Article Read Time

1. Microsoft Ships Its Largest Patch Tuesday on Record, With Two Zero-Days Already Under Attack
Microsoft released roughly 970 security fixes on September 8, the largest single Patch Tuesday in the company’s history by a wide margin. Two of those vulnerabilities were already being exploited before the updates shipped: CVE-2026-81963, a link-following flaw in the Windows Update Stack, and CVE-2026-85880, a heap buffer overflow in Windows ALPC. Neither gives an attacker remote entry on its own, but both offer anyone who already has a foothold a dependable route to SYSTEM privileges.
Source: SecurityWeek URL: https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/
2. “StyleSmuggler” Zero-Day Hit Live Magento and Adobe Commerce Stores Before a Fix Existed
Security firm Sansec observed attackers exploiting an unpatched flaw in Magento Open Source and Adobe Commerce beginning September 4, and published an emergency advisory the next day because storefronts were being compromised in real time. The vulnerability, now tracked as CVE-2026-75650 and rated CVSS 10.0, allows unauthenticated remote code execution against every current release including 2.4.9. Adobe issued an out-of-band hotfix on September 7, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the following day.
Source: Sansec URL: https://sansec.io/research/stylesmuggler-0day
3. GitLab Patches a Perfect-Score Flaw, and Internet-Wide Probing Starts Within a Day
GitLab published fixes for CVE-2026-85706, a path traversal vulnerability in the repository commits API carrying a CVSS score of 10.0. The flaw lets an unauthenticated attacker read arbitrary files from a self-managed GitLab server in a single HTTP request, which puts CI/CD secrets, tokens and source code directly at risk. Researchers at watchTowr confirmed that opportunistic scanning for exposed, unpatched instances began roughly a day after the advisory went out.
Source: watchTowr URL: https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/
4. Baylor Genetics Confirms Breach Affecting 2.8 Million Patients and Employees
The Houston clinical diagnostics laboratory confirmed that an intrusion detected in mid-June exposed the records of 2,810,878 patients and current and former staff. Exposed patient data included names, dates of birth, diagnoses, laboratory results and medical testing information, with Social Security numbers involved for a limited subset. Employee records were hit harder, with Social Security numbers, government identification numbers and financial account details among the stolen material.
Source: Cybersecurity Dive URL: https://www.cybersecuritydive.com/news/baylor-genetics-cyberattack-compromise-patient-data-genetic-testing/828019/
5. EU Cyber Resilience Act Reporting Went Live, and the Clock Is Now 24 Hours
As of September 11, manufacturers selling products with digital elements into the European Union must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform. The timeline is aggressive: an early warning within 24 hours of awareness, a full notification within 72 hours, and a final report within 14 days of a fix being available. Non-compliance carries administrative fines reaching 15 million euros or 2.5 percent of global annual turnover, whichever is higher, and the obligation covers legacy products already on the market.
Source: European Commission, Shaping Europe’s Digital Future URL: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting
