Microsoft’s September Patch Tuesday unleashed one of the most intense vulnerability waves of the year: 973 security holes addressed in Windows, Office, SQL Server, Exchange, SharePoint, Azure and developer tools. Elevation-of-privilege bugs were the most common—438 in total—alongside 258 remote code execution flaws. A particularly alarming concern: two zero-days already under active exploitation (CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack), both ranked as “Important.” Fixes also arrived for Windows Secure Kernel Mode, VBS Enclave and Office RCE issues, underscoring how urgent this patch cycle is for organizations.
Compromised Firewalls & Smart Devices
FortiGate firewalls were exploited via CVE-2025-25249 (a critical heap overflow in FortiOS/ FortiSwitchManager’s CAPWAP service) in a campaign deploying a custom Node.js RAT called PivotC2. Attackers reportedly scanned over 30,000 FortiGate IPs, compromised 178 devices, and even accessed Exchange mailboxes in U.S. organizations—storing stolen data in Wasabi cloud storage. The campaign has been attributed to a financially motivated, Russian-speaking threat group while also leveraging FortiManager and ArubaOS bugs. Affected systems should be updated to FortiOS 7.6.4, 7.4.9, 7.2.12, or 7.0.18 or newer.
Meanwhile, Fortinet disclosed CVE-2026-84393, a certificate validation flaw in its ZTNA (Zero Trust Network Access) portal affecting various FortiOS and FortiProxy versions. The vulnerability, stemming from improper certificate handling, could enable man-in-the-middle attacks that expose ZTNA portal sessions. Though there’s no evidence yet of in-the-wild exploitation, internet-facing portals amplify the risk. Upgrading to FortiOS/FortiProxy version 7.6.7 or newer is strongly advised.
Root-Level RCE & Privacy Alarms
Palo Alto’s PAN-OS plays host to CVE-2026-0310, a buffer overflow in XML processing that allows unauthenticated attackers to achieve root-level execution on PA-Series firewalls. The flaw affects versions below 12.2.3, 12.1.10, several 11.x branches and 10.2.18-h10. VM-Series firewalls face only denial-of-service impacts. With no workarounds available, Palo Alto recommends locking down management interfaces and updating immediately. No confirmed exploit cases as of September 9, 2026.
An investigation into LG’s OLED smart TVs (including its G5 line) revealed they continue scanning home networks and capturing ambient mic input—persisting even when in standby. These actions involve uploading transcribed audio and Wi-Fi network data when reconnected, raising serious privacy concerns, especially in sensitive environments.
Breaches, AI, & Other High-Risk Exploits
Revolut disclosed that a fraudulent request, impersonating a government agency via an official domain, allowed attackers access to customer KYC documents—including passport and driver’s licenses—identity selfies, full transaction histories (including Bitcoin), IBANs, and contact info. Revolut emphasized that core account systems remained intact; this was a sophisticated social engineering breach. On-chain observers noted high-net-worth customers may have been especially targeted.
Other developments include a remote code execution flaw patched in Windows Remote Desktop Client (CVE-2026-69485), a multi-actor AI agent arms race to automate attacks (including rewriting malware, hijacking hotel Wi-Fi, exfiltrating national IDs), a fresh unpatched Magento/Adobe Commerce zero-day dubbed “StyleSmuggler,” and a WeChat zero-click worm proof-of-concept that spreads across iOS and Android without user interaction before mitigation in July.
Additional severe risks emerged in MikroTik RouterOS (unauthenticated SSH access allowing shell control), Check Point VPNs (critical RCE bugs with scores of 9.8 CVSS), a Chrome 153 release closing 230 vulnerabilities including an in-the-wild zero-day, and proofpoint-identified phishing campaigns abusing trusted Google services to steal credentials.
What to Watch
Edge firewalls and perimeter security appliances remain prime targets for threat actors, both state-sponsored and financially motivated. AI tools are accelerating exploit discovery, malware evolution, and campaign scale. Microsoft’s massive patch pile, plus active zero-days, demands urgent attention from IT teams. Especially with Revolut’s incident and similar social engineering cases, credential security and request verification are more critical than ever. Organizations should prioritize patch deployments, audit access controls, and adopt stricter processes for validating data requests.