Skip to main content
Change Risk Intel

This Week in Change Risk — Week of Aug 10, 2026

Ben Ennis Founder, Ennis Studio · former Partner Technology Advisor, ServiceNow · 6 min read

Affiliate disclosure: some vendor links on this site are affiliate links. This recap is general change-management information, not legal, financial, or compliance advice.

Why this week mattered

Every Friday we round up the events that belong on a change advisory board’s radar: what got exploited, what broke, what vendors shipped, and what regulators did, filed under our cybersecurity beat. This week the pattern was the internet-facing admin plane. A business-intelligence tool with a maximum-severity flaw went on the federal must-patch list with confirmed data theft, Microsoft shipped another 400-CVE month dominated by privilege escalation, and the EU’s compliance clock kept running. Here is what a CAB should do with each.

1. KEV additions this week

CISA added three entries to its Known Exploited Vulnerabilities catalog this week, taking the 2026 total past 180 additions (CISA KEV catalog). The one that justifies an emergency change is CVE-2026-72898, an unauthenticated SQL injection in the /api/session/reset_password endpoint of Metabase, rated CVSS 10.0, added August 11 with a same-week August 14 deadline; it lets an attacker bypass authentication and gain administrator access to the connected database (The Hacker News, Bishop Fox advisory). The weakness worth naming: a compromised BI instance is a credential vault, because it stores connection strings for every database it queries. Framework, Anaconda, and n8n have already disclosed unauthorized customer-data access tied to the pre-patch window. The other two additions, CVE-2026-68820 (Windows afd.sys, CVSS 7.0, exploited) and CVE-2026-20349 (Cisco ASA/FTD, CVSS 8.6), both came in with the Patch Tuesday batch below. For a CAB, Metabase is the emergency: any internet-reachable self-hosted instance is in scope, and roughly 11,000 were exposed at disclosure.

2. Cloud incidents worth noting

After two weeks of GitHub Actions failures, the major providers had a genuinely quiet week. Cloudflare resolved an R2 availability issue on August 9 and a narrow 1.1.1.1 DNS-resolver problem confined to its Tel Aviv location, while GitHub cleared two short-lived issues on August 10 affecting Copilot model access and fine-grained token creation; AWS, Azure, and GCP core services showed no new global incidents (Cloudflare status history). The read for a change team: a quiet reliability week is exactly when to close out the deferred resilience work that a P1 always interrupts. The weakness a CAB should still name is regional blast radius — the Cloudflare DNS issue was limited to one city, but a resolver problem is invisible to most monitoring until users report it, so a status-page dependency belongs on the cloud-saas change register the same way a compute region does. Use the quiet stretch to test that your incident bridge and change record share a clock before the next real outage.

3. Vendor moves

The vendor calendar was dominated by Microsoft’s August Patch Tuesday on August 11, which fixed roughly 400 CVEs (counts range from Tenable’s 398 to Qualys’s 421 depending on methodology) with 42 rated critical (Tenable analysis, Krebs on Security). The headline is CVE-2026-68820, an actively exploited elevation-of-privilege flaw in afd.sys, the WinSock driver on effectively every endpoint, attributed by Check Point to the North Korean Lazarus group. The weakness a CAB must plan around: 176 of the ~400 fixes are privilege escalation, so this is a triage exercise, not one change window. Separately, ServiceNow announced its Autonomous Security lineup — six solutions spanning agentic exposure management and automated remediation — on August 4 (ServiceNow newsroom). Useful for change teams that already run ServiceNow ITSM, but the weakness to name is that “autonomous remediation” agents that open and close changes on their own can outrun a CAB’s audit trail if the approval gates are not explicitly wired in.

4. Compliance and regulatory

The live regulatory thread stayed European. NIS2 compliance obligations culminate in an October 17, 2026 deadline for essential and important entities across 18 sectors, and the first administrative penalties under the directive were already issued earlier in 2026 (European Commission NIS2 policy). The change-management read is direct: this week’s Metabase breach is exactly the kind of event that starts NIS2’s 24-hour early-warning clock for an in-scope entity, and the remediation changes filed during that incident become part of the record a regulator can request. A financial-sector CAB should also keep DORA in view — 2025’s ICT-resilience regulation entered its first genuine supervisory-enforcement cycle in 2026, with regulators signaling they will act on incident-reporting failures. The practical step this week, covered in our compliance beat, is to confirm your change record and incident-reporting workflow share a timestamp source so the 24/72/one-month narrative reconstructs cleanly under audit.

5. From the change-management community

The week’s most useful practitioner thread, running across r/sysadmin and Hacker News, reacted to the Metabase disclosure with a blunt question: why was a BI dashboard reachable from the open internet at all? The consensus worth borrowing is that analytics and BI platforms — Metabase, Superset, Redash, Grafana — quietly accumulate the widest data access of any tool in the stack while sitting outside the change-control that governs the databases they read. Several posters noted that these tools get stood up by data teams, not platform teams, so they never enter the CMDB and never get an exposure review. Treat every BI instance as a change actor with database-level blast radius: it belongs on the change register, behind SSO, and off the public internet, with credential rotation triggered the moment a flaw like this lands. That dependency mapping is what our CAB agenda generator is built to surface before an incident, not during one.

6. Chart of the week

We counted CISA KEV additions per week for the last eight weeks, drawing on the catalog’s weekly releases. This week’s three additions sit near the low end of the range, above the two-entry weeks of July 27 and August 3 but far below the July 13 spike of ten.

Bar chart of CISA KEV additions per week for the last eight weeks through the week of August 10, 2026, showing values of 6, 2, 6, 10, 6, 2, 2, and 3, with the current week highlighted in red

Week ofKEV additions
Jun 226
Jun 292
Jul 66
Jul 1310
Jul 206
Jul 272
Aug 32
Aug 103

The signal for capacity planning is unchanged: KEV additions average roughly five per week with occasional spikes, so a CAB sized to absorb about one emergency security change per weekday is right for a normal week. A low-count week like this one, sitting a day after a ~400-CVE Patch Tuesday, is the moment to work down the Microsoft backlog rather than stand down (CISA KEV catalog).

Get this every Friday

This recap goes out as our weekly newsletter — one email, the week’s change-risk signals, no fluff. Subscribe on the site to get it in your inbox every Friday morning.

Recommended reading:

Sources

Published August 14, 2026.