“Audit ISE deployments for CVE-2026-81963 version/patch status and Windows Update Stack zero-day exposure across your entire base before EOD — escalate anything vulnerable to emergency patching.”
M365 Service Degradation (MO1472904): Widespread 502/503 Errors Hit Core Apps
Microsoft confirmed an active service degradation affecting Microsoft 365 suite from September 16, 2026, tracked as incident MO1472904, with users worldwide hitting 502 and 503 HTTP errors across enterprise and consumer accounts. Engineering teams are reviewing telemetry to isolate root cause; no ETA for full resolution has been given. Workaround: Monitor the Microsoft 365 Admin Center for tenant/region-specific scope and consider switching affected users to mobile apps or cached offline access where possible.
Read more →CVE-2026-81963: Windows Update Stack Zero-Day EoP Exploited in the Wild
CVE-2026-81963 is an elevation-of-privilege flaw in the Windows Update Stack stemming from improper link resolution, allowing a local attacker to gain SYSTEM-level privileges. Microsoft confirmed exploitation before the patch was released, making this the first Windows Update Stack EoP zero-day ever exploited in the wild. CISA KEV deadline for federal agencies is 22 September 2026 — MSPs should treat all Windows endpoints as urgent, regardless of patch ring.
Read more →Windows Biometric Service: 64 EoP CVEs Patched — Systemic Fingerprint/Face Auth Weakness
The September 2026 Patch Tuesday release patched 64 separate vulnerabilities in the Windows Biometric Service, nearly all rated as elevation of privilege, suggesting a systemic weakness across the fingerprint and facial-recognition authentication subsystem rather than isolated coding errors. SQL Server follows with 61 vulnerabilities and Windows DHCP Server with 50, all representing infrastructure-critical services commonly exposed across internal enterprise networks. MSPs managing Windows endpoints with biometric authentication or internal SQL/DHCP servers should prioritise this patch cycle.
Read more →Cisco ISE Authentication Bypass Added to CISA KEV Catalog
CISA added a Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) vulnerability to the Known Exploited Vulnerabilities catalog, involving incorrect use of privileged APIs that allows an unauthenticated remote attacker to bypass the web-based management interface and gain unauthorised device access. MSPs managing Cisco ISE deployments should check the CISA KEV catalog for the applicable remediation deadline and apply Cisco-issued patches immediately. No workaround short of patching is confirmed effective for this bypass class.
Read more →CRN Australia: MDR Becoming 'Table Stakes' for Australian MSP Security Portfolios
Cybersecurity executives speaking at CRN Australia events flagged that Managed Detection and Response (MDR) is rapidly becoming a baseline expectation for Australian MSP clients, driven by escalating CVE volumes and threat actor sophistication across firewall and endpoint surfaces. Partners were urged to move beyond next-generation endpoint protection and adopt XDR and MDR capabilities to remain competitive. MSPs not currently offering MDR should assess white-label options such as Sophos MDR or Huntress.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.