Security for Lean IT TeamsWeekly
Security for lean IT: what to patch this week, and what can wait
Updated 12 August 2026 · Timeframe: This week's confirmed-exploited CVEs
5 confirmed-exploited CVEs landed this week. This week that includes Cisco, Microsoft. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.
Why it matters
With no security team, you can't chase everything. Confirmed exploitation is the one signal that reliably separates patch-now from patch-later.
What to do
- Security leaders. Make 'patch all KEV within N days' a written policy; it's the cheapest risk reduction you can mandate.
- Lean IT orgs. This week: patch the KEV CVEs, check Microsoft 365 / your main SaaS for the same, and schedule the rest.
- MSPs. Package the KEV list as this week's standard client maintenance window.
Our take
Most breaches hit organizations that lacked the time, not the tools. Plain-English 'what to patch' guidance is where resilience meets reality for lean IT orgs.
Earlier issues
Past states of this signal, most recent first.
10 August 2026 Security for lean IT: what to patch this week, and what can wait
Timeframe: This week's confirmed-exploited CVEs
6 confirmed-exploited CVEs landed this week. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.
03 August 2026 Security for lean IT: what to patch this week, and what can wait
Timeframe: This week's confirmed-exploited CVEs
3 confirmed-exploited CVEs landed this week. This week that includes Cisco, Fortinet. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.
27 July 2026 Security for lean IT: what to patch this week, and what can wait
Timeframe: This week's confirmed-exploited CVEs
6 confirmed-exploited CVEs landed this week. This week that includes Microsoft. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.