Cyber Resilience

Security for Lean IT TeamsWeekly

Security for lean IT: what to patch this week, and what can wait

Updated 12 August 2026 · Timeframe: This week's confirmed-exploited CVEs

Cisco1Microsoft1Metabase1Progress1JetBrains1
This week's confirmed-exploited CVEs by vendor · security-resilience.ai

5 confirmed-exploited CVEs landed this week. This week that includes Cisco, Microsoft. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.

Why it matters

With no security team, you can't chase everything. Confirmed exploitation is the one signal that reliably separates patch-now from patch-later.

What to do

Our take

Most breaches hit organizations that lacked the time, not the tools. Plain-English 'what to patch' guidance is where resilience meets reality for lean IT orgs.

Earlier issues

Past states of this signal, most recent first.

10 August 2026 Security for lean IT: what to patch this week, and what can wait

Timeframe: This week's confirmed-exploited CVEs

N-able2Progress1JetBrains1Apache1IBM1

6 confirmed-exploited CVEs landed this week. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.

03 August 2026 Security for lean IT: what to patch this week, and what can wait

Timeframe: This week's confirmed-exploited CVEs

Cisco1Fortinet1Arista1

3 confirmed-exploited CVEs landed this week. This week that includes Cisco, Fortinet. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.

27 July 2026 Security for lean IT: what to patch this week, and what can wait

Timeframe: This week's confirmed-exploited CVEs

WordPress2Check Point1Microsoft1Langflow1DD-WRT1

6 confirmed-exploited CVEs landed this week. This week that includes Microsoft. Everything on the KEV list is patch-now; the high-EPSS movers are watch-and-schedule.