Blog
Practical guides for sysadmins — Patch Tuesday recaps, end-of-life planning and keeping software updates under control.
Does this CVE affect me? The five-minute path from identifier to answer
Five sources, five steps, and an order you should not reverse. Why the version number is the real dead end, and why nearly half of newly published entries carry no machine-readable product mapping at all.
The BSI advisory service reports everything — how to filter it down to the software you actually run
250 entries in the feed, 204 of them repeats, the oldest under 48 hours old: how a WID-SEC number is built, which three delivery routes exist, and where each one breaks when you match it against your own estate.
Open-source CVE monitoring: four designs and where each one breaks
9,770 CVE records appeared in July 2026 — half of them without a machine-readable product list. What OpenCVE, cve-bin-tool, Dependency-Track and the feeds from NVD, CISA, BSI and ENISA do with that, and where each approach breaks.
Exchange Server on-premises: 17 proven exploited flaws, out of support since October 2025
Exchange 2016 and 2019 have had no public security updates since 14 October 2025, and the German BSI counted more than 30,000 affected servers in late October. What the exploitation list actually holds, and the three routes left if the cloud is not an option.
Who promises firmware for how long? UniFi, MikroTik, LANCOM and AVM compared
Only one of the four vendors gives your model a date on which firmware maintenance ends. What the other three say instead, why a dated UniFi EOL list does not exist, and the one question to ask before you buy.
FortiOS 7.2 ends on 30 September — your support ended back in March 2025
Fortinet publishes two end dates per firmware branch, not one. FortiOS 7.2 left engineering support on 31/03/2025; end of support is 30/09/2026. What applies in between, which devices upgrade themselves, and why the LTS row means nothing for most estates.
MariaDB 12.2 is dead, 10.11 lives until 2028: which MariaDB version belongs on a server
With MariaDB the height of the version number says nothing about how long it is maintained: 12.2 ended in May 2026, 10.11 gets fixes until February 2028, and 11.4 outlives the younger 11.8 by a year. The rule behind it, the end dates, and the command that shows what you are running.
Buying a NAS by its update promise: Synology, QNAP, TrueNAS and openmediavault
How long will this NAS keep getting updates? The question has two answers — one for the model, one for the operating system branch. What the four common systems actually publish, with dates and sources (as of 19/08/2026).
Nextcloud 32 ends on 30 September — and you cannot just jump to 34
Maintenance for Nextcloud 32 ends on 30/09/2026. Jumping straight to 34 is not supported: major releases have to be walked one at a time. What that means for your schedule, your PHP version and the point releases in between.
Nextcloud, ownCloud Infinite Scale, OpenCloud: not which one does more, but which one stays maintained
Of the three vendors, exactly one publishes an end-of-support date per version. How many branches are maintained at once, for how long, where the date lives — and what the multi-year promise costs.
Proxmox Backup Server instead of Veeam? What the switch does to your lifecycle
Veeam Backup & Replication 12 is supported until 01/02/2027, Proxmox Backup Server 3 only until 31/08/2026 — although it shipped five months later. What the switch really changes about your upgrade rhythm, and what matters more.
Vendor security advisory feeds: 16 verified RSS and Atom addresses
Which vendors publish a security advisory feed, at which address, in which format and how far back it reaches — every URL fetched and counted on 19/08/2026. Plus the silent failure that kills feed subscriptions.
Software inventory with built-in tools: winget, PowerShell, dpkg — and the one column none of them can fill
Four ways to list installed software — registry, winget, Get-AppxPackage, dpkg and rpm — with the command, the output format and what each one systematically misses. And why Win32_Product is the expensive one.
Ransomware comes in through the SSL VPN — four vendors compared
Thirty-three vulnerabilities known to be exploited sit on four perimeter products (as of 19/08/2026), 21 of them flagged for ransomware. What separates FortiOS, PAN-OS, SonicOS and FortiClient EMS — and the question to answer on your own box today.
STARFACE 10, 9 and 8.1 get patched on the same day — which version belongs on your PBX
On 8 July 2026, versions 10.0.1.7, 9.0.3.8 and 8.1.3.7 shipped on the same day with identical fix notes. What the four digits mean, which lines are still maintained, and how the update from 8.0 upwards works without a reinstall.
Synology DSM: six current versions at once — and why your DiskStation sees a different update
Six DSM builds head their own line at the same time, from 7.4.1-90080 down to 6.2.4-25556-8. Only two branches still get fixes. How the number is built, and why your box is offered a different update than the one beside it.
Unattended upgrades on Proxmox and Debian: the package list that has to stay manual
unattended-upgrades never removes a package, which makes it exactly the apt mode Proxmox warns against. Which origins to allow, which blocklist entries matter, why needrestart does nothing in an automated run, and the mistake waiting before the first nightly reboot.
The upgrade path: why you cannot skip a version on FortiOS, GitLab or Proxmox
Going from FortiOS 6.4.9 to 7.6.4 takes six installs, not one. Why intermediate stops are technically forced, the three ways skipping breaks things, why downgrading is not a fallback — and how to reconstruct the path without a vendor account.
Veeam: which version until when — and why “supported” means two things
Veeam publishes two end dates per version: End of Fix and End of Support. Backup & Replication 12 passed the first in November 2025 and runs on until February 2027. Backup for Microsoft 365 8 ends in September 2026 and no successor has shipped yet. The matrix, with both columns.
What WSUS, Intune, winget and Chocolatey each fail to patch
Four deployment tools, four boundaries — and one remainder all four leave alone. What each covers, what it does not, and three questions that measure your real coverage.
winget, Chocolatey or Scoop — and the gap all three leave open
winget covers desktop applications, Chocolatey adds scripting and internal repositories, Scoop runs without admin rights. Of ten typical inventory items, none of the three touches seven — and Scoop has not shipped a release in 372 days (as of 19/08/2026).
WinRAR does not update itself — and that is exactly the problem
Four WinRAR flaws sit in CISA’s catalogue of vulnerabilities known to be exploited, three of them flagged for ransomware use. Why the vendor deliberately ships no updater — and three ways to keep the version current anyway.
Zabbix LTS does not mean five years of bug fixes — and 6.0 proves it
Zabbix 6.0 LTS is listed until 28/02/2027, but full support ended on 28/02/2025. Five years of LTS is three plus two. All nine dated cycles with both date columns — and why the production choice is 7.0 LTS, not 7.4.
What is actually being exploited — and why CVSS gives you the wrong order
163 vulnerabilities known to be exploited (as of 26/07/2026), analysed. Sixteen of them are rated merely medium. Prioritise by severity and stop at high, and you skip exactly the flaws attackers are using right now.
Staying on top of end of life: the gap no patch will close
Unpatched software eventually gets a patch. Software past end of support does not. How to see support cycles early enough to plan the migration instead of living through it.
Microsoft Patch Tuesday July 2026: what sysadmins should do now
July 14, 2026 was Microsoft Patch Tuesday. How to prioritize correctly: actively exploited flaws first, check current versions, keep an eye on end-of-life.