← The Desk 2026-08-02 The Wire
The Perimeter Site

Patching priorities for this week

Gus Tavares
2026-08-02
# Patching priorities for this week If you run a ten-person operation, you don't have a security operations center. You have a person who handles the printers and occasionally remembers to update the server. You cannot patch everything the moment a CVE is published. If you try, you’ll spend your entire quarter staring at progress bars instead of running a business. The only sane way to handle updates is triage. We rank by reality: things already being used by attackers go first, internet-facing gear goes second, and internal software goes whenever there's a gap in the schedule. Right now, the top of the list is your edge hardware. If you use Fortinet FortiOS, you have until August 10 to handle CVE-2025-68686. It’s on CISA's known exploited list. That means attackers aren't just guessing if it works; they know it does. For a small firm, the cost of this patch is maybe an hour of downtime and some nerves. For an enterprise, it's a coordinated rollout across 500 sites with redundancy checks. You don't have that luxury, so just schedule the window and hit the button. Similarly, if you’re using Arista VeloCloud Orchestrator, your deadline was July 30. If you missed CVE-2026-16812, you're currently leaving a command injection vulnerability wide open on your perimeter. Fix it today. Then there is the "if you use it" category. A critical flaw in Ruby on Rails (CVE-2026-66066) dropped today. If your business relies on a custom web app built on Rails, call whoever maintains that code immediately. Most small shops don't write their own frameworks, but if you do, this is the most serious story of the week. The same goes for those running VMware; three separate flaws—including CVE-2026-59310—allow for auth bypass and VM escape. The lowest priority, ironically, is often the one with the scariest numbers. Chrome recently pushed updates fixing 1,442 flaws. That number sounds catastrophic, but it's mostly noise. Browser updates are boring controls that work; just make sure your staff actually restarts their browsers to apply them. I have a problem with how we talk about CVSS scores. You’ll see a "9.8 Critical" and panic. But a 9.8 on an internal tool that requires physical access to the server room is less dangerous than a 6.0 on your public-facing VPN. The vendor assigns the score based on the code, not your network. Don't let a number trick you into patching a low-risk internal app while your firewall is screaming for help. The real danger here isn't just your own gear; it's the second-order effect of the managed service provider (MSP) model. Many small shops outsource their IT to a local firm. If that MSP misses the Fortinet or Arista patches, they aren't just risking one client—they're potentially opening 50 different businesses to the same attack via a single management console. It turns a localized problem into a regional outage. We've seen this cycle before with the VPN flaws of a few years back. The pattern is always the same: attackers find a hole in the "secure" perimeter, and every business using that brand of hardware becomes a target overnight. The only difference now is the speed of exploitation. You might argue that you're too small to be targeted. That’s a mistake. Attackers don't usually pick targets; they pick vulnerabilities. They scan the entire internet for an unpatched FortiOS version and then see who happens to be running it. You aren't being targeted because you're important; you're being targeted because you're open. Check your Fortinet firmware version before you leave on Friday.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.