137 and CVE-2026-63030, since exploitation started soon after disclosure.

Offerings that address it — Prevent: Vulnerability Management, WAF, Firewall, SASE/SSE · Detect: SASE/SSE, Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-60137, CVE-2026-63030</description></item><item><title>KEV: CVE-2026-25089 — Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-deb3d52734fb.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-deb3d52734fb.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Check every client's FortiSandbox deployment (4.4.x, 5.0.x) against this KEV pair — unauthenticated command injection with active exploitation means this jumps the patch queue across your book. Flag any instance reachable from the internet as an emergency ticket, not routine maintenance.

Offerings that address it — Prevent: Vulnerability Management, WAF, Firewall, SASE/SSE, End-user elevation · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-25089, CVE-2026-39808</description></item><item><title>Erlang security advisory (AV26-750)</title><link>https://security-resilience.ai/news/story/sr-c7c25a9036f2.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-c7c25a9036f2.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Scan client stacks for Erlang/OTP and coordinate updates to the fixed versions cited in AV26-750 and the linked erlang/otp advisories.

Offerings that address it — Prevent: End-user elevation, MFA, SSO, Vulnerability Management, SASE/SSE, Firewall · Detect: Managed XDR, SASE/SSE · Respond: Managed XDR

CVEs: CVE-2026-18972</description></item><item><title>Bulletin de sécurité Red Hat (AV26-803)</title><link>https://security-resilience.ai/news/story/sr-7f770e8890d8.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-7f770e8890d8.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Check which clients run Red Hat Advanced Cluster Management for Kubernetes 2 and schedule the AV26-803 updates promptly.

Offerings that address it — Prevent: End-user elevation, MFA, Vulnerability Management, Help Desk validation, SSO · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-10090</description></item><item><title>OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber</title><link>https://security-resilience.ai/news/story/sr-710123f9f849.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-710123f9f849.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Track client adoption of Daybreak Red; advise only mature clients with explicit red-team needs, and watch for policy or compliance implications around reduced guardrails.

Offerings that address it — Prevent: Vulnerability Management, Firewall, SASE/SSE, WAF, End-user elevation · Detect: Managed XDR, SASE/SSE · Respond: Managed XDR

CVEs: CVE-2026-15903</description></item><item><title>Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks</title><link>https://security-resilience.ai/news/story/sr-7477884146cb.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-7477884146cb.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Audit all managed Fortinet firewalls, VPNs, and Schneider Electric devices for the listed vulnerabilities and ensure MFA is enforced on management interfaces. Gunra is using these exact flaws plus Conti-derived ransomware against critical-infrastructure clients.

Offerings that address it — Prevent: MFA, Vulnerability Management, Firewall, SASE/SSE, WAF · Detect: Managed XDR, Vulnerability Management, SASE/SSE · Respond: Managed XDR

CVEs: CVE-2024-5559, CVE-2025-24472</description></item><item><title>Grafana security advisory (AV26-796)</title><link>https://security-resilience.ai/news/story/sr-77cb1da8baf3.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-77cb1da8baf3.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Check every client running Grafana MCP Server or mcp-grafana (≤1.0.0) and update to a fixed version when released.

Offerings that address it — Prevent: Vulnerability Management, WAF, Firewall, SASE/SSE · Detect: Managed XDR · Respond: Managed XDR

CVEs: CVE-2026-19516</description></item><item><title>Pulsetto Vagus Nerve Stimulator</title><link>https://security-resilience.ai/news/story/sr-8fba941379f1.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-8fba941379f1.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>CISA reports active exploitation of CVE-2026-18844 in Pulsetto Vagus Nerve Stimulators. Check every client site or telehealth provider that uses these devices; isolate them from networks and confirm the vendor supplies a patch or workaround.

Offerings that address it — Prevent: MFA, Firewall, SASE/SSE, Vulnerability Management, Third-party · Detect: Managed XDR, SASE/SSE, Vulnerability Management · Respond: Managed XDR

CVEs: CVE-2026-18844</description></item><item><title>Mira Hormone Monitor, Mira Android App</title><link>https://security-resilience.ai/news/story/sr-ad55d1303522.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-ad55d1303522.html</guid><pubDate>Wed, 12 Aug 2026 13:40:34 +0000</pubDate><description>Check client environments for any use of Mira Hormone Monitor devices or the Mira Android app and ensure firmware and app updates are applied. This primarily affects clients in healthcare or fertility tracking.

Offerings that address it — Prevent: MFA, SSO, SASE/SSE, Firewall, Vulnerability Management, WAF, End-user elevation, Gateway, IEP (M365 email protection), Help Desk validation · Detect: Managed XDR, SASE/SSE, Gateway, IEP (M365 email protection) · Respond: Managed XDR

CVEs: CVE-2026-64934, CVE-2026-66098, CVE-2026-66340, CVE-2026-66832, CVE-2026-66875, CVE-2026-67558</description></item></channel></rss>