ZeroHour

Search: “cve-2016-5084”

30 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Microsoft Patch Tuesday for August 2026 Fixed a Zero

Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including an actively exploited WinSock zero-day CVE-2026-68820 and wormable DNS RCE CVE-2026-62878.

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, .NET and other products, with 62 rated Critical. The actively exploited CVE-2026-68820 is a use-after-free in the Windows WinSock afd.sys driver that can yield SYSTEM privileges via a race condition. CVE-2026-62878 is a critical, wormable stack buffer overflow in Windows DNS Server allowing unauthenticated, remote code execution without user interaction. Other notable fixes include WDS TFTP RCE CVE-2026-62893, a QUIC flaw affecting roughly 13.5 million sites (CVE-2026-62815), an Exchange authentication bypass EoP demonstrated at Pwn2Own Berlin (CVE-2026-62911), and two TPM 2.0 reference implementation fixes.

Security Affairs · Aug 12, 2026Advisory in the wildCVE-2026-68820CVE-2026-62878CVE-2026-62893+5 CVEs

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Tenable reports Microsoft's August 2026 Patch Tuesday addresses 398 CVEs including three zero-days, one exploited in the wild (CVE-2026-68820).

Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 important, and one moderate, and three zero-days among them. One zero-day is confirmed as exploited in the wild. The release covers components including .NET, .NET Framework, Active Directory Certificate Services (AD CS), Azure services, and Windows. Tenable's count omits two CVEs assigned by MITRE, CVE-2026-6726 and CVE-2026-6727.

Tenable Blog · Aug 11, 2026Vulnerability in the wildCVE-2026-68820CVE-2026-6726CVE-2026-67271

CVE-2026-50522: Microsoft SharePoint Server RCE Vulnerability

CVE-2026-50522 is an unauthenticated .NET deserialization RCE in SharePoint Server Subscription, 2019, and 2016; Microsoft patched it July 14, 2026.

CVE-2026-50522 (CWE-502) lets unauthenticated attackers send crafted serialized .NET payloads to network-accessible SharePoint endpoints, triggering gadget-chain deserialization and remote code execution under the privileged SharePoint service account. It affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 Enterprise; Microsoft published the advisory on July 14, 2026. The EPSS score is 20.346%, but no public PoC exists and the flaw is not in CISA's KEV catalog at publication. Mitigations include applying Microsoft updates, rotating SharePoint machine keys, enabling AMSI, and restricting internet exposure.

CVE-2026-73749: HPE ArubaOS-CX RCE

HPE patched CVE-2026-73749, a critical unauthenticated remote code execution flaw in ArubaOS-CX network switch software; affected devices need prompt updates.

HPE released patches for CVE-2026-73749, a critical unauthenticated remote code execution vulnerability in HPE Aruba Networking AOS-CX switch operating system. Published details are limited, but the flaw allows unauthenticated attackers to execute code on affected AOS-CX devices. Administrators running ArubaOS-CX should prioritize applying HPE's update.

SOCRadar · 12d agoVulnerabilityCVE-2026-73749

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

A maximum-severity (CVSS 10.0) unauthenticated RCE flaw in SAP Commerce Cloud, CVE-2026-58231, is under active exploitation days after patching.

CVE-2026-58231, rated 10.0 on CVSS, stems from insufficient authorization checks and input validation in SAP Commerce Cloud, enabling unauthenticated arbitrary code execution. Defused Cyber's honeypots detected exploitation attempts three days after the patch, and KEVIntel independently confirmed two attempts on August 14 from a US IP address. Onapsis urges customers to patch and rebuild, with an IP Filter Set offered as a temporary workaround. No actor attribution yet, though prior SAP NetWeaver flaw CVE-2025-31324 was exploited by China-nexus and criminal groups.

The Hacker News · Aug 17, 2026Exploit / PoC in the wildCVE-2026-58231CVE-2025-31324

Windows Remote Desktop Client Vulnerability Allows Attackers to Execute Remote Code

Microsoft patched CVE-2026-69485, an 8.8 CVSS RCE flaw in the Windows Remote Desktop Client affecting Windows 10/11 and Server 2016-2025.

Microsoft's September 2026 updates fix CVE-2026-69485, an Important-rated remote code execution vulnerability (CVSS 3.1: 8.8, temporal 7.7) in the Windows Remote Desktop Client caused by use of an uninitialized resource. An authenticated attacker with low privileges could send a specially crafted network request to execute code on an affected server, with no user interaction required. Microsoft says the flaw was not publicly disclosed before patching and rates exploitation as 'Less Likely' with no evidence of active exploitation. Affected products span Windows Server 2016, 2019, 2022 and 2025 and Windows 10 (1607-22H2) and Windows 11 (23H2-26H1), with fixes delivered via KBs including KB5123099, KB5122876 and KB5122882.

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Microsoft's September 2026 Patch Tuesday fixes a record 964 CVEs, including two zero-days actively exploited in the wild.

Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 101 rated critical and 824 rated important, making it the largest Patch Tuesday to date. The release includes fixes for two zero-days that were exploited in the wild, with CVE-2026-81963 and CVE-2026-85880 highlighted in the release. Affected products span Windows core components, Office, Exchange, .NET, Visual Studio, Active Directory services (including AD CS and AD FS) and numerous Azure services. Tenable notes the release surpasses July's as the biggest ever.

Tenable Blog · 8d agoVulnerability in the wildCVE-2026-81963CVE-2026-858801

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom patched two VMware Workstation and Fusion flaws, including critical integer overflow CVE-2026-59346 (CVSS 9.3), letting guest admins execute host code; no exploitation seen.

Broadcom released updates fixing CVE-2026-59346 (CVSS 9.3), an integer-overflow vulnerability allowing a malicious actor with local administrative privileges on a VM with a VMXNET3 adapter to execute code on the host, and CVE-2026-59347 (CVSS 8.1), a stack-based buffer overflow in HGFS allowing code execution as the host's VMX process. Both flaws affect VMware Workstation and Fusion 25H2 and 26H1, have no workarounds, and are fixed in Workstation 26H1u1 and Fusion 26H1u1. No in-the-wild exploitation has been observed, though VMware vCenter flaws CVE-2026-59309 and CVE-2026-59310, the latter suspected of China-nexus APT use, have recently breached 361 unique victim IPs across 47 countries.

Broadcom Patches Critical VMware Workstation and Fusion VM

Broadcom patched critical VMware Workstation and Fusion VM-escape flaws CVE-2026-59346 (CVSS 9.3) and CVE-2026-59347 (CVSS 8.1); update to 26H1u1.

Advisory VMSA-2026-0007 fixes CVE-2026-59346 (CVSS 9.3), an integer overflow in the VMXNET3 virtual network adapter, and CVE-2026-59347 (CVSS 8.1), a stack-based buffer overflow in HGFS. A malicious actor with local administrative privileges inside a VM could execute code on the host in both cases. The flaws affect Workstation and Fusion 25H2 and 26H1 and are fixed in version 26H1u1 with no workarounds available. The bugs were reported independently by researchers working with Trend Micro Zero Day Initiative and by Tencent Xuanwu Lab.

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs details a pre-authentication remote code execution flaw, tracked as CVE-2026-8452, in Citrix NetScaler appliances.

watchTowr Labs published technical analysis of a pre-authentication remote code execution vulnerability in Citrix NetScaler, tentatively assigned CVE-2026-8452. The CVE identifier is marked as provisional in the write-up. No confirmation of in-the-wild exploitation is provided in the available text.

watchTowr Labs · Aug 14, 2026Exploit / PoCCVE-2026-8452

CVE-2019-1068: A remote code execution vulnerability exists in ...

CISA added CVE-2019-1068, a high-severity remote code execution flaw in Microsoft SQL Server, to its KEV catalog after confirming exploitation in the wild.

CVE-2019-1068 (CVSS 8.8, CWE-20) is an improper input validation flaw allowing unauthenticated RCE in Microsoft SQL Server 2014 SP2/SP3, 2016, and 2017 on 32-bit and x64 builds. Exploitation requires low complexity and low privileges with no user interaction, and CISA formally added it to the KEV catalog on August 26, 2026. The CVE was originally published on July 15, 2019 and carries an EPSS score of 52.8%. Administrators must inventory affected SQL Server assets and apply vendor patches on an accelerated timeline.

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

ONLYOFFICE's ownCloud integration plugin 9.12 has an SSRF flaw (CVE-2026-84282) letting authenticated admins probe internal networks; no patch exists yet.

CERT/CC published VU#943094 for a server-side request forgery in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin version 9.12, tracked as CVE-2026-84282. The /apps/onlyoffice/ajax/settings/address endpoint does not validate the user-supplied document server URL, so an authenticated administrator can make the ownCloud server send arbitrary requests to localhost and internal hosts. Differences in error responses (connection failures vs SSL/TLS errors) let attackers enumerate open and closed TCP ports for internal reconnaissance. The vendor could not be reached, so no official patch is available; CERT recommends disabling the plugin and applying egress filtering until a fix ships.

Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

Microsoft's record September 2026 Patch Tuesday fixes 974 CVEs, including two exploited Windows privilege-escalation zero-days and 20 wormable bugs.

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two actively exploited zero-days: CVE-2026-85880, an ALPC heap buffer overflow, and CVE-2026-81963 in the Windows Update Stack, both CVSS 7.8 local privilege escalations. It also addresses an unauthenticated Exchange RCE (CVE-2026-55007) triggered by Visio attachment content indexing under memory pressure, an RDP use-after-free (CVE-2026-69525, CVSS 9.8), and 20 wormable flaws in DNS, DHCP, SMB, Active Directory, and other components. ZDI attributed the rising volume partly to AI-assisted vulnerability discovery, noting no corresponding spike in active exploits yet.

Security Affairs · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+3 CVEs2

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday fixes 400+ vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820) used by North Korean attackers.

Microsoft's August 2026 Patch Tuesday fixes over 400 vulnerabilities, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver exploited in the wild by North Korean actors deploying a kernel-mode rootkit in Operation Dream Job. Critical unauthenticated remote code execution flaws in Microsoft QUIC (CVE-2026-62815) and Windows DNS (CVE-2026-62878) were also patched, alongside a SharePoint RCE chain combining CVE-2026-63520 with CVE-2026-55040. Researcher Nightmare-Eclipse released ShieldBreak, a PoC bypassing the July RoguePlanet Microsoft Defender patch (CVE-2026-50656), confirmed working by Will Dormann on Windows 11.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-68820CVE-2026-62832CVE-2026-72971+6 CVEs1

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

ConnectWise patched critical ScreenConnect flaw CVE-2026-84869 (CVSS 9.9) exploited since August 20 in worm-like attacks; CISA added it to KEV.

ConnectWise released urgent patches for CVE-2026-84869 (CVSS 9.9), a missing authorization and improper privilege management flaw in ScreenConnect allowing file transfer and execution through active remote sessions without host confirmation. Huntress reported in-the-wild exploitation since August 20, with attackers using rogue ScreenConnect clients to push four VBScript files for persistence and worm-like propagation to other ScreenConnect clients. The flaw is fixed in ScreenConnect 26.6.5, with disabling the TransferFiles permission as a temporary mitigation. CISA added the CVE to its KEV catalog, requiring federal agencies to patch within three days under BOD 26-04.

SecurityWeekupdated · 13h agofirst · 2d agoExploit / PoC in the wild 4 sourcesCVE-2026-848691

CVE-2026-50522: Patch Critical SharePoint RCE Now

Microsoft patched CVE-2026-50522 (CVSS 9.8), an unauthenticated deserialization RCE in on-premises SharePoint servers, in its July 2026 updates; no exploitation confirmed at disclosure.

CVE-2026-50522 is a critical (CVSS 9.8) deserialization of untrusted data flaw (CWE-502) allowing unauthenticated remote code execution on on-premises Microsoft SharePoint servers. It affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, with fixes shipped in Microsoft's July 14, 2026 security updates; SharePoint Online is not listed as affected. No public evidence of active exploitation of this specific CVE existed at disclosure, though CISA's SSVC judged the attack automatable with total technical impact.

SAP Patches Critical Extended Passport Processing Vulnerability

SAP patches CVSS 10.0 flaw CVE-2026-44756 (OVERPASS) enabling unauthenticated RCE in S/4HANA and NetWeaver, plus three other criticals; no in-the-wild exploitation reported.

CVE-2026-44756 is a CVSS 10.0 memory corruption flaw in Extended Passport (EPP) deserialization, triggered when a user session opens across web, SAP GUI, and RFC vectors. Exploitation yields command execution as the SAP OS account, database credential and password hash recovery, session reading, and data or binary modification; affected products include S/4HANA, ERP/ECC, NetWeaver, Web Dispatcher, and BW/4HANA. Three other criticals were patched: CVE-2026-58240 (S4GET, missing authentication affecting all S/4HANA 2025 and earlier releases), CVE-2026-76969 (CAP credential disclosure), and CVE-2026-66768 (NetWeaver access control). Onapsis and SAP report no indicators of in-the-wild exploitation.

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19490 is a critical unauthenticated authentication bypass in Citrix NetScaler ADC and Gateway, remotely exploitable without user interaction.

An advisory published August 19, 2026 describes CVE-2026-19490, a critical authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw carries a CVSS v4.0 base score of 9.3 and is remotely exploitable by unauthenticated attackers over the network without user interaction or elevated privileges. NetScaler ADC and Gateway are widely deployed enterprise products positioned at or near the network perimeter, providing load balancing, SSL/TLS offloading, and secure remote access. The text does not state whether exploitation has been observed in the wild.

Rapid7 Blog · 28d agoVulnerabilityCVE-2026-194901

Microsoft fixes record 964 flaws, including 2 exploited zero-days

Microsoft's September Patch Tuesday fixes a record 964 CVEs, including two actively exploited Windows privilege-escalation zero-days, CVE-2026-81963 and CVE-2026-85880.

Microsoft's September 2026 Patch Tuesday addresses 964 customer-patchable CVEs (104 Critical, 860 Important), the largest release on record, out of 974 total listed. Two actively exploited zero-days are fixed: CVE-2026-81963, a link-following elevation-of-privilege flaw in the Windows Update Stack, and CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape, both with CVSS 7.8. Both zero-days were exploited before a patch was available and grant SYSTEM-level access after an initial foothold. The release also includes high-severity RCE fixes for Windows DNS Server, Remote Desktop Services, Exchange Server, SharePoint, and SQL Server.

Malwarebytes Labs · 7d agoExploit / PoC in the wildCVE-2026-81963CVE-2026-858801

Microsoft breaks Patch Tuesday record with 974-CVE deluge

Microsoft's record 974-CVE Patch Tuesday ships two exploited Windows zero-days, while Adobe's StyleSmuggler zero-day (CVE-2026-75650) gives unauthenticated RCE in Magento.

Microsoft's September Patch Tuesday addresses 974 CVEs, including two zero-days already under exploitation: CVE-2026-85880, a Windows ALPC privilege escalation leading to SYSTEM via sandbox escape, and CVE-2026-81963, a Windows Update Stack privilege escalation. Adobe patched 172 CVEs, including the max-severity StyleSmuggler zero-day CVE-2026-75650 in Magento and Adobe Commerce, which Sansec reports is being exploited since September 4 to inject PHP into templates and install a C2-connected backdoor. CISA added CVE-2026-85880, CVE-2026-81963, and CVE-2026-75650 to its Known Exploited Vulnerabilities Catalog with patch deadlines of September 22 and September 11. The piece also notes Google-patched Chrome V8 zero-day CVE-2026-85046 lacks a Microsoft advisory for Edge, and flags nine Exchange Server flaws including remote unauthenticated RCE CVE-2026-55007.

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)

Actively exploited Citrix NetScaler flaw CVE-2026-8452, patched in June, now added to CISA KEV; attackers deploy web shells and run discovery commands.

CISA added CVE-2026-8452, a memory overflow vulnerability in Citrix NetScaler ADC/Gateway, to its Known Exploited Vulnerabilities catalog on August 26, 2026, giving federal agencies until August 29 to remediate. Citrix disclosed and patched the flaw on June 30, 2026 in versions 14.1-72.61, 13.1-63.18, and 13.1-37.272. watchTowr Labs found the flaw can be chained into unauthenticated remote code execution and released a PoC on August 14. Previdian and Defused reported exploitation with web shells named x.php and z.php from at least three unique source IPs.

Help Net Security · 21d agoExploit / PoC in the wildCVE-2026-8452CVE-2015-3246CVE-2015-5287+3 CVEs

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

CISA added actively exploited CVE-2026-21962, a CVSS 10.0 unauthenticated flaw in Oracle HTTP Server and WebLogic Proxy Plug-in, to KEV with an August 27 deadline.

CISA added CVE-2026-21962 (CVSS 10.0), an improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate by August 27, 2026. The unauthenticated flaw allows remote attackers with network access to create, delete, or modify critical data, potentially gain broad access, and cause a scope change to other systems; affected versions are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. CloudSEK honeypot data from January-February 2026 showed widespread exploitation of the flaw alongside older WebLogic RCEs including CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271.

Security Affairs · 22d agoExploit / PoC in the wildCVE-2026-21962CVE-2020-14882CVE-2020-14883+2 CVEs

CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)

CISA added two actively exploited SonicWall SMA1000 flaws to KEV: pre-auth SSRF CVE-2026-83548 (CVSS 10) and post-auth RCE CVE-2026-83549; patch by September 5.

CISA added CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. CVE-2026-83548 is a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface; CVE-2026-83549 is a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix and older are affected; fixes ship in 12.4.3-03526 and 12.5.0-02952. Qualys customers can detect vulnerable assets via QID 388624.

Qualys ThreatPROTECT · 13d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Microsoft's September 2026 Patch Tuesday ships 964 fixes including two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) and a wormable DNS RCE.

Microsoft's September 2026 Patch Tuesday includes 964 Microsoft vulnerabilities requiring customer action, a record attributed to AI-assisted bug discovery, plus 174 third-party/open-source and 23 Chromium/Edge CVEs. Two zero-days are exploited in the wild: CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape and privilege escalation, and CVE-2026-81963, a Windows Update Stack escalation to SYSTEM. CVE-2026-69730, an unauthenticated Windows DNS RCE, is not yet exploited but Microsoft expects exploitation, and roughly 20 bugs could be wormable. Separately, SAP issued a critical CVSS 10.0 fix for the EPP component used in S/4HANA and NetWeaver.

CSO Online · 8d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-69730+2 CVEs1

CVE-2026-33824: CISA Flags Windows IKE RCE as Exploited

CISA added four actively exploited vulnerabilities to its KEV catalog, headlined by CVE-2026-33824, a Windows IKE Service Extensions remote code execution flaw.

CISA's KEV addition, dated August 18, covers CVE-2026-33824 in Windows IKE Service Extensions, CVE-2026-55040 in on-premises Microsoft SharePoint Server, CVE-2026-59310 in Broadcom VMware vCenter, and CVE-2026-65400 in Apple macOS Screen Sharing. KEV listing confirms observed exploitation in the wild. Three of the four products are frequently deployed as high-value enterprise infrastructure, including remote-access endpoints and collaboration platforms.

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two Windows zero-days exploited in the wild for privilege escalation.

Microsoft patched 974 vulnerabilities, its largest Patch Tuesday ever, including CVE-2026-85880, a heap buffer overflow in Windows ALPC allowing AppContainer sandbox escape to System, and CVE-2026-81963, a link-following flaw in the Windows Update Stack enabling local privilege escalation. Both were exploited as zero-days before the patch. ZDI's Dustin Childs says 20 of the fixed flaws are wormable, enabling unauthenticated remote code execution. The release also covers 723 Windows flaws and 222 Office bugs, plus fixes in Exchange, SharePoint, SQL Server, Azure and Exchange Server RCE (CVE-2026-55007).

SecurityWeek · 8d agoExploit / PoC in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+5 CVEs1

Adobe Commerce max-severity bug comes under active attack

Attackers are actively exploiting CVE-2026-75650 (CVSS 10.0), an unauthenticated RCE zero-day in Adobe Commerce/Magento, deploying a Rust backdoor on e-commerce servers.

Sansec identified active exploitation of a CVSS 10.0 zero-day (CVE-2026-75650) in Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9, dubbed StyleSmuggler. The attack abuses crafted style properties in Magento template processing to execute PHP while rendering a 'Payment Transaction Failed Reminder' email, then launches a Rust backdoor connecting to C2 at 99.84.67.186 disguised as NTP traffic. Exploitation began September 4, 2026; Adobe released emergency hotfix VULN-393411, but Sansec also observed a second attacker deploying a PHP web shell in the product-image cache.

CSO Online · 8d agoExploit / PoC in the wildCVE-2026-75650

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two actively exploited Windows zero-days, CVE-2026-85880 and CVE-2026-81963.

Microsoft fixed a record 974 CVEs in its September 2026 Patch Tuesday, surpassing the previous record of 570 in July 2026, with Windows affected by 723 flaws and Office by 111, including 119 critical vulnerabilities. Two zero-days are actively exploited: CVE-2026-85880, a 7.8 heap-based buffer overflow in Windows ALPC allowing AppContainer privilege escalation, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack enabling local privilege escalation. Microsoft attributed the update surge partly to agentic AI tools used to discover zero-day vulnerabilities, and researchers highlighted critical RCE flaws in Windows DNS, DHCP and Deployment Services as priorities.

Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help

High-severity authentication bypass CVE-2026-62911 in Exchange Server has public exploit code; about 22,000 servers remain unpatched and internet-exposed.

Microsoft's August 2026 Patch Tuesday fixed CVE-2026-62911 (CVSS 8.0), an authentication bypass affecting Exchange Server 2016, 2019 and Subscription Edition. Successful exploitation lets an attacker with basic privileges take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. As of September 1, Shadowserver identified roughly 22,000 unpatched, internet-exposed Exchange servers, including about 6,200 in the US and 5,100 in Germany. NCSC-NL confirmed working exploit code is publicly available, while CISA has not yet reported exploitation in the wild.

Zscaler ThreatLabz · 13d agoVulnerabilityCVE-2026-629112

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP patched CVE-2026-44756 (CVSS 10.0), an unauthenticated kernel memory corruption allowing OS command execution, plus three other critical flaws.

SAP's September security updates include CVE-2026-44756 (OVERPASS, CVSS 10.0), a missing boundary validation during deserialization of Extended Passport (EPP) data in the SAP kernel, enabling unauthenticated attackers to run arbitrary OS commands with SAP administrative privileges. Also patched: CVE-2026-58240 (S4GET, CVSS 9.8), a missing authentication check in SAP NetWeaver Message Server yielding RCE as <sid>adm; CVE-2026-76969 (9.4), credential disclosure in SAP Cloud Application Programming Model multi-tenant apps; and CVE-2026-66768 (9.0), improper access control in SAP NetWeaver SAP GUI for Java. Onapsis, which discovered the flaws, says none have been exploited to date and recommends prioritizing internet-facing SAP systems.