// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Friday, September 18, 2026

2 CRITICAL2 WARNING5 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Audit ISE deployments for CVE-2026-81963 version/patch status and Windows Update Stack zero-day exposure across your entire base before EOD — escalate anything vulnerable to emergency patching.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE1 item
WARNING☁️ M365/Azure

M365 Service Degradation (MO1472904): Widespread 502/503 Errors Hit Core Apps

Microsoft confirmed an active service degradation affecting Microsoft 365 suite from September 16, 2026, tracked as incident MO1472904, with users worldwide hitting 502 and 503 HTTP errors across enterprise and consumer accounts. Engineering teams are reviewing telemetry to isolate root cause; no ETA for full resolution has been given. Workaround: Monitor the Microsoft 365 Admin Center for tenant/region-specific scope and consider switching affected users to mobile apps or cached offline access where possible.

Read more →
🔐 SECURITY2 items
CRITICAL🔐 Security

CVE-2026-81963: Windows Update Stack Zero-Day EoP Exploited in the Wild

CVE-2026-81963 is an elevation-of-privilege flaw in the Windows Update Stack stemming from improper link resolution, allowing a local attacker to gain SYSTEM-level privileges. Microsoft confirmed exploitation before the patch was released, making this the first Windows Update Stack EoP zero-day ever exploited in the wild. CISA KEV deadline for federal agencies is 22 September 2026 — MSPs should treat all Windows endpoints as urgent, regardless of patch ring.

Read more →
WARNING🔐 Security

Windows Biometric Service: 64 EoP CVEs Patched — Systemic Fingerprint/Face Auth Weakness

The September 2026 Patch Tuesday release patched 64 separate vulnerabilities in the Windows Biometric Service, nearly all rated as elevation of privilege, suggesting a systemic weakness across the fingerprint and facial-recognition authentication subsystem rather than isolated coding errors. SQL Server follows with 61 vulnerabilities and Windows DHCP Server with 50, all representing infrastructure-critical services commonly exposed across internal enterprise networks. MSPs managing Windows endpoints with biometric authentication or internal SQL/DHCP servers should prioritise this patch cycle.

Read more →
🔥 NETWORKING1 item
CRITICAL🔥 Networking

Cisco ISE Authentication Bypass Added to CISA KEV Catalog

CISA added a Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) vulnerability to the Known Exploited Vulnerabilities catalog, involving incorrect use of privileged APIs that allows an unauthenticated remote attacker to bypass the web-based management interface and gain unauthorised device access. MSPs managing Cisco ISE deployments should check the CISA KEV catalog for the applicable remediation deadline and apply Cisco-issued patches immediately. No workaround short of patching is confirmed effective for this bypass class.

Read more →
📡 INDUSTRY1 item
INFO📡 Industry

CRN Australia: MDR Becoming 'Table Stakes' for Australian MSP Security Portfolios

Cybersecurity executives speaking at CRN Australia events flagged that Managed Detection and Response (MDR) is rapidly becoming a baseline expectation for Australian MSP clients, driven by escalating CVE volumes and threat actor sophistication across firewall and endpoint surfaces. Partners were urged to move beyond next-generation endpoint protection and adopt XDR and MDR capabilities to remain competitive. MSPs not currently offering MDR should assess white-label options such as Sophos MDR or Huntress.

Read more →
Thursday, September 17, 2026
Monday, September 21, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice