Wednesday, September 9, 2026
Daily digest
Microsoft's September Patch Tuesday dominates today's news with a record-breaking 974 CVEs — the largest single patch release in company history — including two actively exploited Windows zero-days. Combined with a Defender zero-day patch bypass and multiple other actively exploited flaws (Chrome, N-able, F5), this is a heavy patch-and-triage day.
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft's September Patch Tuesday addressed 974 vulnerabilities — the largest batch ever released — spanning 723 Windows flaws, 111 in Office, 62 in SQL, and 22 in Developer Tools. Two vulnerabilities are confirmed actively exploited in the wild, and over 110 are rated critical.
Why it matters: This is an unprecedented patch volume for an Intune-managed Windows 11 fleet — prioritize the two actively exploited CVEs and the critical RCEs (Skype for Business, MSMQ, RRAS) immediately, and expect testing/deployment strain given CMMC patch-management (SI/CM control) expectations.
New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
A researcher published a proof-of-concept for a new Microsoft Defender zero-day, codenamed ShieldCrash, which bypasses Microsoft's patch for the previously disclosed ShieldBreak flaw (CVE-2026-69414). The bypass allows an attacker to escalate to SYSTEM privileges, and the researcher says Microsoft has not fully fixed the underlying issue.
Why it matters: Defender is the primary endpoint control on this reader's Intune-managed Windows 11 fleet — an unpatched privilege-escalation bypass in the AV/EDR itself undermines a core NIST 800-171 control and warrants close monitoring for Microsoft's next fix.
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google patched 230 vulnerabilities in Chrome, including CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine that is being actively exploited. This is the seventh Chrome zero-day patched this year.
Why it matters: Chrome is a common browser on Intune-managed endpoints; push the update via managed browser policy promptly given active exploitation.
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CISA added CVE-2026-86218, a maximum-severity pre-authentication RCE in N-able N-central, to its Known Exploited Vulnerabilities catalog. Federal civilian agencies are required to patch by September 11, 2026.
Why it matters: If N-central or similar RMM tooling is used anywhere in the environment or by an MSP with access to this network, treat this as a KEV-mandated emergency patch under CMMC vulnerability management timelines.
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Sophos published analysis of malware tied to breaches of F5 BIG-IP Access Policy Manager appliances that injects a PHP web shell directly into memory when Apache loads legitimate BIG-IP scripts, allowing it to evade disk-based file integrity scans. Three specific BIG-IP APM scripts are targeted.
Why it matters: BIG-IP appliances are widely deployed at the network edge in government and defense environments; if this or similar F5 gear is in use, disk-based scanning alone won't detect this implant — memory forensics or vendor IOC checks are needed.
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP released updates fixing multiple vulnerabilities including CVE-2026-44756, a maximum-severity memory corruption flaw in SAP Extended Passport (EPP) Processing that allows unauthenticated remote code execution.
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Check Point Research demonstrated that a single hidden instruction planted in a ChatGPT conversation could cause the assistant to covertly read data from a user's connected Gmail account and exfiltrate it to a second attacker-controlled ChatGPT account, all while appearing to respond normally.
Why it matters: Any use of ChatGPT or similar assistants with connected mailboxes/data sources in this environment should be reviewed against prompt-injection risk before allowing account/data connectors, particularly relevant to a self-hosted AI stack's threat model.
Intelligence Agencies Warn of China's Large-Scale AI Model Distillation Efforts
US cybersecurity and intelligence agencies issued a joint statement accusing China-based AI companies — including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI — of systematically extracting proprietary capabilities from American frontier models (Claude, GPT, Gemini, Grok) through industrial-scale distillation attacks.
Why it matters: Reinforces the case for restricting or vetting Chinese-origin open-weight models (e.g., DeepSeek derivatives) in any self-hosted AI stack touching CUI, given the government's framing of these as a national-security supply-chain concern.
CBP Begins IT Access Control Overhaul After Watchdog Finds Vulnerabilities
Customs and Border Protection is overhauling its IT access controls after a DHS Office of Inspector General report found the agency failed to properly secure systems and information.
Why it matters: A useful benchmark example of access-control failures cited by an IG report — worth reviewing against your own AC family controls (NIST 800-171 3.1.x) as a reminder of what auditors flag.
Navy Moves Sailors' Personnel Records From Aging Data Center to Cloud
The Navy migrated sailors' personnel files and more than 50 applications that use that data from the Millington data center to a cloud environment.
Switzerland Tests a FOSS Escape Route From Microsoft 365
The Swiss Army is piloting open-source alternatives to Microsoft 365 and other American cloud applications as part of a broader push toward digital sovereignty.
Over 36,000 Exposed Plex Servers Vulnerable to Recent Flaws
More than 36,000 internet-exposed Plex Media Server instances remain unpatched against recently disclosed vulnerabilities, leaving them open to exploitation.