Threat and Security Update – September, 2026

Share This Article


Stay Ahead of Threats with the Latest Vulnerability Updates for September


Stay up to date on critical cyber risks, Microsoft’s September Patch Tuesday, and other notable third-party vulnerabilities. Timely patching is key to maintaining a strong security posture and protecting your business from threats. 

Quick Highlights

  • Microsoft Patch Tuesday: 
    – 974 vulnerabilities disclosed. This month’s Patch Tuesday release marks the record for the largest number of vulnerabilities patched in one release. This is the second time in 2026 that Microsoft has exceeded its patch record, with the first being the July 2026 Patch Tuesday release. 
    – 119 rated Critical, 2 are Zero-Day (2 actively exploited) 
    Out-of-Band Patch published September 3rd patches the “ShieldBreak” exploit in MS Defender from last month 
  • Advisories from Major Vendors: 
    Adobe: 170 vulnerabilities patched across 8 products 
    Cisco2 critical-severity and 2 high-severity flaws, including [_] 
    Fortinet2 high-severity flaws in FortiSandbox and FortiOS/FortiProxy 
    Ivanti6 critical, 4 high-severity flaws in Ivanti Neurons for ITSM, Ivanti Endpoint Manager Mobile (EPMM), and Ivanti Sentry 
    SAP4 critical, 5 high-severity vulnerabilities in SAP Extended Passport (EPP) Processing, SAP NetWeaver, SAP Cloud Application Programming Model, SAP ABAP Developer Tools, SAP Integration Suite, SAP Commerce Cloud 
    SonicWall2 critical-severity vulnerabilities in SonicWall SMA1000 Series Appliances and SonicWall NSM On-Prem 
  • Top Threats to Watch: 
    Active Exploitation of Critical Internet-Facing Vulnerabilities – Attackers are actively exploiting newly disclosed flaws, including Magento/Adobe Commerce, N-able N-central, Broadcom advisories, and exposed Microsoft Exchange servers. These issues can enable remote code execution, credential theft, and persistence before organizations can patch. 
    MFA Bypass Through Adversary-in-the-Middle (AiTM) Phishing – Threat actors are increasingly using Evilginx2-style kits, NovaCookies, and BigBear 2.0 tosteal Microsoft 365 session cookies. Once captured, these tokens can bypass MFA and enable account takeover without the user’s password.
    Abuse of Legitimate Remote Access and Management Tools – Threat actors continue using trusted RMM tools for access and persistence, including rogue ScreenConnect activity and phishing campaigns leveraging legitimate remote access software. This makes malicious activity harder to distinguish from normal administration. 
    Malware Distribution Through Trusted Software and AI-Themed Lures – Attackers are using fake installers, counterfeit download sites, and impersonated AI brands to deliver malware. These campaigns increase the risk of infostealer, remote access trojan, and credential theft infections. 
    Data Theft and Extortion Operations Expanding Across Sectors – Recent ransomware, cloud data theft, and phishing activity show attackers increasingly stealing data before applying extortion pressure. This trend raises risk across sectors, even when ransomware encryption is not used. 

Windows 10 Reaches End of Support

As of October 14, 2025, Microsoft has officially ended support for Windows 10. October 2025’s Patch Tuesday was the final security update for the OS—unless your organization enrolls in the Extended Security Updates (ESU) program. 

  • What This Means for Your Organization: 
    – No more security patches or bug fixes for Windows 10 devices  
    – Increased exposure to vulnerabilities and compliance risks  
    – Continued support requires either: 1.) Enrolling in Microsoft’s paid ESU program, or 2.) Upgrading to Windows 11
  • Upgrading Windows 11  
    Unlike traditional feature upgrades, Windows 11 25H2 is built on the same servicing branch and code base as Windows 11 24H2, making the transition simpler and lower risk.  

    Fortress has thoroughly tested Windows 11 25H2 and recommends upgrading all supported devices. To begin the upgrade process, contact our 24/7/365 Security Operations Team or reach out to your client experience manager.  

Windows 11 End of Support

As of November 2025, Microsoft has officially ended support for earlier versions of Windows 11 (listed below).

  • Windows 11 version 21H2 (All Editions) 
  • Windows 11 version 22H2 (All Editions) 
  • Windows 11 version 23H2 (Home & Pro) 

We would also like to highlight several upcoming End of Support dates for the following Windows releases: 

  • Windows 11 version 23H2 (Enterprise & Education) – Support ends November 10, 2026. After this date, these editions will no longer receive security updates or fixes. 
  • Windows 11 version 24H2 (Home & Pro) – Support ends October 13, 2026. Devices running these editions should be upgraded before this date to remain supported and secure. 

Fortress recommends reviewing device inventories ahead of these deadlines to ensure systems are upgraded in advance and remain within a supported lifecycle. 

* Some specialized editions of Windows 11 24H2 (e.g. Long Term Support Cycle) will continue to receive extended support through 2029. However, for all other editions we recommend upgrading to Windows 11 25H2.  

Windows Server 2016 End of Support

Support for Windows Server 2016 is scheduled to end on January 12, 2027, which is now less than a year away. After this date, Microsoft will no longer provide security updates, bug fixes, or technical support for the platform. 

Organizations still running Windows Server 2016 should begin planning upgrade or migration strategies to avoid increased security risk and compliance concerns once support ends. 

Fortress recommends reviewing affected systems early to allow sufficient time for testing, upgrades, or workload migration before the end-of-support deadline. 

Need help planning your transition?

Fortress SRM can help assess your environment, prioritize upgrades, and ensure your endpoints remain patch-compliant and secure.

Patch Tuesday Summary

Microsoft September 2026 Patch Tuesday 
974 vulnerabilities disclosed, including 119 critical and 2 zero-days. By category:

  • 438 Elevation of Privilege 
  • 258 Remote Code Execution 
  • 173 Information Disclosure 
  • 56 Denial of Service 
  • 19 Security Feature Bypass 
  • 16 Spoofing 
  • 13 Tampering 

Critical Common Vulnerabilities and Exposures (CVEs)

Windows Zero Days

CVE-ID Details Severity Exploited? 
CVE-2026-81963 Windows Update Stack elevation of privilege vulnerability Important Yes, actively exploited 
CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability Important Yes, actively exploited 

Other Critical CVE’s Worth Mentioning

CVE-ID Details Severity Exploited? 
CVE-2026-70352 Azure AI Language elevation of privilege vulnerability Critical Not aware 
CVE-2026-69857 Azure Cosmos DB spoofing vulnerability Critical Not aware 
CVE-2026-80098 Copilot Studio elevation of privilege vulnerability Critical Not aware 
CVE-2026-83941 Entra ID elevation of privilege vulnerability Critical Not aware 
CVE-2026-72986, CVE-2026-73018 Graphic Fonts remote code execution vulnerability Critical Not aware 
CVE-2026-72981 IP Helper remote code execution vulnerability Critical Not aware 
CVE-2026-85507 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). Critical Not aware 
CVE-2026-85508 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). Critical Not aware 
CVE-2026-85509 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. Critical Not aware 
CVE-2026-85506 ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). Critical Not aware 
CVE-2026-85504 FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_textin libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. Critical Not aware 
CVE-2026-34182 CMS AuthEnvelopedData processing may accept forged messages Critical Not aware 
CVE-2026-83711 Microsoft Azure Active Directory B2C elevation of privilege vulnerability Critical Not aware 
CVE-2026-62906 Microsoft Discovery Studio information disclosure vulnerability Critical Not aware 
CVE-2026-65772 Microsoft Dynamics 365 On-Premises remote code execution vulnerability Critical Not aware 
CVE-2026-62916 Microsoft Entra ID elevation of privilege vulnerability Critical Not aware 
CVE-2026-70178 Microsoft Fabric elevation of privilege vulnerability Critical Not aware 
CVE-2026-78439 Microsoft Office Graphics Component remote code execution vulnerability Critical Not aware 
CVE-2026-81955, CVE-2026-77493 Windows Graphics Component remote code execution vulnerability Critical Not aware 
CVE-2026-73006 DirectWrite remote code execution vulnerability Critical Not aware 
CVE-2026-69285, CVE-2026-78505, CVE-2026-77898, CVE-2026-69632 Microsoft Office remote code execution vulnerability Critical Not aware 
CVE-2026-81949, CVE-2026-81948, CVE-2026-81950, CVE-2026-81959, CVE-2026-81953, CVE-2026-81951 Microsoft Excel remote code execution vulnerability Critical Not aware 
CVE-2026-78509, CVE-2026-78525, CVE-2026-78519 Microsoft Office Outlook remote code execution vulnerability Critical Not aware 
CVE-2026-78520 Microsoft Office Outlook information disclosure vulnerability Critical Not aware 
CVE-2026-69678, CVE-2026-69797, CVE-2026-69767 Microsoft Office PowerPoint remote code execution vulnerability Critical Not aware 
CVE-2026-78510, CVE-2026-81952 Microsoft Word remote code execution vulnerability Critical Not aware 
CVE-2026-77504 Microsoft Office Word remote code execution vulnerability Critical Not aware 
CVE-2026-70351 Microsoft WebP Image Extension remote code execution vulnerability Critical Not aware 
CVE-2026-81352 Web Media Extensions remote code execution vulnerability Critical Not aware 
CVE-2026-58599 HEVC Video Extensions remote code execution vulnerability Critical Not aware 
CVE-2026-69601 Microsoft Windows Media Foundation remote code execution vulnerability Critical Not aware 
CVE-2026-65818 Power Automate elevation of privilege vulnerability Critical Not aware 
CVE-2026-78449, CVE-2026-78450, CVE-2026-69530 Windows Reliable Multicast Transport Driver (RMCAST) remote code execution vulnerability Critical Not aware 
CVE-2026-69827, CVE-2026-77505, CVE-2026-69858, CVE-2026-69813, CVE-2026-69730 Windows DNS Server remote code execution vulnerability Critical Not aware 
CVE-2026-66302 Skype for Business remote code execution vulnerability Critical Not aware 
CVE-2026-69854 Spring Cloud Azure elevation of privilege vulnerability Critical Not aware 
CVE-2026-67378, CVE-2026-67631, CVE-2026-67643, CVE-2026-67636 Microsoft SQL Server remote code execution vulnerability Critical Not aware 
CVE-2026-65669 Microsoft SQL Server elevation of privilege vulnerability Critical Not aware 
CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver remote code execution vulnerability Critical Not aware 
CVE-2026-69874 Windows ALPC elevation of privilege vulnerability Critical Not aware 
CVE-2026-72958 Windows Credential Guard elevation of privilege vulnerability Critical Not aware 
CVE-2026-72954, CVE-2026-72957 Windows Deployment Services remote code execution vulnerability Critical Not aware 
CVE-2026-72979, CVE-2026-69845 Windows DHCP Server remote code execution vulnerability Critical Not aware 
CVE-2026-72987 Windows DNS remote code execution vulnerability Critical Not aware 
CVE-2026-73010, CVE-2026-78444 Microsoft Failover Cluster remote code execution vulnerability Critical Not aware 
CVE-2026-73017 Graphics Kernel remote code execution vulnerability Critical Not aware 
CVE-2026-69784, CVE-2026-81354, CVE-2026-69740, CVE-2026-69799, CVE-2026-69820, CVE-2026-69864, CVE-2026-69710, CVE-2026-69725 Windows Hello elevation of privilege vulnerability Critical Not aware 
CVE-2026-72980 Windows Hello security feature bypass vulnerability Critical Not aware 
CVE-2026-69769 Windows HTTP Print Provider remote code execution vulnerability Critical Not aware 
CVE-2026-72961 Windows Hyper-V elevation of privilege vulnerability Critical Not aware 
CVE-2026-69603, CVE-2026-80083 Windows Hyper-V remote code execution vulnerability Critical Not aware 
CVE-2026-73023, CVE-2026-77495, CVE-2026-73013, CVE-2026-70296, CVE-2026-69860, CVE-2026-69499 Windows Imaging Component remote code execution vulnerability Critical Not aware 
CVE-2026-72983 Internet Connection Sharing (ICS) remote code execution vulnerability Critical Not aware 
CVE-2026-69676 Windows Kerberos remote code execution vulnerability Critical Not aware 
CVE-2026-69712 Windows Key Distribution Center remote code execution vulnerability Critical Not aware 
CVE-2026-70203, CVE-2026-72960 Windows Media Player remote code execution vulnerability Critical Not aware 
CVE-2026-69579 Windows Message Queuing remote code execution vulnerability Critical Not aware 
CVE-2026-72982 Windows Netlogon remote code execution vulnerability Critical Not aware 
CVE-2026-70586 Windows Paint remote code execution vulnerability Critical Not aware 
CVE-2026-69649 Raw Image Extension remote code execution vulnerability Critical Not aware 
CVE-2026-69518 Windows Remote Desktop remote code execution vulnerability Critical Not aware 
CVE-2026-72959, CVE-2026-69590, CVE-2026-69852, CVE-2026-72950 Windows Routing and Remote Access Service (RRAS) remote code execution vulnerability Critical Not aware 
CVE-2026-69501, CVE-2026-83939, CVE-2026-69846, CVE-2026-69906 Windows Secure Kernel Mode elevation of privilege vulnerability Critical Not aware 
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) remote code execution vulnerability Critical Not aware 
CVE-2026-69595, CVE-2026-70585, CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver remote code execution vulnerability Critical Not aware 
CVE-2026-69829 Windows Shell remote code execution vulnerability Critical Not aware 
CVE-2026-72962 Windows USB Video Driver elevation of privilege vulnerability Critical Not aware 
CVE-2026-69890 Windows Virtual Trusted Platform Module elevation of privilege vulnerability Critical Not aware 
CVE-2026-83501 Windows Virtualization-Based Security (VBS) information disclosure vulnerability Critical Not aware 
CVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave elevation of privilege vulnerability Critical Not aware 
CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability – A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. Important Not aware 

Microsoft September 2026 Security Update Release

3rd Party Critical CVE’s Worth Mentioning

Adobe Products *

CVE-ID(s) Affected Product Issues Key Risks 
CVE-2026-19232 CVE-2025-64830 CVE-2026-75735 CVE-2026-27238 CVE-2026-75736 CVE-2026-75737 CVE-2026-75738 CVE-2026-71440 CVE-2026-27227 CVE-2026-75739 CVE-2025-64618 CVE-2025-64610 CVE-2026-75740 CVE-2026-75741 CVE-2025-64589 CVE-2025-64588 CVE-2026-75742 CVE-2025-64584 CVE-2026-27222 CVE-2026-71357 CVE-2025-64542 CVE-2026-75719 CVE-2026-75720 CVE-2026-75722 CVE-2026-75724 CVE-2026-75725 CVE-2026-71356 CVE-2026-75727 CVE-2026-79905 CVE-2026-27258 CVE-2025-64868 CVE-2025-64866 CVE-2026-75729 CVE-2025-64854 CVE-2026-71388 CVE-2026-75730 CVE-2026-75731 CVE-2025-64838 CVE-2026-75733 CVE-2026-75734 CVE-2026-75695 CVE-2026-75696 CVE-2026-75700 CVE-2026-75701 CVE-2026-75702 CVE-2026-75704 CVE-2026-75705 CVE-2026-75706 CVE-2026-75707 CVE-2026-75708 CVE-2026-75709 CVE-2026-75710 CVE-2026-75711 CVE-2026-75712 CVE-2026-75713 CVE-2026-75714 CVE-2026-75715 CVE-2026-75716 CVE-2026-75717 CVE-2026-75718 CVE-2026-75668 CVE-2026-75669 CVE-2026-75670 CVE-2026-75671 CVE-2026-75672 CVE-2026-75674 CVE-2026-75675 CVE-2026-75677 CVE-2026-75678 CVE-2026-75679 CVE-2026-75680 CVE-2026-75681 CVE-2026-75683 CVE-2026-75685 CVE-2026-75687 CVE-2026-75690 CVE-2026-75691 CVE-2026-75692 CVE-2026-75693 CVE-2026-75694 CVE-2026-19713 CVE-2026-75629 CVE-2026-75635 CVE-2026-75636 CVE-2026-75637 CVE-2026-75639 CVE-2026-75640 CVE-2026-75642 CVE-2026-75643 CVE-2026-75644 CVE-2026-75646 CVE-2026-75647 CVE-2026-75651 CVE-2026-75652 CVE-2026-75657 CVE-2026-75659 CVE-2026-75660 CVE-2026-75661 CVE-2026-75666 CVE-2026-75667 CVE-2026-19644 CVE-2026-19612 CVE-2026-19479 CVE-2026-72627 CVE-2026-72626 CVE-2026-71565 CVE-2026-75726 Adobe Experience Manager 1 Critical, 105Important, 1 Moderate Arbitrary code execution Privilege escalation Security feature bypass 
CVE-2026-48273 CVE-2026-75746 CVE-2026-76190 CVE-2026-75993 CVE-2026-75999 CVE-2026-75998 CVE-2026-76000 CVE-2026-76002 CVE-2026-21269 Adobe ColdFusion 6 Critical, 3 Important Application denial-of-service Arbitrary code execution Arbitrary file system read Privilege escalation 
CVE-2026-76199 CVE-2026-82007 CVE-2026-82006 CVE-2026-75631 CVE-2026-82005 CVE-2026-75863 CVE-2026-75862 CVE-2026-75771 Adobe Photoshop 8 Critical Arbitrary code execution  
CVE-2026-75991 CVE-2026-75990 CVE-2026-75992 Adobe Illustrator 3 Critical Arbitrary code execution 
CVE-2026-76191 Adobe Animate 1 Critical Arbitrary code execution 
CVE-2026-76200 CVE-2026-76201 CVE-2026-77111 CVE-2026-77109 CVE-2026-77774 CVE-2026-76202 CVE-2026-77110 CVE-2026-77108 CVE-2026-75650 Adobe Commerce 9 Critical Arbitrary code execution Privilege escalation Security feature bypass 
CVE-2026-81996 CVE-2026-81994 CVE-2026-81983 CVE-2026-79907 CVE-2026-79908 CVE-2026-79909 CVE-2026-80161 CVE-2026-81973 CVE-2026-81975 CVE-2026-81976 CVE-2026-81992 CVE-2026-81979 CVE-2026-81980 CVE-2026-81981 CVE-2026-81985 CVE-2026-81986 CVE-2026-81987 CVE-2026-81988 CVE-2026-81989 CVE-2026-81990 CVE-2026-81997 CVE-2026-81982 CVE-2026-82001 CVE-2026-80160 CVE-2026-80162 CVE-2026-81977 CVE-2026-81978 CVE-2026-81993 CVE-2026-81984 CVE-2026-81991 CVE-2026-79910 CVE-2026-80159 Adobe Acrobat and Reader 21 Critical, 11 Important Application denial-of-service Arbitrary code execution Arbitrary file system read Arbitrary file system write Memory exposure Privilege escalation 
CVE-2026-82004 Adobe Campaign Classic 1 Critical Arbitrary code execution 

Adobe Security Bulletins

Cisco *

CVE-ID(s) Details Severity Exploited? 
CVE-2026-20274 CVE-2026-20275 CVE-2026-20276 CVE-2026-20277 CVE-2026-20278 CVE-2026-20279 CVE-2026-20280 Cisco IOS XR Software Security Hardening Release: September 2026 Critical Not aware 
CVE-2026-20212 Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability Critical Not aware 
CVE-2026-20293 Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability High Yes, proof-of-concept exploit code available 
CVE-2026-20281 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability High Not aware 

Cisco Security Advisories

Fortinet *

Fortinet * 

CVE-ID(s) Details Severity Exploited? 
CVE-2026-26084 An improper access control vulnerability in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. High Not aware 
CVE-2026-84393 An improper certificate validation vulnerability in FortiOS and FortiProxyAgentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. High Not aware 

Fortinet PSIRT Advisories

Ivanti *

Ivanti * 

CVE-ID(s) Details Severity Exploited? 
CVE-2026-12744  CVE-2026-12745  CVE-2026-12651  CVE-2026-12650  CVE-2026-12648  CVE-2026-12645  CVE-2026-12646  CVE-2026-12647  Ivanti Neurons for ITSM (Multiple CVEs) 6 Critical, 2 High Not aware 
CVE-2026-18851 Ivanti Endpoint Manager Mobile High Not aware 
CVE-2026-83527 Ivanti Sentry High Not aware 

Ivanti September 2026 Security Update

SAP *

CVE-ID(s) Details Severity Exploited? 
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing Critical Not aware 
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) Critical Not aware 
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) Critical Not aware 
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) Critical Not aware 
CVE-2026-58243 Privilege Escalation vulnerability in SAP ABAP Developer Tools High Not aware 
CVE-2026-76958 XML External Entity (XXE) Vulnerability in SAP Integration Suite High Not aware 
CVE-2026-76967 Insecure Deserialization in SAP NetWeaver Business Client High Not aware 
CVE-2026-66767 Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform High Not aware 
CVE-2026-2332 CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) High Yes, proof-of-concept exploit code available 

SAP September 2026 Security Notes

SonicWall * 

CVE-ID(s) Details Severity Exploited? 
CVE-2026-83548, CVE-2026-83549 SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities Critical Yes, actively exploited 
CVE-2026-78327, CVE-2026-78328, CVE-2026-81939 SonicWall NSM On-Prem Affected ByMultiple Vulnerabilities Critical Not aware 

SonicWall September 2026 Security Notes

Google Chrome 

  • Version: 151.0.7922.137/.138 (Windows and Mac), 151.0.7922.137 (Linux) 
  • Release Date: Tuesday, August 11, 2026 
  • Key Fixes: 5 high-severity security fixes (CVE-2026-19556, CVE-2026-19557, CVE-2026-19558, CVE-2026-19559, CVE-2026-19560) 

Chrome Release Notes

* Not handled by Fortress SRM. 

Threat Intelligence Trends – September 2026

The following resources are grouped by threat type / category. 

AI-Enabled / Emerging Threats

Title 

Short summary 1-3 sentences. 

Link Read more →  

Fake AI, Real Malware: Attackers Impersonating AI Brands  

Sophos reports that threat actors are abusing the popularity of AI tools by creating fake websites and installers that impersonate well-known AI brands, tricking users into downloading malware. The campaign highlights how cybercriminals are leveraging AI-related interest to distribute infostealers, remote access trojans, and other malicious payloads. 

Read more -> https://www.sophos.com/en-gb/blog/fake-ai-real-malware-attackers-impersonating-ai-brands 

Malicious Packages Served from Unauthorized Registry Server  

Coder disclosed that an unauthorized package registry server served malicious packages to some users, potentially exposing systems that automatically pulleddependencies from the affected source. The advisory details impacted versions, indicators of compromise, and remediation steps for organizations using Coder deployments.  

Read more -> https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65 

Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress has observed unauthorized ScreenConnect installations appearing across unrelated hosts, indicating possible worm-like propagation or widespread abuse of remote access tooling. The activity raises concerns about compromised environments and highlights the need for organizations to audit ScreenConnect deployments and investigate unexpected installations. 

Read more -> https://www.huntress.com/blog/rogue-screenconnect-installations 

Counterfeit Installers to System Compromise: Tracking a Deceptive Software Download Campaign  

Microsoft details a malicious software distribution campaign that uses counterfeit installers and fake download sites to trick users into installing malware, leading to system compromise and follow-on attacks. The campaign demonstrates how threat actors blend social engineering with trusted software brands to gain initial access and maintain persistence. 

Read more -> https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/ 

#StopRansomware: Medusa Ransomware  

CISA, the FBI, and MS-ISAC provide updated guidance on Medusa ransomware, detailing tactics, techniques, procedures (TTPs), indicators of compromise, and mitigation recommendations based on ongoing investigations. The advisory warns that Medusa operators continue to target organizations across multiple sectors using phishing, credential theft, and exploitation of vulnerable systems to gain initial access. 

Read more -> https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a 

Defending Against an Active Threat to Siemens S7 Series PLCs  

CISA warns of active threat activity targeting Siemens S7 series programmable logic controllers (PLCs), which are widely used in industrial control system (ICS) environments. The advisory provides detection, mitigation, and defensive guidance for organizations operating affected Siemens equipment to reduce the risk of operational disruption or compromise. 

Read more -> https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a 

Social Engineering & Phishing

BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft  

Researchers observed the BigBear 2.0 phishing campaign leveraging Evilginx2 adversary-in-the-middle infrastructure to steal Microsoft 365 session cookies, allowing attackers to bypass MFA and gain unauthorized access to user accounts. The campaign highlights the continued effectiveness of cookie theft and AiTM phishing against organizations relying solely on MFA for account protection. 

Read more -> https://cybersecuritynews.com/bigbear-2-0-evilginx2/

Cloud Data Theft, Extortion, Vishing, and Proxy Infrastructure Alert Pack  

This alert pack appears to focus on threat activity involving cloud data theft, extortion campaigns, vishing (voice phishing), and the use of proxy infrastructure to facilitate attacks or evade detection. It is intended to help defenders understand and track these evolving tactics and associated indicators.  

Read more -> https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxies 

NovaCookies at Scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations  

Island Research examines NovaCookies, a phishing-as-a-service platform sold for as little as $320 that enables attackers to steal authentication cookies and bypass MFA protections. The service has been used to target hundreds of organizations, highlighting the growing accessibility and effectiveness of adversary-in-the-middle phishing operations. 

Read more -> https://www.island.io/blog/novacookies-at-scale-inside-the-320-phishing-service-targeting-hundreds-of-organizations 

US-First RMM Phishing Campaign: Malware Analysis ANY.RUN analyzes a phishing campaign targeting U.S. organizations that leverages remote monitoring and management (RMM) tools for initial access, social engineering, and malware delivery. The campaign demonstrates how attackers combine phishing with legitimate remote access software to evade detection and establish persistent access to victim environments. 

Read more -> https://any.run/cybersecurity-blog/us-campaign-malware-analysis/ 

Vulnerabilities & Experts

Microsoft Exchange Servers Exposed to Mailbox Takeover Bug  

Cybernews reports that thousands of Microsoft Exchange servers remain vulnerable to a flaw that could enable attackers to take over user mailboxes, potentially leading to unauthorized email access and account compromise. The exposure underscores the importance of promptly applying available security updates and auditing internet-facing Exchange deployments. 

Read more -> https://cybernews.com/security/thousands-of-microsoft-exchange-servers-vulnerable/ 

StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack  

Sansec reports that a critical remote code execution vulnerability, CVE-2026-75650, is being actively exploited against Magento and Adobe Commerce sites, allowing attackers to compromise stores and potentially gain full control of affected environments. Organizations running these platforms should review the advisory and apply mitigations immediately due to ongoing attacks. Read more -> https://sansec.io/research/stylesmuggler-0day 

N-central 2026.3 Hotfix 4 – CVE-2026-86218  

N-able has released N-central 2026.3 Hotfix 4 to address CVE-2026-86218, a security vulnerability affecting the N-central remote monitoring and management platform. Customers are advised to review the advisory and apply the hotfix promptly to reduce exposure to potential exploitation. 

Read more -> https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/ 

Recommended Actions

Mitigations

  • Prioritize rapid patching for actively exploited and internet-facing systems, including Microsoft zero-days, Adobe Commerce/Magento, SonicWall SMA1000, Exchange, SQL Server, DNS, DHCP, Remote Desktop, and other exposed services. 
  • Reduce external exposure by limiting public access to administrative portals, VPN appliances, RMM platforms, web applications, and legacy remote access services. 
  • Treat recently exposed Adobe Commerce/Magento and SonicWall SMA1000 systems as higher risk until logs, credentials, tokens, and system integrity have been reviewed. 
  • Strengthen identity controls with phishing-resistant MFA where feasible, tighter Conditional Access, shorter session lifetimes, and reauthentication for risky sign-ins. 
  • Validate offline or immutable backups and confirm ransomware recovery procedures are tested and documented. 

Monitoring

  • Monitor for abnormal sign-ins, token replay behavior, impossible travel, unfamiliar devices, suspicious inbox rules, and other signs of Microsoft 365 account takeover. 
  • Watch for unauthorized RMM tools, unexpected administrative activity, configuration changes, new accounts, outbound callbacks, or anomalous web requests on edge devices and critical systems. 
  • Use vendor advisories, CISA KEV, endpoint alerts, and vulnerability management data to prioritize remediation based on exploitation activity and business exposure. 

Detection Tips

  • Investigate privilege escalation alerts following malware, phishing, or suspicious script activity, as these events may indicate hands-on-keyboard activity after initial access. 
  • For cloud and email environments, correlate sign-in, mailbox, file access, risky user, and inbox rule activity to identify possible session-cookie theft or account compromise. 
  • For exposed web applications and appliances, review for suspicious files, web shells, configuration changes, unexpected outbound traffic, and unauthorized administrative access. 
  • For ransomware risk, alert on mass file changes, unusual archive creation, credential dumping tools, suspicious PowerShell, lateral movement, and data staging or exfiltration activity. 

About Fortress SRM’s Vigilant Managed Cyber Hygiene Offering 

Why Patching Matters

Unpatched software is a leading cause of breaches—nearly 1 in 3 attacks exploit known vulnerabilities. 

Vigilant Managed Cyber Hygiene

 Fortress SRM’s Vigilant Managed Cyber Hygiene simplifies patch management. 

  • Automated updates with 97%+ success rate for Microsoft & 100+ third-party applications 
  • Critical patches, OS upgrades, and configuration updates for all devices, on/off network 
  • 24/7/365 U.S.-based monitoring and real-time reporting for full visibility 

Stay Protected. Stay Proactive.

Learn how Fortress SRM can enhance your cybersecurity strategy