September 2026 News & Updates (a new record)

CTC News

  • Current MyIT Clients – Our September monthly maintenance is underway. This month’s focus includes Windows security updates, backup testing, software inventory verification, and endpoint protection health checks.
  • MyIT Program Reminder – For businesses running without managed IT, the MyIT Program provides enterprise-level protection without enterprise-level pricing. With no term agreements, you can cancel anytime if you don’t find value. Details available here.

Industry News

  • Microsoft September 2026 Patch Tuesday Shatters All Records – Microsoft patched approximately 974 vulnerabilities this month, the largest single Patch Tuesday release in history. To put that in perspective: Microsoft released 1,009 patches in 2024 (the entire year) and 1,139 in 2025 (again, the entire year). This single month nearly matched that entire year. Year-to-date for 2026, Microsoft has already patched over 2,600 vulnerabilities — more than double the previous record — with three months still remaining.
  • Two Windows Zero-Days Under Active ExploitationCVE-2026-85880 (Windows ALPC elevation of privilege) and CVE-2026-81963 (Windows Update Stack elevation of privilege) are both confirmed exploited in the wild. Both allow attackers with low-privilege local access to escalate to SYSTEM. CISA added both to the Known Exploited Vulnerabilities catalog with a September 22 remediation deadline.
  • Adobe Commerce “StyleSmuggler” Zero-Day (CVE-2026-75650) – Adobe patched 172 CVEs this month, including a critical unauthenticated remote code execution flaw in Magento and Adobe Commerce that has been actively exploited since September 4. Attackers are injecting malicious PHP code through template styles properties and installing persistent backdoors. CISA set a September 11 deadline for federal agencies.
  • Chrome Zero-Day CVE-2026-85046 – Google patched a high-severity type confusion flaw in the V8 JavaScript engine on September 3. Both Chrome and Microsoft Edge (which uses Chromium) are affected. Google confirmed active exploitation in the wild. Microsoft has not yet published a separate advisory for the Edge variant.
  • Patch Tuesday Breaking Remote Desktop – Microsoft’s latest Windows updates are proving troublesome, with serious Remote Desktop failures and another bug hitting Remote Desktop users.
  • SonicWall SMA1000 Under Active Attack – Two zero-days (CVE-2026-83548 and CVE-2026-83549) are being chained for unauthenticated RCE on SMA1000 6210/7210/8200v appliances. CISA KEV-listed September 2. Does not affect firewall SSL-VPN or SMA 100 Series. Patch now.
  • Cisco Secure FMC Authentication Bypass (CVE-2026-20079) – CVSS 10.0 flaw allows unauthenticated remote attackers to execute scripts and obtain root access on Firewall Management Center. Active exploitation confirmed; CISA set a federal remediation deadline of September 12. If you have Cisco FMC, patch immediately
  • ConnectWise ScreenConnect Critical Flaw (CVE-2026-84869)CVSS 9.9 vulnerability allows attackers to transfer and execute files through active remote sessions without host confirmation. CISA added it to the Known Exploited Vulnerabilities catalog on September 11; worm-like attacks have been observed since August 20. If you use ScreenConnect, patch clients to version 26.6.5 immediately and audit session logs for unauthorized file transfers. If patching is delayed, disable the TransferFiles permission
  • Fortinet FortiSandbox Critical RCE (CVE-2026-39808 & CVE-2026-25089) – Unauthenticated remote code execution via command injection. CISA confirmed active exploitation and ordered federal agencies to patch by September 19. Also relevant: CVE-2026-26083, another FortiSandbox RCE. If you use Fortinet FortiSandbox, prioritize firmware updates immediately.
  • Fortinet FortiCloud SSO Vulnerabilities (CVE-2025-25249 & CVE-2026-24858) – Heap-based buffer overflow and authentication bypass in FortiCloud SSO. CISA added both to the KEV catalog. Attackers with any FortiCloud account could pivot to other registered devices. If you have FortiGate firewalls with FortiCloud SSO enabled, verify patches and review for unauthorized admin accounts or VPN configuration changes

Updates

MicrosoftMicrosoft’s September 2026 Patch Tuesday is unprecedented: approximately 974 vulnerabilities patched, including 104 critical bugs and 2 zero-day vulnerabilities actively exploited in the wild. This single monthly release nearly matched Microsoft’s entire previous record year of 2020 (1,245 CVEs). The year-to-date total for 2026 now exceeds 2,600 vulnerabilities — more than double the previous annual record.

The breakdown by category includes hundreds of elevation of privilege, remote code execution, information disclosure, and denial of service vulnerabilities across Windows, Office, SQL Server, SharePoint, Azure, and Developer Tools. Microsoft has credited AI-assisted vulnerability discovery for the accelerating volume.

Actively Exploited:
CVE-2026-85880 – Windows Advanced Local Procedure Call (ALPC) elevation of privilege. Heap-based buffer overflow allows low-privilege attackers to escape AppContainer sandboxes and gain SYSTEM privileges. Affects Windows 10 and Server 2012-2022. Discovered by Volexity and Proofpoint.

CVE-2026-81963 – Windows Update Stack elevation of privilege. Improper link resolution allows authorized local attackers to gain SYSTEM privileges. Affects Windows 11 and Server 2025. Discovered by Romain Deperne of Airbus Helicopters and Microsoft Threat Intelligence Center.

Microsoft releases regular updates the second Tuesday of each month, often referred to as “Patch Tuesday.” These updates are categorized as Low, Moderate, Important or Critical. If you have one or more of these products installed, especially if the update is listed as Important or Critical, it’s important that the updates are installed.

Additional details on this month’s Microsoft updates are available from SANS Internet Storm Center, Krebs on Security, Bleeping Computer, and Rapid7.


Adobe has released 10 bulletins this month addressing 172 vulnerabilities, including a critical zero-day (CVE-2026-75650, “StyleSmuggler”) actively exploited in Adobe Commerce and Magento Open Source since September 4. The flaw allows unauthenticated remote code execution via malicious PHP code injection in template styles. Adobe also released priority updates for ColdFusion, Experience Manager, Acrobat Reader, Photoshop, Illustrator, and Animate. Details available from Adobe and SecurityWeek..

Additional details are available from Adobe Here including links to download the update(s) and instructions for installation.


Need IT Support for your Home or Business? We’d love to help!

Are you a small to medium sized business looking to leverage technology and enable your business and workforce to work smarter and more efficiently? Do you already have computers, servers, firewalls, VPNs or other technology that you’re not taking full advantage of? Are you looking for an IT Service Provider who understands small to medium sized businesses needs and the challenges that we face that can work with you to grow your business rather than just sell you time?

Cyber Tech Cafe is an IT Service Company with a focus on helping small to medium business get the most out of their technology investment. As a small business ourselves, we understand the challenges you face and have designed our service offerings to help you get the most out of your technology dollar. We offer on-call, as needed support if you just need a quick fix or extra set of hands right now. We also offer maintenance plans that we call “MyIT” that are designed to address the most common concerns (patch management, disaster recovery / backup, log review, etc.) that are based on the number of workstations and servers that you have and have no term contract. We believe that, if you find value in what we’re doing, you’ll find a way to keep us around without a contract saying that you have to.

If you have questions about the MyIT plans or have an IT need that you need addressed right now, let us know. We look forward to the opportunity to earn your business.

Article Submitted by Nathan J. Underwood, CEH