// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Monday, September 14, 2026

4 WARNING4 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Identify every internet-facing or internally-accessible DNS server and RDS host in your managed infrastructure and create a priority patch schedule for today — these CVEs are network-adjacent attack vectors, not client-side.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE2 items
WARNING☁️ M365/Azure

Microsoft SQL Server Elevation of Privilege CVE-2026-66814 Flagged in September Patch Tuesday

Microsoft's record-breaking September 2026 Patch Tuesday (974 CVEs) includes CVE-2026-66814, an elevation-of-privilege vulnerability in Microsoft SQL Server. The release spans Windows clients and servers, M365 apps, SQL Server, Exchange Server, and Azure — MSPs should treat Office product patching separately from Windows updates as they are delivered via different channels. No known workaround; apply the September Patch Tuesday update immediately.

Read more →
WARNING☁️ M365/Azure

Microsoft 365 Multi-Day Auth Outage Resolved After 67 Hours (Aug 31–Sep 3)

A core authentication misconfiguration triggered a ~67-hour outage starting August 31, knocking out Exchange Online, Teams, SharePoint, Copilot, Defender XDR, Purview, Universal Print, and the M365 Admin Center. Microsoft closed incidents EX1464935 and MO1465074 on September 3 after remediation at 10:00 AM UTC. A Post-Incident Report is promised but not yet published; workaround was to use OWA via direct URL where accessible.

Read more →
🔐 SECURITY2 items
WARNING🔐 Security

Windows DNS Server Critical RCE CVE-2026-69730 (CVSS 9.8) Patched — Network-Reachable with No Auth

CVE-2026-69730 is a critical, unauthenticated remote code execution vulnerability in Windows DNS Server with a CVSS score of 9.8, patched in the September 2026 Patch Tuesday release. Any network-reachable DNS server running Windows is potentially exposed; no user interaction is required for exploitation. Apply KB5122871 urgently and restrict DNS server exposure at the perimeter as a temporary measure.

Read more →
WARNING🔐 Security

Remote Desktop Services Unauthenticated RCE — No Click Required, Patch Tuesday Sept 2026

September Patch Tuesday addresses an unauthenticated RCE in Remote Desktop Services where a network-adjacent attacker sends crafted requests, achieving code execution on the host with no authentication and no user interaction required. MSPs should immediately audit which client environments expose RDP to broader networks. Workaround: restrict RDS to VPN or zero-trust access only; patch via the September cumulative update.

Read more →
Friday, September 11, 2026
Tuesday, September 15, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice