Stay Ahead of Threats with the Latest Vulnerability Updates for September
Stay up to date on critical cyber risks, Microsoft’s September Patch Tuesday, and other notable third-party vulnerabilities. Timely patching is key to maintaining a strong security posture and protecting your business from threats.
Quick Highlights
- Microsoft Patch Tuesday:
– 974 vulnerabilities disclosed. This month’s Patch Tuesday release marks the record for the largest number of vulnerabilities patched in one release. This is the second time in 2026 that Microsoft has exceeded its patch record, with the first being the July 2026 Patch Tuesday release.
– 119 rated Critical, 2 are Zero-Day (2 actively exploited)
– Out-of-Band Patch published September 3rd patches the “ShieldBreak” exploit in MS Defender from last month
- Advisories from Major Vendors:
– Adobe: 170 vulnerabilities patched across 8 products
– Cisco: 2 critical-severity and 2 high-severity flaws, including [_]
– Fortinet: 2 high-severity flaws in FortiSandbox and FortiOS/FortiProxy
– Ivanti: 6 critical, 4 high-severity flaws in Ivanti Neurons for ITSM, Ivanti Endpoint Manager Mobile (EPMM), and Ivanti Sentry
– SAP: 4 critical, 5 high-severity vulnerabilities in SAP Extended Passport (EPP) Processing, SAP NetWeaver, SAP Cloud Application Programming Model, SAP ABAP Developer Tools, SAP Integration Suite, SAP Commerce Cloud
– SonicWall: 2 critical-severity vulnerabilities in SonicWall SMA1000 Series Appliances and SonicWall NSM On-Prem
- Top Threats to Watch:
– Active Exploitation of Critical Internet-Facing Vulnerabilities – Attackers are actively exploiting newly disclosed flaws, including Magento/Adobe Commerce, N-able N-central, Broadcom advisories, and exposed Microsoft Exchange servers. These issues can enable remote code execution, credential theft, and persistence before organizations can patch.
– MFA Bypass Through Adversary-in-the-Middle (AiTM) Phishing – Threat actors are increasingly using Evilginx2-style kits, NovaCookies, and BigBear 2.0 tosteal Microsoft 365 session cookies. Once captured, these tokens can bypass MFA and enable account takeover without the user’s password.
– Abuse of Legitimate Remote Access and Management Tools – Threat actors continue using trusted RMM tools for access and persistence, including rogue ScreenConnect activity and phishing campaigns leveraging legitimate remote access software. This makes malicious activity harder to distinguish from normal administration.
– Malware Distribution Through Trusted Software and AI-Themed Lures – Attackers are using fake installers, counterfeit download sites, and impersonated AI brands to deliver malware. These campaigns increase the risk of infostealer, remote access trojan, and credential theft infections.
– Data Theft and Extortion Operations Expanding Across Sectors – Recent ransomware, cloud data theft, and phishing activity show attackers increasingly stealing data before applying extortion pressure. This trend raises risk across sectors, even when ransomware encryption is not used.
Windows 10 Reaches End of Support
As of October 14, 2025, Microsoft has officially ended support for Windows 10. October 2025’s Patch Tuesday was the final security update for the OS—unless your organization enrolls in the Extended Security Updates (ESU) program.
- What This Means for Your Organization:
– No more security patches or bug fixes for Windows 10 devices
– Increased exposure to vulnerabilities and compliance risks
– Continued support requires either: 1.) Enrolling in Microsoft’s paid ESU program, or 2.) Upgrading to Windows 11
- Upgrading Windows 11
Unlike traditional feature upgrades, Windows 11 25H2 is built on the same servicing branch and code base as Windows 11 24H2, making the transition simpler and lower risk.
Fortress has thoroughly tested Windows 11 25H2 and recommends upgrading all supported devices. To begin the upgrade process, contact our 24/7/365 Security Operations Team or reach out to your client experience manager.
Windows 11 End of Support
As of November 2025, Microsoft has officially ended support for earlier versions of Windows 11 (listed below).
- Windows 11 version 21H2 (All Editions)
- Windows 11 version 22H2 (All Editions)
- Windows 11 version 23H2 (Home & Pro)
We would also like to highlight several upcoming End of Support dates for the following Windows releases:
- Windows 11 version 23H2 (Enterprise & Education) – Support ends November 10, 2026. After this date, these editions will no longer receive security updates or fixes.
- Windows 11 version 24H2 (Home & Pro) – Support ends October 13, 2026. Devices running these editions should be upgraded before this date to remain supported and secure.
Fortress recommends reviewing device inventories ahead of these deadlines to ensure systems are upgraded in advance and remain within a supported lifecycle.
* Some specialized editions of Windows 11 24H2 (e.g. Long Term Support Cycle) will continue to receive extended support through 2029. However, for all other editions we recommend upgrading to Windows 11 25H2.
Windows Server 2016 End of Support
Support for Windows Server 2016 is scheduled to end on January 12, 2027, which is now less than a year away. After this date, Microsoft will no longer provide security updates, bug fixes, or technical support for the platform.
Organizations still running Windows Server 2016 should begin planning upgrade or migration strategies to avoid increased security risk and compliance concerns once support ends.
Fortress recommends reviewing affected systems early to allow sufficient time for testing, upgrades, or workload migration before the end-of-support deadline.
Need help planning your transition?
Fortress SRM can help assess your environment, prioritize upgrades, and ensure your endpoints remain patch-compliant and secure.
Patch Tuesday Summary
Microsoft September 2026 Patch Tuesday
974 vulnerabilities disclosed, including 119 critical and 2 zero-days. By category:
- 438 Elevation of Privilege
- 258 Remote Code Execution
- 173 Information Disclosure
- 56 Denial of Service
- 19 Security Feature Bypass
- 16 Spoofing
- 13 Tampering
Critical Common Vulnerabilities and Exposures (CVEs)
Windows Zero Days
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-81963 | Windows Update Stack elevation of privilege vulnerability | Important | Yes, actively exploited |
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability | Important | Yes, actively exploited |
Other Critical CVE’s Worth Mentioning
| CVE-ID | Details | Severity | Exploited? |
| CVE-2026-70352 | Azure AI Language elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-69857 | Azure Cosmos DB spoofing vulnerability | Critical | Not aware |
| CVE-2026-80098 | Copilot Studio elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-83941 | Entra ID elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-72986, CVE-2026-73018 | Graphic Fonts remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72981 | IP Helper remote code execution vulnerability | Critical | Not aware |
| CVE-2026-85507 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). | Critical | Not aware |
| CVE-2026-85508 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). | Critical | Not aware |
| CVE-2026-85509 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. | Critical | Not aware |
| CVE-2026-85506 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). | Critical | Not aware |
| CVE-2026-85504 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_textin libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. | Critical | Not aware |
| CVE-2026-34182 | CMS AuthEnvelopedData processing may accept forged messages | Critical | Not aware |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-62906 | Microsoft Discovery Studio information disclosure vulnerability | Critical | Not aware |
| CVE-2026-65772 | Microsoft Dynamics 365 On-Premises remote code execution vulnerability | Critical | Not aware |
| CVE-2026-62916 | Microsoft Entra ID elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-70178 | Microsoft Fabric elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-78439 | Microsoft Office Graphics Component remote code execution vulnerability | Critical | Not aware |
| CVE-2026-81955, CVE-2026-77493 | Windows Graphics Component remote code execution vulnerability | Critical | Not aware |
| CVE-2026-73006 | DirectWrite remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69285, CVE-2026-78505, CVE-2026-77898, CVE-2026-69632 | Microsoft Office remote code execution vulnerability | Critical | Not aware |
| CVE-2026-81949, CVE-2026-81948, CVE-2026-81950, CVE-2026-81959, CVE-2026-81953, CVE-2026-81951 | Microsoft Excel remote code execution vulnerability | Critical | Not aware |
| CVE-2026-78509, CVE-2026-78525, CVE-2026-78519 | Microsoft Office Outlook remote code execution vulnerability | Critical | Not aware |
| CVE-2026-78520 | Microsoft Office Outlook information disclosure vulnerability | Critical | Not aware |
| CVE-2026-69678, CVE-2026-69797, CVE-2026-69767 | Microsoft Office PowerPoint remote code execution vulnerability | Critical | Not aware |
| CVE-2026-78510, CVE-2026-81952 | Microsoft Word remote code execution vulnerability | Critical | Not aware |
| CVE-2026-77504 | Microsoft Office Word remote code execution vulnerability | Critical | Not aware |
| CVE-2026-70351 | Microsoft WebP Image Extension remote code execution vulnerability | Critical | Not aware |
| CVE-2026-81352 | Web Media Extensions remote code execution vulnerability | Critical | Not aware |
| CVE-2026-58599 | HEVC Video Extensions remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69601 | Microsoft Windows Media Foundation remote code execution vulnerability | Critical | Not aware |
| CVE-2026-65818 | Power Automate elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-78449, CVE-2026-78450, CVE-2026-69530 | Windows Reliable Multicast Transport Driver (RMCAST) remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69827, CVE-2026-77505, CVE-2026-69858, CVE-2026-69813, CVE-2026-69730 | Windows DNS Server remote code execution vulnerability | Critical | Not aware |
| CVE-2026-66302 | Skype for Business remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69854 | Spring Cloud Azure elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-67378, CVE-2026-67631, CVE-2026-67643, CVE-2026-67636 | Microsoft SQL Server remote code execution vulnerability | Critical | Not aware |
| CVE-2026-65669 | Microsoft SQL Server elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-81355 | Virtual Hard Disk (VHD) Miniport Driver remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69874 | Windows ALPC elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-72958 | Windows Credential Guard elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-72954, CVE-2026-72957 | Windows Deployment Services remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72979, CVE-2026-69845 | Windows DHCP Server remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72987 | Windows DNS remote code execution vulnerability | Critical | Not aware |
| CVE-2026-73010, CVE-2026-78444 | Microsoft Failover Cluster remote code execution vulnerability | Critical | Not aware |
| CVE-2026-73017 | Graphics Kernel remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69784, CVE-2026-81354, CVE-2026-69740, CVE-2026-69799, CVE-2026-69820, CVE-2026-69864, CVE-2026-69710, CVE-2026-69725 | Windows Hello elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-72980 | Windows Hello security feature bypass vulnerability | Critical | Not aware |
| CVE-2026-69769 | Windows HTTP Print Provider remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72961 | Windows Hyper-V elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-69603, CVE-2026-80083 | Windows Hyper-V remote code execution vulnerability | Critical | Not aware |
| CVE-2026-73023, CVE-2026-77495, CVE-2026-73013, CVE-2026-70296, CVE-2026-69860, CVE-2026-69499 | Windows Imaging Component remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72983 | Internet Connection Sharing (ICS) remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69676 | Windows Kerberos remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69712 | Windows Key Distribution Center remote code execution vulnerability | Critical | Not aware |
| CVE-2026-70203, CVE-2026-72960 | Windows Media Player remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69579 | Windows Message Queuing remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72982 | Windows Netlogon remote code execution vulnerability | Critical | Not aware |
| CVE-2026-70586 | Windows Paint remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69649 | Raw Image Extension remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69518 | Windows Remote Desktop remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72959, CVE-2026-69590, CVE-2026-69852, CVE-2026-72950 | Windows Routing and Remote Access Service (RRAS) remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69501, CVE-2026-83939, CVE-2026-69846, CVE-2026-69906 | Windows Secure Kernel Mode elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-73009 | Windows Secure Socket Tunneling Protocol (SSTP) remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69595, CVE-2026-70585, CVE-2026-78445 | Windows Services for NFS ONCRPC XDR Driver remote code execution vulnerability | Critical | Not aware |
| CVE-2026-69829 | Windows Shell remote code execution vulnerability | Critical | Not aware |
| CVE-2026-72962 | Windows USB Video Driver elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-69890 | Windows Virtual Trusted Platform Module elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-83501 | Windows Virtualization-Based Security (VBS) information disclosure vulnerability | Critical | Not aware |
| CVE-2026-83498 | Windows Virtualization-Based Security (VBS) Enclave elevation of privilege vulnerability | Critical | Not aware |
| CVE-2026-55007 | Microsoft Exchange Server Remote Code Execution Vulnerability – A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. | Important | Not aware |
Microsoft September 2026 Security Update Release
3rd Party Critical CVE’s Worth Mentioning
Adobe Products *
| CVE-ID(s) | Affected Product | Issues | Key Risks |
| CVE-2026-19232 CVE-2025-64830 CVE-2026-75735 CVE-2026-27238 CVE-2026-75736 CVE-2026-75737 CVE-2026-75738 CVE-2026-71440 CVE-2026-27227 CVE-2026-75739 CVE-2025-64618 CVE-2025-64610 CVE-2026-75740 CVE-2026-75741 CVE-2025-64589 CVE-2025-64588 CVE-2026-75742 CVE-2025-64584 CVE-2026-27222 CVE-2026-71357 CVE-2025-64542 CVE-2026-75719 CVE-2026-75720 CVE-2026-75722 CVE-2026-75724 CVE-2026-75725 CVE-2026-71356 CVE-2026-75727 CVE-2026-79905 CVE-2026-27258 CVE-2025-64868 CVE-2025-64866 CVE-2026-75729 CVE-2025-64854 CVE-2026-71388 CVE-2026-75730 CVE-2026-75731 CVE-2025-64838 CVE-2026-75733 CVE-2026-75734 CVE-2026-75695 CVE-2026-75696 CVE-2026-75700 CVE-2026-75701 CVE-2026-75702 CVE-2026-75704 CVE-2026-75705 CVE-2026-75706 CVE-2026-75707 CVE-2026-75708 CVE-2026-75709 CVE-2026-75710 CVE-2026-75711 CVE-2026-75712 CVE-2026-75713 CVE-2026-75714 CVE-2026-75715 CVE-2026-75716 CVE-2026-75717 CVE-2026-75718 CVE-2026-75668 CVE-2026-75669 CVE-2026-75670 CVE-2026-75671 CVE-2026-75672 CVE-2026-75674 CVE-2026-75675 CVE-2026-75677 CVE-2026-75678 CVE-2026-75679 CVE-2026-75680 CVE-2026-75681 CVE-2026-75683 CVE-2026-75685 CVE-2026-75687 CVE-2026-75690 CVE-2026-75691 CVE-2026-75692 CVE-2026-75693 CVE-2026-75694 CVE-2026-19713 CVE-2026-75629 CVE-2026-75635 CVE-2026-75636 CVE-2026-75637 CVE-2026-75639 CVE-2026-75640 CVE-2026-75642 CVE-2026-75643 CVE-2026-75644 CVE-2026-75646 CVE-2026-75647 CVE-2026-75651 CVE-2026-75652 CVE-2026-75657 CVE-2026-75659 CVE-2026-75660 CVE-2026-75661 CVE-2026-75666 CVE-2026-75667 CVE-2026-19644 CVE-2026-19612 CVE-2026-19479 CVE-2026-72627 CVE-2026-72626 CVE-2026-71565 CVE-2026-75726 | Adobe Experience Manager | 1 Critical, 105Important, 1 Moderate | Arbitrary code execution Privilege escalation Security feature bypass |
| CVE-2026-48273 CVE-2026-75746 CVE-2026-76190 CVE-2026-75993 CVE-2026-75999 CVE-2026-75998 CVE-2026-76000 CVE-2026-76002 CVE-2026-21269 | Adobe ColdFusion | 6 Critical, 3 Important | Application denial-of-service Arbitrary code execution Arbitrary file system read Privilege escalation |
| CVE-2026-76199 CVE-2026-82007 CVE-2026-82006 CVE-2026-75631 CVE-2026-82005 CVE-2026-75863 CVE-2026-75862 CVE-2026-75771 | Adobe Photoshop | 8 Critical | Arbitrary code execution |
| CVE-2026-75991 CVE-2026-75990 CVE-2026-75992 | Adobe Illustrator | 3 Critical | Arbitrary code execution |
| CVE-2026-76191 | Adobe Animate | 1 Critical | Arbitrary code execution |
| CVE-2026-76200 CVE-2026-76201 CVE-2026-77111 CVE-2026-77109 CVE-2026-77774 CVE-2026-76202 CVE-2026-77110 CVE-2026-77108 CVE-2026-75650 | Adobe Commerce | 9 Critical | Arbitrary code execution Privilege escalation Security feature bypass |
| CVE-2026-81996 CVE-2026-81994 CVE-2026-81983 CVE-2026-79907 CVE-2026-79908 CVE-2026-79909 CVE-2026-80161 CVE-2026-81973 CVE-2026-81975 CVE-2026-81976 CVE-2026-81992 CVE-2026-81979 CVE-2026-81980 CVE-2026-81981 CVE-2026-81985 CVE-2026-81986 CVE-2026-81987 CVE-2026-81988 CVE-2026-81989 CVE-2026-81990 CVE-2026-81997 CVE-2026-81982 CVE-2026-82001 CVE-2026-80160 CVE-2026-80162 CVE-2026-81977 CVE-2026-81978 CVE-2026-81993 CVE-2026-81984 CVE-2026-81991 CVE-2026-79910 CVE-2026-80159 | Adobe Acrobat and Reader | 21 Critical, 11 Important | Application denial-of-service Arbitrary code execution Arbitrary file system read Arbitrary file system write Memory exposure Privilege escalation |
| CVE-2026-82004 | Adobe Campaign Classic | 1 Critical | Arbitrary code execution |
Cisco *
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-20274 CVE-2026-20275 CVE-2026-20276 CVE-2026-20277 CVE-2026-20278 CVE-2026-20279 CVE-2026-20280 | Cisco IOS XR Software Security Hardening Release: September 2026 | Critical | Not aware |
| CVE-2026-20212 | Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability | Critical | Not aware |
| CVE-2026-20293 | Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability | High | Yes, proof-of-concept exploit code available |
| CVE-2026-20281 | Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability | High | Not aware |
Fortinet *
Fortinet *
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-26084 | An improper access control vulnerability in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. | High | Not aware |
| CVE-2026-84393 | An improper certificate validation vulnerability in FortiOS and FortiProxyAgentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. | High | Not aware |
Ivanti *
Ivanti *
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-12744 CVE-2026-12745 CVE-2026-12651 CVE-2026-12650 CVE-2026-12648 CVE-2026-12645 CVE-2026-12646 CVE-2026-12647 | Ivanti Neurons for ITSM (Multiple CVEs) | 6 Critical, 2 High | Not aware |
| CVE-2026-18851 | Ivanti Endpoint Manager Mobile | High | Not aware |
| CVE-2026-83527 | Ivanti Sentry | High | Not aware |
Ivanti September 2026 Security Update
SAP *
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-44756 | Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing | Critical | Not aware |
| CVE-2026-58240 | Missing Authentication check in SAP NetWeaver (Message Server) | Critical | Not aware |
| CVE-2026-76969 | Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) | Critical | Not aware |
| CVE-2026-66768 | Improper Access Control in SAP NetWeaver (SAP GUI for Java) | Critical | Not aware |
| CVE-2026-58243 | Privilege Escalation vulnerability in SAP ABAP Developer Tools | High | Not aware |
| CVE-2026-76958 | XML External Entity (XXE) Vulnerability in SAP Integration Suite | High | Not aware |
| CVE-2026-76967 | Insecure Deserialization in SAP NetWeaver Business Client | High | Not aware |
| CVE-2026-66767 | Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform | High | Not aware |
| CVE-2026-2332 | CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) | High | Yes, proof-of-concept exploit code available |
SAP September 2026 Security Notes
SonicWall *
| CVE-ID(s) | Details | Severity | Exploited? |
| CVE-2026-83548, CVE-2026-83549 | SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities | Critical | Yes, actively exploited |
| CVE-2026-78327, CVE-2026-78328, CVE-2026-81939 | SonicWall NSM On-Prem Affected ByMultiple Vulnerabilities | Critical | Not aware |
SonicWall September 2026 Security Notes
Google Chrome
- Version: 151.0.7922.137/.138 (Windows and Mac), 151.0.7922.137 (Linux)
- Release Date: Tuesday, August 11, 2026
- Key Fixes: 5 high-severity security fixes (CVE-2026-19556, CVE-2026-19557, CVE-2026-19558, CVE-2026-19559, CVE-2026-19560)
* Not handled by Fortress SRM.
Threat Intelligence Trends – September 2026
The following resources are grouped by threat type / category.
AI-Enabled / Emerging Threats
Title
Short summary 1-3 sentences.
Link Read more →
Fake AI, Real Malware: Attackers Impersonating AI Brands
Sophos reports that threat actors are abusing the popularity of AI tools by creating fake websites and installers that impersonate well-known AI brands, tricking users into downloading malware. The campaign highlights how cybercriminals are leveraging AI-related interest to distribute infostealers, remote access trojans, and other malicious payloads.
Read more -> https://www.sophos.com/en-gb/blog/fake-ai-real-malware-attackers-impersonating-ai-brands
Malicious Packages Served from Unauthorized Registry Server
Coder disclosed that an unauthorized package registry server served malicious packages to some users, potentially exposing systems that automatically pulleddependencies from the affected source. The advisory details impacted versions, indicators of compromise, and remediation steps for organizations using Coder deployments.
Read more -> https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress has observed unauthorized ScreenConnect installations appearing across unrelated hosts, indicating possible worm-like propagation or widespread abuse of remote access tooling. The activity raises concerns about compromised environments and highlights the need for organizations to audit ScreenConnect deployments and investigate unexpected installations.
Read more -> https://www.huntress.com/blog/rogue-screenconnect-installations
Counterfeit Installers to System Compromise: Tracking a Deceptive Software Download Campaign
Microsoft details a malicious software distribution campaign that uses counterfeit installers and fake download sites to trick users into installing malware, leading to system compromise and follow-on attacks. The campaign demonstrates how threat actors blend social engineering with trusted software brands to gain initial access and maintain persistence.
#StopRansomware: Medusa Ransomware
CISA, the FBI, and MS-ISAC provide updated guidance on Medusa ransomware, detailing tactics, techniques, procedures (TTPs), indicators of compromise, and mitigation recommendations based on ongoing investigations. The advisory warns that Medusa operators continue to target organizations across multiple sectors using phishing, credential theft, and exploitation of vulnerable systems to gain initial access.
Read more -> https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Defending Against an Active Threat to Siemens S7 Series PLCs
CISA warns of active threat activity targeting Siemens S7 series programmable logic controllers (PLCs), which are widely used in industrial control system (ICS) environments. The advisory provides detection, mitigation, and defensive guidance for organizations operating affected Siemens equipment to reduce the risk of operational disruption or compromise.
Read more -> https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
Social Engineering & Phishing
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
Researchers observed the BigBear 2.0 phishing campaign leveraging Evilginx2 adversary-in-the-middle infrastructure to steal Microsoft 365 session cookies, allowing attackers to bypass MFA and gain unauthorized access to user accounts. The campaign highlights the continued effectiveness of cookie theft and AiTM phishing against organizations relying solely on MFA for account protection.
Read more -> https://cybersecuritynews.com/bigbear-2-0-evilginx2/
Cloud Data Theft, Extortion, Vishing, and Proxy Infrastructure Alert Pack
This alert pack appears to focus on threat activity involving cloud data theft, extortion campaigns, vishing (voice phishing), and the use of proxy infrastructure to facilitate attacks or evade detection. It is intended to help defenders understand and track these evolving tactics and associated indicators.
Read more -> https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxies
NovaCookies at Scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations
Island Research examines NovaCookies, a phishing-as-a-service platform sold for as little as $320 that enables attackers to steal authentication cookies and bypass MFA protections. The service has been used to target hundreds of organizations, highlighting the growing accessibility and effectiveness of adversary-in-the-middle phishing operations.
Read more -> https://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizations
US-First RMM Phishing Campaign: Malware Analysis ANY.RUN analyzes a phishing campaign targeting U.S. organizations that leverages remote monitoring and management (RMM) tools for initial access, social engineering, and malware delivery. The campaign demonstrates how attackers combine phishing with legitimate remote access software to evade detection and establish persistent access to victim environments.
Read more -> https://any.run/cybersecurity-blog/us-campaign-malware-analysis/
Vulnerabilities & Experts
Microsoft Exchange Servers Exposed to Mailbox Takeover Bug
Cybernews reports that thousands of Microsoft Exchange servers remain vulnerable to a flaw that could enable attackers to take over user mailboxes, potentially leading to unauthorized email access and account compromise. The exposure underscores the importance of promptly applying available security updates and auditing internet-facing Exchange deployments.
Read more -> https://cybernews.com/security/thousands-of-microsoft-exchange-servers-vulnerable/
StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack
Sansec reports that a critical remote code execution vulnerability, CVE-2026-75650, is being actively exploited against Magento and Adobe Commerce sites, allowing attackers to compromise stores and potentially gain full control of affected environments. Organizations running these platforms should review the advisory and apply mitigations immediately due to ongoing attacks. Read more -> https://sansec.io/research/stylesmuggler-0day
N-central 2026.3 Hotfix 4 – CVE-2026-86218
N-able has released N-central 2026.3 Hotfix 4 to address CVE-2026-86218, a security vulnerability affecting the N-central remote monitoring and management platform. Customers are advised to review the advisory and apply the hotfix promptly to reduce exposure to potential exploitation.
Read more -> https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
Recommended Actions
Mitigations
- Prioritize rapid patching for actively exploited and internet-facing systems, including Microsoft zero-days, Adobe Commerce/Magento, SonicWall SMA1000, Exchange, SQL Server, DNS, DHCP, Remote Desktop, and other exposed services.
- Reduce external exposure by limiting public access to administrative portals, VPN appliances, RMM platforms, web applications, and legacy remote access services.
- Treat recently exposed Adobe Commerce/Magento and SonicWall SMA1000 systems as higher risk until logs, credentials, tokens, and system integrity have been reviewed.
- Strengthen identity controls with phishing-resistant MFA where feasible, tighter Conditional Access, shorter session lifetimes, and reauthentication for risky sign-ins.
- Validate offline or immutable backups and confirm ransomware recovery procedures are tested and documented.
Monitoring
- Monitor for abnormal sign-ins, token replay behavior, impossible travel, unfamiliar devices, suspicious inbox rules, and other signs of Microsoft 365 account takeover.
- Watch for unauthorized RMM tools, unexpected administrative activity, configuration changes, new accounts, outbound callbacks, or anomalous web requests on edge devices and critical systems.
- Use vendor advisories, CISA KEV, endpoint alerts, and vulnerability management data to prioritize remediation based on exploitation activity and business exposure.
Detection Tips
- Investigate privilege escalation alerts following malware, phishing, or suspicious script activity, as these events may indicate hands-on-keyboard activity after initial access.
- For cloud and email environments, correlate sign-in, mailbox, file access, risky user, and inbox rule activity to identify possible session-cookie theft or account compromise.
- For exposed web applications and appliances, review for suspicious files, web shells, configuration changes, unexpected outbound traffic, and unauthorized administrative access.
- For ransomware risk, alert on mass file changes, unusual archive creation, credential dumping tools, suspicious PowerShell, lateral movement, and data staging or exfiltration activity.
About Fortress SRM’s Vigilant Managed Cyber Hygiene Offering
Why Patching Matters
Unpatched software is a leading cause of breaches—nearly 1 in 3 attacks exploit known vulnerabilities.
Vigilant Managed Cyber Hygiene
Fortress SRM’s Vigilant Managed Cyber Hygiene simplifies patch management.
- Automated updates with 97%+ success rate for Microsoft & 100+ third-party applications
- Critical patches, OS upgrades, and configuration updates for all devices, on/off network
- 24/7/365 U.S.-based monitoring and real-time reporting for full visibility
Stay Protected. Stay Proactive.
Learn how Fortress SRM can enhance your cybersecurity strategy

