“Cross-reference your client estate against CISA's 1,311 actively exploited CVE list today — prioritize any matches that appear in your Windows, Cisco, Citrix, or Fortinet environments for this week's patch cycle.”
Microsoft 365 Multi-Day Auth Outage Resolved After 67 Hours (EX1464935 / MO1465074)
A core authentication misconfiguration starting 31 August 2026 took down Exchange Online, Teams, SharePoint, OneDrive, Copilot, Defender XDR, Purview, and the M365 Admin Center for nearly 67 hours, resolving 3 September. Microsoft's status page confirmed the root cause was a 'core authentication configuration used by multiple Microsoft 365 services.' Workaround: organisations with alternative email/messaging platforms (e.g. Google Workspace as backup) experienced less disruption — Microsoft recommends multi-region and backup communication channel planning.
Read more →CVE-2026-81963: Windows Update Stack Zero-Day — Entire Windows Fleet at Risk
CVE-2026-81963 is the first Windows Update Stack elevation-of-privilege flaw ever exploited in the wild as a zero-day. A local attacker with low privileges can exploit improper link resolution to reach SYSTEM with no user interaction, making it a reliable post-compromise escalation primitive chainable after phishing or credential theft. The attack surface covers every supported Windows client and server. No workaround; apply September 2026 Patch Tuesday updates immediately.
Read more →Critical Word and Excel RCE Flaws Patched — Malicious Documents Can Execute Without Macros
September Patch Tuesday includes Critical RCE fixes for CVE-2026-81959 and CVE-2026-81953 (Excel) and CVE-2026-81952 (Word), all triggerable via malicious documents. Twelve additional Office Critical patches can be triggered through the Preview or Reading Pane, requiring no user interaction beyond previewing a file — a technique favoured by both commodity phishing and targeted intrusion operators. Workaround: Disable Preview Pane in Outlook and File Explorer until patched.
Read more →CISA KEV: Cisco FMC Auth Bypass (CVSS 10.0), Citrix NetScaler (9.3) and Fortinet FortiOS — Federal Patch Deadline 12 September 2026
CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of 12 September 2026: CVE-2026-20079 (Cisco Secure Firewall Management Center, authentication bypass allowing unauthenticated root-level OS access, CVSS 10.0), CVE-2026-19490 (Citrix NetScaler ADC/Gateway authentication bypass, CVSS 9.3), and CVE-2025-25249 (Fortinet FortiOS/FortiSwitchManager/FortiSASE heap buffer overflow enabling unauthenticated RCE). Cisco confirmed active exploitation targeting CVE-2026-20079 began in August 2026. Patch immediately; no viable workaround for CVE-2026-20079 — restrict FMC web interface access to trusted IPs as an interim measure.
Read more →CISA KEV Catalog Now Tracks 1,311 Actively Exploited CVEs — MSPs Should Cross-Reference Client Estates
The CISA Known Exploited Vulnerabilities catalog now lists 1,311 vulnerabilities confirmed as being exploited by attackers, updated daily. The catalog spans Cisco, Fortinet, Citrix, Palo Alto, Ivanti, VMware and many others. MSPs should map client software and device inventories against the KEV list as a priority patching signal ahead of CVSS severity scores alone.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.