“Query your entire client base for Windows 11 and Server 2025 builds TODAY — you need a definitive list before the exploit goes mainstream.”
September Patch Tuesday: Windows Update Stack Zero-Day (CVE-2026-81963) Affects All Windows 11 and Server 2025 Builds
CVE-2026-81963, actively exploited in the wild, affects Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2025 including Server Core — Windows 10 and older servers are not affected. A local attacker with low privileges can exploit an improper link-resolution flaw to reach SYSTEM privileges with no user interaction, making it an ideal post-compromise escalation primitive when chained with phishing or credential theft. MSPs should flag endpoints with unknown or stale Windows Update status for immediate remediation and watch for unexpected SYSTEM-level processes spawned from standard user sessions.
Read more →Cisco ISE Privileged API Bypass: Unauthenticated Remote Access Confirmed Exploited
Cisco's Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain an actively exploited vulnerability allowing unauthenticated remote attackers to bypass the web management interface entirely via incorrect privileged API use. CISA has listed it in the KEV catalog under BOD 26-04, requiring federal agencies to patch urgently — a strong signal for MSPs to act immediately on any ISE deployment. Apply Cisco's published advisory patch; restrict management interface access to trusted networks as an interim workaround.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.