Why this week mattered: ControlUp shipped its most aggressive release cadence in months — headlined by the Agent ONE beta, which finally collapses its sprawling agent lineup into a single component — while Ivanti used its August Patch Tuesday forecast to warn admins that AI-accelerated CVE discovery is outpacing most teams’ ability to triage, let alone patch. Add incremental-but-useful drops from Microsoft Intune/Windows 365 and Omnissa’s Horizon stack, plus a NetScaler SAML flaw still worth double-checking your patch level against, and it’s a week of steady platform grinding rather than headline-grabbing launches.
Microsoft (Intune / Windows 365)
Controlled Configuration for Microsoft Defender settings enters preview. Intune can now be made the authoritative source for Defender antivirus settings, overriding Group Policy, Configuration Manager, and local scripts — a direct shot at the config-drift problem that plagues co-managed and legacy-migrated fleets.
Samsung Knox E-FOTA firmware management lands for Android Enterprise. Admins can now control firmware versions and schedule downloads/installs on corporate-owned Samsung COSU/COBO/COPE devices directly from Intune, without user interaction.
Windows 365 adds Autopilot Device Preparation for Citrix-hosted Cloud PCs. This brings Citrix Cloud PC provisioning in line with native Windows 365 deployment, ensuring required apps and scripts are staged before first user access.
Bulk deprovisioning for Cloud PCs in grace period hits public preview. Windows 365 Enterprise and Flex Dedicated admins can now clear out multiple grace-period Cloud PCs at once instead of waiting out the standard 7-day window one machine at a time.
Omnissa (Horizon / Workspace ONE)
App Volumes 2606 ships with CVE vulnerability reporting built in. Beyond the new custom package lifecycle stages and smart card auth support for App Volumes Manager, the release adds native CVE reporting — useful ammunition for teams justifying patch cycles to security.
Dynamic Environment Manager 2606 adds AD username targeting for policies. The release also brings bulk-delete for personalization files and fixes a long-standing “Run once” bug affecting non-DirectFlex environments.
ControlUp
Agent ONE beta consolidates ControlUp’s agent sprawl into a single component. Instead of separate agents for Desktops, VDI, and Compliance, Agent ONE is a unified deployment target — a meaningful ops simplification for shops running ControlUp across mixed physical/VDI/DaaS estates.
DaaS IQ picks up host pool performance charts and license capacity alerts. New collapsible Session Host Configuration views and status-based license alerts give Azure Virtual Desktop admins tighter visibility without leaving the ControlUp console.
Employee Incidents widget now breaks out App Incidents, BSODs, and DEX Score events separately. Paired with new alert scoping by device tags, it’s a small but practical upgrade for teams trying to triage “is this a device problem or an app problem” faster.
Ivanti
Ivanti’s August Patch Tuesday forecast calls out an unsustainable patch volume. Todd Schell notes July alone produced 600+ CVEs industry-wide (with only three confirmed actively exploited), and argues AI-driven vulnerability discovery is now outpacing teams’ ability to deploy fixes — his recommendation is to triage by known-exploited status and internet exposure rather than patch everything on release day.
If you’re still behind on July, prioritize SharePoint. The same forecast flags CVE-2026-50522 (actively exploited SharePoint RCE that can steal machine keys and persist post-patch) as the item to close out first, alongside watching for the incoming “LegacyHive” Windows registry-hive disclosure.
Citrix
Worth a re-check: NetScaler’s CVE-2026-8451 SAML memory-disclosure flaw saw active scanning within 24 hours of disclosure. It’s not brand-new (Citrix patched it June 30, exploitation was confirmed in early July), but with a CVSS of 8.8 and watchTowr researchers flagging it as part of a broader pattern of NetScaler memory-handling bugs, it’s a good prompt to confirm your ADC/Gateway fleet is actually on 14.1-72.61 / 13.1-63.18 or later if you haven’t checked recently.