“Update your incident status page now and send M365 clients a preemptive outage notification — don't wait for them to call.”
Major M365 Outage: Exchange Online, Teams, SharePoint, Copilot & Defender XDR All Affected
A core authentication misconfiguration in Microsoft 365 triggered a widespread outage beginning around 1 September 2026, taking down Outlook, Teams, SharePoint, Copilot, Defender XDR, Universal Print, and the M365 Admin Center simultaneously. Microsoft tracked the Exchange Online component under incident ID EX1464935 and confirmed gradual recovery in progress, with extended monitoring in place. No workaround was published; affected users should monitor the M365 Service Health Dashboard and consider out-of-band comms (phone/SMS) for critical client alerts during future incidents.
Read more →Xbox Live, Microsoft Store & Minecraft Also Hit in Ongoing September 2 Outage Wave
On 2 September 2026, a second wave of disruptions was reported affecting Xbox Live, Outlook, Microsoft 365, Microsoft Store, and Minecraft simultaneously — suggesting a continuing or related infrastructure issue. The CyberSec Guru reported Microsoft was still actively working incidents EX1464935 and MO1465074 as of that date. MSPs should check Service Health Dashboard proactively and have documented client communication plans ready for ongoing instability.
Read more →CISA KEV Update: Six New Exploited Flaws Added Including Citrix NetScaler and SQL Server — September 9 Deadline
CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including a high-severity Citrix NetScaler ADC/Gateway bug linked to observed web shell deployments, and a remote code execution flaw in Microsoft SQL Server (CVE-2019-1068). Federal agencies face a remediation deadline of September 9, 2026 for most of the newly added CVEs. MSPs managing government or critical infrastructure clients should treat September 9 as an urgent patching deadline.
Read more →ShieldBreak (CVE-2026-69414): Unpatched Defender Privilege Escalation Bypass — PoC Public, No Fix Yet
A researcher disclosed CVE-2026-69414 ('ShieldBreak'), an elevation-of-privilege bypass in the Microsoft Malware Protection Engine that sidesteps Microsoft's earlier July 2026 fix for the related 'RoguePlanet' flaw. PoC exploit code is publicly available and Microsoft rates exploitation as 'more likely', yet no official patch has been released as of late August 2026. Workaround: Prevent untrusted code execution via AppLocker or Windows Defender Application Control; monitor for Microsoft out-of-band update.
Read more →Flamingo Raises $4.5M to Deploy Agentic AI Platform for MSPs — Consolidates 19 IT/Security Tool Categories
Miami-based startup Flamingo announced a $4.5 million seed round led by Vertex Ventures (total funding $6.7M) to build OpenFrame, an open infrastructure platform that combines IT and security tooling while placing AI agents in the operating layer. The company claims OpenFrame can consolidate up to 19 IT and security product categories, directly targeting MSP tool sprawl. This is one to watch for MSPs exploring stack consolidation alongside AI-driven automation in H2 2026.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.