<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Patch-Tuesday on CuraSec</title><link>https://curasec.metacog.co.kr/tags/patch-tuesday/</link><description>Recent content in Patch-Tuesday on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 25 Aug 2026 11:39:54 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/patch-tuesday/index.xml" rel="self" type="application/rss+xml"/><item><title>August Patch Tuesday breaks printing/PDF in WPF apps</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-microsoft-august-updates-break-printing-pdf-export-in-wpf-ap/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-microsoft-august-updates-break-printing-pdf-export-in-wpf-ap/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you run WPF-based applications, hold or test the August .NET Framework update before deploying; monitor Microsoft&amp;rsquo;s known-issue tracker for a fix or workaround before pushing to production.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>August 2026 Patch Tuesday: Exploited Zero-Day Among 415 CVEs</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-august-2026-patch-tuesday-one-exploited-zero-day-and-62-crit/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-august-2026-patch-tuesday-one-exploited-zero-day-and-62-crit/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> An actively exploited zero-day in this cycle demands prioritization over routine patching; read the full CrowdStrike analysis to identify the affected product and fast-track that specific patch ahead of the 62 criticals.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The exploited zero-day likely carries a detection angle — review the full analysis for associated TTPs or IOCs and build or tune a detection before patch coverage is complete across the estate.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A 415-CVE patch cycle with one exploited zero-day is operationally significant but below board altitude unless the zero-day proves systemic; no leadership action required until the engineering team surfaces exposure details.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft August 2026 Patch Tuesday: 398 Fixes, One Actively Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-plugs-nearly-400-security-holes/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-plugs-nearly-400-security-holes/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Apply August 2026 Patch Tuesday updates now, prioritizing the one actively exploited vulnerability and the two publicly disclosed issues first, then triage the remaining 395 by severity and exposure surface.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Once Microsoft releases specifics on the actively exploited CVE, build or tune detections for exploitation attempts; the two pre-patched public disclosures may already have known TTPs worth hunting against Windows endpoint telemetry.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A cycle of nearly 400 patches with confirmed in-the-wild exploitation is useful board-level context on Microsoft platform risk, but your engineering team owns the response — no leadership action required unless the exploited CVE turns out to be systemic.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft August 2026 Patch Tuesday: 400 Flaws, 1 Actively Exploited Zero-Day</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-d/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-d/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> One actively exploited zero-day among 400 CVEs makes this a high-priority patch cycle; apply August 2026 Patch Tuesday updates immediately, focusing first on the in-the-wild zero-day once specific CVE identifiers are confirmed from Microsoft&amp;rsquo;s advisory.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The actively exploited zero-day creates a detection obligation; once the specific CVE and affected component are identified from Microsoft&amp;rsquo;s release notes, build or tune detections for exploitation attempts and sweep endpoints for signs of pre-patch compromise.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft August Patch Tuesday: 398 Fixes, Windows Driver LPE Zero-Day Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-patches-398-flaws-including-a-windows-driver-zero/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-patches-398-flaws-including-a-windows-driver-zero/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVE-2026-68820 is CISA KEV-listed with a public GitHub PoC and confirmed active exploitation — apply August 2026 Patch Tuesday updates immediately, prioritizing this kernel driver fix to close the SYSTEM-level LPE path.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active in-the-wild exploitation of a SYSTEM-level LPE means attackers may already have escalated on unpatched endpoints — hunt for anomalous SYSTEM-privilege process spawns from unexpected parent processes and tune EDR alerts for T1068 kernel-driver abuse since the public PoC widens attacker access.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A 398-patch batch with one actively exploited zero-day may strain standard patch SLAs — confirm your teams have triaged CVE-2026-68820 as this week&amp;rsquo;s priority and verify compliance with your critical-patch SLA before the next board or audit checkpoint.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-68820 — CISA KEV: listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Patch Tuesday Aug 2026: 418 CVEs, 1 Exploited Zero-Day</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-patch-tuesday-august-2026-tue-aug-11th/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-microsoft-patch-tuesday-august-2026-tue-aug-11th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> With 62 critical CVEs including remote code execution in QUIC and DNS Server plus one actively exploited privilege escalation zero-day, prioritize patching Windows systems this week — target the exploited zero-day and RCE bugs in DNS Server and QUIC-enabled stacks first.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> One vulnerability is confirmed exploited in the wild; hunt for privilege escalation activity on Windows endpoints since August 11 and tune EDR/SIEM detections for post-exploit behavior while engineering patches.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The scale (418 patches, 62 critical, active exploitation) warrants confirming your patch SLA is on track and reviewing exposure of any internet-facing Windows DNS infrastructure with your team this quarter.&lt;/li>
&lt;/ul></description></item><item><title>SAP Commerce Cloud CVSS 10.0 Unauthenticated RCE Flaw Patched</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-sap-commerce-cloud-flaw-could-let-unauthenticated-attackers/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-sap-commerce-cloud-flaw-could-let-unauthenticated-attackers/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC on GitHub for a CVSS 10.0 unauthenticated RCE in SAP Commerce Cloud Data Hub Adapter makes exploitation practical now; apply SAP&amp;rsquo;s patch for CVE-2026-58231 immediately and verify no unauthorized access to the Data Hub Adapter endpoint prior to patching.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC available for unauthenticated RCE, sweep web access logs for anomalous requests to SAP Commerce Cloud Data Hub Adapter endpoints and hunt for post-exploitation activity (unusual process spawns, lateral movement) on Commerce Cloud hosts since the disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether your organization runs SAP Commerce Cloud and, if so, verify the engineering team has emergency-patched CVE-2026-58231; a public PoC for a max-severity unauthenticated RCE on an e-commerce platform warrants a same-week status check and potential customer notification if the platform handles transaction data.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-58231 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Windows 11 KB5121003 &amp; KB5120240 cumulative updates released</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-windows-11-kb5121003-kb5120240-cumulative-updates-released/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-windows-11-kb5121003-kb5120240-cumulative-updates-released/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Schedule deployment of KB5121003 (25H2/24H2) and KB5120240 (23H2) through your standard Windows update pipeline; no KEV or PoC signals elevate this to emergency patching.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft July 2026 Patch Tuesday: 570 Flaws, 2 Actively Exploited Zero-Days</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two zero-days actively exploited in the wild against Microsoft products demand immediate patching priority this cycle; apply July 2026 Patch Tuesday updates now, triaging the exploited CVEs before the routine 570-flaw backlog.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The summary confirms active exploitation but provides no IOCs, TTPs, or ATT&amp;amp;CK mappings yet — monitor vendor and threat-intel feeds for those details, then build or tune detections targeting the specific zero-day exploit behaviors once published.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Record patch volume plus two actively exploited zero-days warrants confirming with engineering that patch management is accelerated this cycle; brief leadership if customer security questionnaires or board inquiries arrive about the record-breaking release.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft July 2026 Patch Tuesday: 622 CVEs, 2 Actively Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patch-tuesday-july-2026-the-ai-acopolypse-is-here/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patch-tuesday-july-2026-the-ai-acopolypse-is-here/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two vulnerabilities are already under active exploitation in this cycle; apply Microsoft&amp;rsquo;s July 2026 updates immediately, prioritizing the two exploited CVEs and the 62 criticals — check the Microsoft Security Update Guide for specific product versions and patches.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Two actively exploited CVEs exist in this release but no IOCs or TTPs are provided here; pull the specific CVE details from Microsoft&amp;rsquo;s bulletin this week and build or tune detections for exploitation attempts against the affected components.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A record-volume Patch Tuesday with confirmed active exploitation is worth a brief to engineering leadership to confirm prioritization; validate that patch SLAs for critical and exploited CVEs are being met this cycle.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft July 2026 Patch Tuesday: 622 CVEs, Two Exploited Zero-Days</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-july-2026-patch-tuesday-microsoft-patches-622-vulnerabilitie/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-july-2026-patch-tuesday-microsoft-patches-622-vulnerabilitie/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two actively exploited zero-days in Microsoft products warrant immediate prioritization of July Patch Tuesday; apply updates now, focusing on the exploited CVEs first — check the full advisory to identify affected components (Windows, Edge, Office, etc.) and patch to current versions within your critical SLA.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Active exploitation of two zero-days means adversaries may already be in unpatched estates; review the CrowdStrike analysis for TTPs and any IOCs tied to those exploits, then build or tune detections targeting post-exploitation behaviors for the affected components before the broader threat actor ecosystem adopts these.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Two actively exploited zero-days in this cycle elevate urgency beyond routine patch cadence — confirm with your engineering team this week that the exploited CVEs are being fast-tracked, and assess whether affected components touch regulated systems or customer-facing infrastructure that could trigger disclosure obligations.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft July 2026 Patch Tuesday: 622 CVEs, Two Zero-Days Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patches-record-622-flaws-including-two-zero-days-u/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patches-record-622-flaws-including-two-zero-days-u/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two vulnerabilities are under active exploitation with incident responders credited, making them immediate priorities — apply the July 2026 Microsoft updates now, targeting the two exploited CVEs first, then work through the remaining 620 on your normal risk-ranked cadence.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of both zero-days (with IR team involvement confirmed) means assume some estates are already hit — hunt for post-exploitation indicators on Windows systems that lag the July patch cycle and tune detections for lateral movement or privilege escalation patterns consistent with Microsoft kernel/privilege bugs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A record 622-CVE release with two actively exploited flaws is likely to surface in board or customer conversations this week — confirm your patch team is triaging the exploited CVEs on an expedited timeline and prepare a brief status for leadership in case questions arise.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft July 2026 Patch Tuesday: Record 570 CVEs Fixed</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patches-a-record-570-security-flaws/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-patches-a-record-570-security-flaws/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review the full July 2026 Patch Tuesday advisory this week and triage the 570 CVEs by severity and KEV/exploitation status; the sheer volume demands a systematic prioritization pass rather than blanket deferral.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, active exploitation detail, or detection angles are surfaced in this item; the AI-assisted discovery explanation for the volume surge is context worth noting but yields no immediate hunt or rule work.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> AI-accelerated vulnerability discovery is producing structurally higher patch volumes quarter over quarter; assess whether current patch SLAs and engineering capacity can absorb this cadence, and flag the trend as a resourcing input for next planning cycle.&lt;/li>
&lt;/ul></description></item><item><title>Windows 10 KB5099539 Extended Security Update Released</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-releases-windows-10-kb5099539-extended-security-up/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-microsoft-releases-windows-10-kb5099539-extended-security-up/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Windows 10 is in ESU territory; if you still run Win10 endpoints or golden images, deploy KB5099539 to stay covered under the extended support contract — schedule within your normal patch window.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization is paying for Windows 10 ESU, confirm KB5099539 is being deployed; if not, this is a prompt to assess Win10 fleet size and budget for ESU licensing or migration costs before end-of-extended-support.&lt;/li>
&lt;/ul></description></item><item><title>Windows 11 June 2026 cumulative updates released (570+ fixes)</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-windows-11-kb5101650-kb5099414-cumulative-updates-released/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-windows-11-kb5101650-kb5099414-cumulative-updates-released/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Schedule deployment of KB5101650/KB5099414 through your standard patch pipeline; 570+ fixes is a large surface but no KEV or PoC signals elevate this to emergency patching.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>