“Pull Entra sign-in logs for the last 48 hours on every M365 tenant and look for anomalous authentication patterns or flagged risky sign-ins; simultaneously queue the two Windows zero-day patches for this week's change windows.”
Microsoft Entra ID Auth Bypass (CVE-2026-62916, CVSS 9.1) — Server-Side Fix Applied, Audit Logs Required
A critical authentication bypass in Microsoft Entra ID (CVE-2026-62916, CVSS 9.1) allowed attackers to take an alternate authentication path without credentials; the exploitation window was open for several weeks before Microsoft deployed a server-side fix, meaning no Windows Update is required but immediate audit action is. Admins should review Entra ID sign-in and PIM logs from August 21 through September 3 for unexplained privilege escalations, and check Copilot Studio maker portals and Microsoft Fabric workspace permissions for unauthorised changes. No customer-side patch is needed, but the pre-fix exploitation window makes log review urgent.
Read more →AI Platform Triple-Outage: Anthropic, OpenAI, and xAI Down Simultaneously on September 3
On September 3, Anthropic, xAI, and OpenAI all reported separate model incidents within roughly 90 minutes of each other, causing cascading degradation in downstream AI coding tools including Cursor and GitHub Copilot. All incidents resolved Thursday afternoon, but the simultaneous failures highlight the concentration risk of MSPs and helpdesks relying on cloud-hosted LLM providers without fallback options. MSPs should review their AI tooling dependencies and consider local or multi-provider redundancy strategies.
Read more →Patch Tuesday September 2026: Record ~973 CVEs Fixed, Two Windows Zero-Days Actively Exploited
Microsoft's September 2026 Patch Tuesday — its largest ever — fixes approximately 973 CVEs across Windows, Office, SQL Server, Exchange, and developer tools, including two elevation-of-privilege zero-days already exploited in the wild: CVE-2026-85880 (Windows ALPC heap buffer overflow) and CVE-2026-81963 (Windows Update Stack link-following flaw), both CVSS 7.8. Additionally, 20 vulnerabilities are flagged as potentially wormable (RCE without authentication or user interaction), and critical RCE flaws land in DNS, Remote Desktop Services, Exchange Server, and SharePoint. Deploy KB5122871 and KB5122876 immediately; no workaround exists for the exploited EoP flaws — patching is the only reliable fix.
Read more →CVE-2026-85880 (Windows ALPC) — Sandbox Escape to SYSTEM Privileges, Actively Exploited
CVE-2026-85880 is a heap buffer overflow in the Windows Advanced Local Procedure Call component allowing a low-privilege AppContainer process to escape its sandbox and gain SYSTEM-level privileges with no additional user interaction required. It is confirmed as actively exploited in the wild and was privately weaponised before public disclosure, meeting the strict zero-day definition. No workaround is available; apply the September 2026 cumulative update (KB5122871 / KB5122876) within 24 hours.
Read more →September 2026 Patch Tuesday: Wormable RCE in Exchange, RDS, DNS, SharePoint — 113 Critical CVEs
Beyond the two exploited zero-days, this month's update flags CVE-2026-55007 (RCE in Exchange Server), CVE-2026-69525 (RCE in Remote Desktop Services), CVE-2026-69465 (RCE in SharePoint), and a DNS RCE among the 113 Critical-rated issues — several of which ZDI's Dustin Childs classifies as wormable due to no-authentication, no-interaction exploitation paths. Windows Server 2012 and Exchange 2016 are approaching end-of-life, making migration urgent for organisations still running these versions. Prioritise ring-0 testing and rapid deployment; Exploit Wednesday reverse-engineering typically begins within hours of Patch Tuesday.
Read more →AI 'Patch Apocalypse' Trend: September 2026 Sees Largest Patch Tuesday Ever, Driven by AI-Assisted Vulnerability Discovery
Security researchers are coining the term 'Patch Apocalypse' to describe a sharp acceleration in Microsoft vulnerability disclosures: July saw 621 fixes, August 421, and September nearly doubled August with ~973 CVEs — the largest month-over-month jump in Patch Tuesday history. The acceleration is attributed to AI-assisted vulnerability discovery tooling enabling researchers and threat actors alike to find flaws faster than ever before. MSPs need to reassess their patch deployment cadence and ring structures given that monthly patch loads are now approaching four figures.
Read more →Kaseya 2026 Survey: 55% of MSPs Have Automated Only ~25% of Their Workload — AI Gap Widens
Kaseya's 2026 MSP benchmark survey found that 55% of MSPs have automated only about a quarter of their workload, with just 1% approaching full automation, despite 48% of clients wanting AI-enabled services and 67% of MSPs now selling AI-related offerings. The gap between client demand and MSP delivery is identified as a strategic positioning problem rather than a tooling shortage — every major automation platform (Rewst, Atera, NinjaOne, ConnectWise, SuperOps) is commercially available now. MSPs that focused AI on one high-volume pain point (patch management, tier-1 ticket routing) report up to 320% ROI within 18 months.
Read more →ASIC Chair Outlines New Regulatory Strategy Weighing Impact on Small Business — MSP Compliance Implications
ASIC Chair Sarah Court's September 4 opening statement to the Parliamentary Joint Committee introduced a new Statement of Expectations requiring ASIC to weigh regulatory impact on small businesses and new entrants alongside five priorities in its Corporate Plan 2026–27. This signals a potential recalibration of compliance obligations affecting SMBs and their MSPs across financial services sectors. Australian MSPs servicing financial services clients should monitor ASIC's Corporate Plan 2026–27 for compliance deadline changes relevant to data handling, cyber resilience, and incident reporting obligations.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.