“Audit all Fortinet devices and Adobe Commerce instances in your customer base TODAY — create a prioritized patch/mitigation list and notify account teams before your customers read about it in Twitter.”
Microsoft Exchange Server EoP Vuln (CVE-2026-96940, CVSS 8.8) — October Patch Tuesday Ships Early
Microsoft's October 2026 Patch Tuesday (released 2 October) fixes a single CVE: an Elevation of Privilege flaw in Exchange Server 2016 CU23, 2019 CU14/CU15, and Subscription Edition RTM, rated CVSS 8.8. No active exploitation has been confirmed this cycle, but Exchange remains a high-value target and patching is strongly advised this week. Apply KB5129955/KB5129956/KB5129957/KB5129958 as appropriate for your Exchange version.
Read more →Azure Maps Rendering Failures Reported Across APAC, Europe and UK (Early October 2026)
Multiple user-submitted reports from 2–3 October 2026 indicate Azure Maps is failing to load in Power BI — both online and desktop — across tenants in Malaysia, Spain, and Norway, with at least one report from the UK. Microsoft's Azure portal status page showed the service as operational, suggesting the issue may be tenant- or region-specific rather than a declared incident. Workaround: switch affected Power BI reports to an alternative mapping visual or check Azure Service Health for your specific tenant.
Read more →Azure Configuration Incident (1 Oct): Multi-Region Disruption Now Resolved, PIR Due
A misconfiguration event on 1 October 2026 caused service degradation across Azure regions including France Central, North Europe, Southeast Asia, UK South, and UK West, with recovery confirmed by 02:15 UTC. Microsoft's downstream M365 impact was tracked under MO1437424, and the company has committed to publishing a final Post Incident Review. Automated recovery and rollback improvements are targeted for completion in October 2026.
Read more →Apple CVE-2026-86950 (CoreGraphics) Confirmed Exploited in Targeted iOS Attacks — CISA KEV
CISA added CVE-2026-86950 to its KEV catalog on 29 September 2026, with a federal deadline of 2 October. Apple confirmed the out-of-bounds write vulnerability in CoreGraphics may have been exploited in 'extremely sophisticated' targeted attacks against specific individuals on iOS versions prior to iOS 27. MSPs managing Apple device fleets should prioritise updating to iOS 27 immediately; no known workaround exists beyond the OS update.
Read more →Adobe Commerce/Magento CVE-2026-71362 (EPSS 88%) Leads CISA's Latest Exploitation Wave
CISA confirmed 10 newly exploited CVEs in the last 7 days, led by CVE-2026-71362 affecting Adobe Commerce and Magento with an EPSS exploitation probability of 88%. MSPs supporting e-commerce clients on Magento/Adobe Commerce should treat this as urgent, as the high EPSS score reflects active attacker interest. Apply Adobe's available patches immediately and audit affected storefronts for signs of compromise.
Read more →CRITICAL: Fortinet FortiMail Zero-Day CVE-2026-104286 (CVSS 9.8) Actively Exploited — No Patch Yet
Fortinet disclosed CVE-2026-104286 on 1 October 2026, a critical path traversal and null byte injection zero-day in FortiMail (versions 7.2.x–8.0.1) allowing unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests. CISA added it to the KEV catalog the same day; patches (8.0.2, 7.6.7, 7.4.9) are not yet released. Workarounds: disable IBE via CLI (`config system encryption ibe / set status disable / end`), restrict management interface to trusted networks, or block POST requests to /ibe containing `../`; Fortinet has published IoC IPs 79.141.169.187 and 45.129.0.192 to hunt in logs.
Read more →Fortinet Leads Firewall Vendors in Unauthenticated CVEs for 2026 — Eight Flaws Including Active Exploitation
A mid-year analysis confirms Fortinet has accumulated 8+ unauthenticated CVEs across FortiOS, FortiSandbox, FortiSIEM, FortiAuthenticator, and FortiClient EMS in 2026, with multiple under confirmed active exploitation. Palo Alto recorded two critical firewall OS flaws (including CVE-2026-0300, CVSS 9.8 root RCE), both on the CISA KEV list. MSPs managing multi-vendor firewall estates should audit firmware versions across all Fortinet and PAN-OS platforms urgently.
Read more →Supply Chain Attacks Weaponising MSP Access Credentials on the Rise — Channel Alert
ChannelE2E flagged this week that supply chain attacks are increasingly targeting MSP remote access credentials and RMM platforms as an entry point into downstream SMB client environments, consistent with the ACSC's N-central advisory. The trend underscores the need for MFA enforcement, IP-restricted RMM access, and privileged access workstations for all MSP tooling. Australian MSPs should review their RMM access policies and consider implementing a formal supply chain security attestation process for clients.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.