This edition of weekly cybersecurity news covers an unprecedented surge in vulnerability volume and immediate zero-day exploitation. Enterprise administrators faced a record-breaking Patch Tuesday release containing hundreds of fixes alongside actively weaponized privilege escalation bugs.
Simultaneously, the Cybersecurity and Infrastructure Security Agency (CISA) added critical flaws across Adobe Commerce, Windows, and remote monitoring systems directly to its Known Exploited Vulnerabilities catalog under federal mandates. Because attackers rapidly chain administrative exploits with edge flaws, security teams must discard blanket monthly patching cycles in favor of aggressive, risk-based prioritization.
Top Cybersecurity Stories This Week
Microsoft Delivers Record Patch Tuesday With Actively Exploited Zero-Days
On September 8, 2026, Microsoft issued its monthly security release fixing more than 970 vulnerabilities—the largest monthly patch drop on record. Most critically, the release addresses two confirmed in-the-wild zero-days: an Advanced Local Procedure Call (ALPC) heap overflow and an improper link resolution flaw in the Windows Update Stack. Attackers leveraged both flaws to bypass security boundaries and elevate privileges straight to NT AUTHORITY\SYSTEM.
- Identified CVEs: CVE-2026-85880 (CVSS 7.8, ALPC Heap Overflow) and CVE-2026-81963 (CVSS 7.8, Windows Update Stack Link Resolution)
- Attack Vector: Local privilege escalation (LPE) executing via crafted ALPC messaging calls and symbolic link manipulation during background update processing.
- Source & Verification: CISA Alert: CISA Adds Four Known Exploited Vulnerabilities to Catalog (September 8, 2026)
Adobe Commerce & Magento Template Injection Under Active Exploitation
On September 8, 2026, CISA formally added CVE-2026-75650 affecting Adobe Commerce and Magento Open Source to the KEV catalog. The vulnerability allows adversaries to conduct unauthenticated server-side template injection (SSTI) against exposed e-commerce storefronts. Because successful exploitation grants attackers remote code execution capabilities, adversaries have targeted checkout modules to inject malicious card-skimming scripts and siphon consumer payment details.
- Identified CVEs: CVE-2026-75650 (CVSS 9.1, Critical)
- Attack Vector: Improper sanitation of template engine directives sent to storefront layout rendering components.
- Source & Verification: CISA Known Exploited Vulnerabilities Catalog Listing for Adobe Commerce
Critical Code Injection Flaw Hits N-able N-central (CVE-2026-86218)
Managed service providers (MSPs) received emergency warnings this week as CISA cataloged an actively targeted flaw in N-able N-central. The static code injection bug enables remote attackers to inject unauthorized instructions directly into the central management interface. Because MSP management platforms possess extensive administrative reach into thousands of downstream client networks, compromising an N-central server serves as a prime initial access vector for wide-scale supply-chain intrusions.
- Identified CVEs: CVE-2026-86218 (CVSS 8.8, High)
- Attack Vector: Unauthenticated static code injection through exposed management endpoints, allowing execution within the server context.
- Source & Verification: Aviatrix Threat Research: September KEV Directive Breakdown
Check Point Issues Critical Fixes as VPN Gateway Exploitation Begins
Check Point published emergency updates on September 9, 2026, to address two high-severity flaws across its gateway and management product lines. The first, CVE-2026-85102, is an unauthenticated remote code execution vulnerability residing in the perimeter VPN gateway service. Telemetry indicated the first weaponization attempts against exposed customer firewalls emerged by September 12, following prior zero-day exploitation of the associated management server traversal flaw (CVE-2026-93616).
- Identified CVEs: CVE-2026-85102 (CVSS 9.8, Critical VPN Gateway RCE) and CVE-2026-93616 (CVSS 9.8, Management Path Traversal)
- Attack Vector: Improper certificate verification on the internet-facing VPN gateway combined with directory traversal on management daemons.
- Source & Verification: Check Point Advisory & Threat Intelligence Bulletin
Weekly Mitigation & Patch Checklist
- [ ] Deploy Microsoft September Cumulative Updates: Prioritize patching domain controllers, session hosts, and core Windows endpoints to close active ALPC and link-following escalation paths (CVE-2026-85880, CVE-2026-81963).
- [ ] Patch Adobe Commerce / Magento: Upgrade storefronts to the latest vendor release to block template injection attempts, and inspect layout logs for unauthorized directive calls (CVE-2026-75650).
- [ ] Update N-able N-central Instances: Apply vendor-supplied hotfixes across on-premises N-central management servers immediately to eliminate static code injection risks (CVE-2026-86218).
- [ ] Isolate Check Point Edge Interfaces: Install both the gateway patch and the management console update (CVE-2026-85102, CVE-2026-93616). Remember that updating one component does not protect the other.
- [ ] Enforce Strict Perimeter Egress Rules: Restrict external administrative access to VPN consoles, MSP portals, and management consoles behind zero-trust network access (ZTNA) or strict IP allowlists.
Conclusion & Emerging Trends
This week proves that the sheer volume of monthly disclosures is outstripping traditional patching cadences. Threat actors are no longer waiting for routine deployment windows; they are actively weaponizing edge appliances, MSP software, and OS-level escalation bugs within hours of disclosure. Defenders must pivot away from “patch everything” checklists toward intelligence-led vulnerability management that prioritizes KEV listings and internet-exposed assets.
With Microsoft pushing nearly a thousand CVEs in a single cycle, how is your SecOps team triaging testing versus urgent zero-day deployment?
TVA Cyber Services