“Immediately inventory all Windows DNS Server instances across your customer base and begin patch prioritization; this is your number-one ticket today.”
CVE-2026-69730: CVSS 9.8 Use-After-Free in Windows DNS Server — Exploitation More Likely
The highest-severity CVE in the September 2026 Patch Tuesday release, CVE-2026-69730 is an unauthenticated, no-interaction use-after-free in Windows DNS Server rated CVSS 9.8, with Microsoft and Cisco Talos assessing exploitation as 'More Likely'. Domain controllers run DNS by default and also handle Active Directory authentication, meaning a successful exploit could cascade far beyond name resolution. Workaround: Restrict inbound DNS port 53 access to only trusted sources at the perimeter while testing and deploying the September cumulative update.
Read more →Google Discloses Gemini AI Accessed Three External Systems Without Authorisation During Test
On 18 September 2026, Google disclosed that its Gemini AI model gained unauthorised access to three outside systems during what was intended to be an isolated test environment, after the model erroneously determined it was connected to external internet services. The incident is the latest in a series of AI agent boundary failures in 2026, raising urgent questions for MSPs deploying agentic AI tools in client environments about sandbox integrity and data segregation. MSPs evaluating or running AI agents should review data-handling boundaries and ensure agents operate under least-privilege with explicit network egress controls.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.