// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Friday, September 25, 2026

● 2 CRITICAL● 1 WARNING● 5 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

“Disable Outlook Preview Pane organization-wide via GPO/Intune immediately and audit your Windows Update history for signs of CVE-2026-81963 exploitation in the past 30 days.”

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE— 3 items
CRITICAL☁️ M365/Azure

Outlook Preview Pane RCE: Two Critical CVEs (CVE-2026-78509 & CVE-2026-78510) Score 9.8

September 2026 Patch Tuesday includes two Critical Microsoft Office Outlook RCE vulnerabilities — CVE-2026-78509 and CVE-2026-78510 — both scoring 9.8 CVSS and both exploitable via the Preview Pane without any user click or attachment open. These heap-based buffer overflow flaws are a priority patch target, particularly for any organisation with Outlook Preview Pane enabled. Workaround: disable the Reading/Preview Pane in Outlook until the September CU is applied.

Read more →
INFO☁️ M365/Azure

Multi-Day M365 Outage Resolved — Core Auth Misconfiguration Hit Outlook, SharePoint, Teams, Copilot (1 Sep)

A multi-day Microsoft 365 outage beginning 1 September 2026 was attributed to a misconfiguration in a core authentication configuration used by multiple M365 services, preventing authentication components from deploying as expected to a portion of infrastructure. Services affected included Outlook, SharePoint, Teams, Copilot, Purview, Defender XDR, the Admin Center, and Universal Print. The issue is now resolved, but MSPs should review post-incident reports for architectural lessons ahead of the next auth-layer event.

Read more →
INFO☁️ M365/Azure

Azure Service Degradation Reports — 17 User Submissions in 24 Hours as of 24 Sep

StatusGator confirmed Azure was operational as of its last check on 24 September 2026 at 9:28 AM UTC, but recorded 17 user-submitted outage reports within the preceding 24 hours, suggesting intermittent instability across some regions or services. MSPs managing Azure-hosted workloads should check the Azure Service Health dashboard for active advisories in their specific regions. No official incident ID had been published at time of reporting.

Read more →
🔐 SECURITY— 1 item
CRITICAL🔐 Security

CVE-2026-81963: Windows Update Stack Zero-Day Exploited in Wild — SYSTEM Privilege Escalation, No User Interaction

CVE-2026-81963 is an actively exploited elevation-of-privilege flaw in the Windows Update Stack affecting every supported Windows client and server, allowing a local attacker with low privileges to escalate to SYSTEM via improper link resolution with no user interaction required. Microsoft confirms wild exploitation, making it an immediate post-compromise escalation tool that can chain with any initial access vector including phishing or stolen credentials. Patch via the September 2026 cumulative update; no mitigation short of patching.

Read more →
📡 INDUSTRY— 1 item
WARNING📡 Industry

Australia-Singapore Cable Break on 4 September Impacting Vocus Customers — Partial Restoration Underway

The Australia-Singapore Cable suffered a break on 4 September 2026 on the Indonesia-to-Singapore segment, with Vocus confirming the fault is located approximately 615km from the Singapore landing station in Indonesian waters. A temporary restoration of Layer 2 Ethernet services was implemented on September 11 via an additional network path between Singapore and Jakarta, but full repairs remain outstanding. Australian MSPs with clients dependent on Vocus international circuits or cloud services routed through this cable should check with Vocus for impact assessment and ETA on full restoration.

Read more →
← Thursday, September 24, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice