The Dashboard is Green. The Servers are Gone.
# The Dashboard is Green. The Servers are Gone.
Microsoft just dropped 622 flaws in a single Tuesday.
That number is designed to induce a specific kind of paralysis. When a vendor releases a list that long, the goal isn't clarity; it's a statistical wash. It allows the security team to tell the board they're "managing a high volume of vulnerabilities" while the sysadmins, overwhelmed by the sheer noise, prioritize the updates that don't break the legacy apps. It's a symbiotic relationship of plausible deniability.
But if you're staring at that list, stop. Most of it is noise.
If you want to know what actually matters this week, look at the gap between the CVSS score and the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS score is a theoretical exercise in "what if." The KEV is a record of "who is already inside."
Here is the hierarchy of urgency for July 15, ranked by how likely you are to be the victim of a very bad Friday.
First, the immediate fires. CISA added the SonicWall SMA1000 and Microsoft SharePoint Server flaws to the KEV on July 14. For the SonicWall appliances, the federal patch deadline is July 17. That is a 72-hour window. If you are running those appliances and haven't patched, you aren't "evaluating the risk"—you're just waiting for the notification.
The SharePoint flaw (CVE-2026-56164) is equally urgent. It's a missing authentication for a critical function. In plain English: the front door is unlocked and the sign says "come on in." Because this is internet-facing and actively exploited, this is your priority zero. Everything else pauses until this is done.
Second, the identity crisis. The Microsoft Active Directory Federation Services flaw (CVE-2026-56155) also hit the KEV on the 14th. You have until July 28 to fix this, but don't let the calendar fool you. AD FS is the keys to the kingdom. When attackers target identity providers, they aren't looking for one server; they're looking for the ability to forge tokens and walk through your network as a ghost.
Then there is the weirdness. CVE-2008-4128, a Cisco IOS flaw from eighteen years ago, was added to the KEV on July 13. This is the most telling part of the week. It reminds us that attackers don't always want the shiny new zero-day. Often, they just want the old, forgotten piece of hardware in the basement that everyone forgot to decommission in 2012. If you have "legacy" gear, you have a liability.
Now, let's talk about what you can actually ignore for a few days. The Joomla extensions (Balbooa Forms and iCagenda) are in the KEV, but unless your core business relies on those specific plugins, they aren't the reason you should be skipping lunch.
The most interesting tension this week is SAP. Two NetWeaver ABAP flaws (CVE-2026-44747 and 44761) carry a CVSS score of 9.9. In any other week, a 9.9 would trigger a company-wide panic. But they aren't in the KEV yet.
The standard corporate response here is to deprioritize them because "there's no evidence of active exploitation." This is a dangerous gamble. KEV is a lagging indicator. By the time a vulnerability is officially added to the catalog, the sophisticated groups have usually been using it for weeks. They don't announce their presence; they just settle in. If you're a Fortune 500 company running SAP, you're pricing in a risk that you cannot afford.
The second-order effect here is the insurance fallout. When the breach happens, the forensic auditors won't care that the SAP flaw wasn't in the KEV. They'll see a 9.9 CVSS score and a patch that sat unapplied for a month. Suddenly, "reasonable security measures" becomes a debate about whether you followed a government list or a vendor's severity rating. The insurer will find the gap that saves them the payout.
We've seen this pattern before. Remember the Citrix NetScaler madness of a few years back? The same rhythm: a critical edge device is exploited, a patch is released, and a handful of organizations treat the deadline as a suggestion. Those organizations became the primary case studies for the next three years of ransomware trends. The parallel is exact: the edge is the easiest way in, and the slowest way to fix.
So, we're left with the usual corporate theater. The CISO will report that "patching compliance is at 94%." That number is a lie. It means they patched the 600 easy Microsoft flaws and ignored the three hard ones that actually matter.
Which leads me to the only question that actually matters for your Tuesday morning meeting:
Who in this room is actually verifying that the SonicWall and SharePoint patches are live, and who is just trusting the dashboard that tells us we're "compliant"?
◼