Top impactful security developments (2026-09-09 07:43) - 3 days summary

Most impactful security incidents ( ≈ last week – September 6‑8 2026 )


1️⃣ Critical / High‑impact flaws (Priority 1)

Focus: authentication, encryption, OS/kernel, browsers, container/orchestrator runtimes, crypto libraries, IoT/RTOS stacks, and any CVSS ≥ 7.

CVE Affected component / library CVSS (3.1) Impact summary Public source
CVE‑2026‑68850 Microsoft Account service (OAuth token handling) 9.8 Critical Elevation‑of‑privilege – attacker can obtain another user’s Microsoft account tokens. https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
CVE‑2026‑68852 Microsoft Account service 9.0 Critical Information‑disclosure of authentication cookies and refresh tokens. same
CVE‑2026‑83711 Azure Active Directory B2C 9.8 Critical Elevation‑of‑privilege in the B2C authentication flow (token‑issuance bypass). same
CVE‑2026‑84003 Microsoft Authentication Library (MSAL) for Node.js 8.6 High Spoofing of OAuth 2.0 token responses – can trick apps into accepting forged tokens. same
CVE‑2026‑69294 / CVE‑2026‑69299 COM for Windows (legacy RPC) 8.5 High / 9.0 Critical Information‑disclosure and elevation‑of‑privilege via COM object misuse. same
CVE‑2026‑69355, CVE‑2026‑69641, CVE‑2026‑55007, CVE‑2026‑69356, CVE‑2026‑69375, CVE‑2026‑69361, CVE‑2026‑69380, CVE‑2026‑69382, CVE‑2026‑69378 Microsoft Exchange Server 8.0‑9.5 Critical Multiple remote‑code‑execution (RCE) and privilege‑escalation paths in Exchange web services and Outlook‑Web‑Access. same
CVE‑2026‑70178 Microsoft Fabric (micro‑service orchestration) 9.3 Critical Elevation‑of‑privilege in Fabric’s service‑mesh authentication. same
CVE‑2026‑78439 Microsoft Office Graphics Component (Office 365) 9.8 Critical RCE via crafted Office document exploiting a graphics‑rendering bug. same
CVE‑2026‑81955 Windows Graphics Component (Win32) 9.8 Critical RCE in the graphics driver stack (kernel‑mode). same
CVE‑2026‑73006 DirectWrite (Windows graphics) 9.8 Critical RCE via malformed font data. same
CVE‑2026‑77493 Windows Graphics Component (Win32) 9.8 Critical RCE in the graphics subsystem. same
CVE‑2026‑69276 UxTheme library (uxtheme.dll) 9.8 Critical RCE when loading a malicious theme file. same
CVE‑2026‑70351 WebP Image Extension (Windows) 9.8 Critical RCE triggered by a crafted WebP image. same
CVE‑2026‑58600 / CVE‑2026‑58599 HEVC Video Extensions (Windows) 9.8 Critical (both) RCE / privilege‑escalation via malformed video streams. same
CVE‑2026‑81353 / CVE‑2026‑81352 HEIF / Web Media Extensions 9.8 Critical RCE when processing crafted image/media files. same
CVE‑2026‑69408, CVE‑2026‑62706, CVE‑2026‑69386, CVE‑2026‑62744, CVE‑2026‑69601 Windows Media Foundation 9.8 Critical (69601) – multiple RCE paths in media pipeline. same
CVE‑2026‑69586 Windows PDF Viewer 9.8 Critical RCE via malicious PDF. same
CVE‑2026‑78452 / CVE‑2026‑78451 Windows SCSI Class driver 8.5 High / 9.0 Critical Information‑disclosure and privilege‑escalation via SCSI I/O. same
CVE‑2026‑69453, CVE‑2026‑69554, CVE‑2026‑69305, CVE‑2026‑69507, CVE‑2026‑70145, CVE‑2026‑69322, CVE‑2026‑69585, CVE‑2026‑68896, CVE‑2026‑69608, CVE‑2026‑69911, CVE‑2026‑69600 Windows Search Component 8.0‑9.0 Critical Tampering, elevation‑of‑privilege and information‑disclosure via search‑index manipulation. same
CVE‑2026‑69444, CVE‑2026‑69456, CVE‑2026‑69531 Windows Speech API 8.5 High Privilege‑escalation and tampering of speech‑recognition services. same
CVE‑2026‑69397 OpenSSH for Windows 9.8 Critical RCE when processing crafted SSH packets (kernel‑mode). same
CVE‑2026‑65818 / CVE‑2026‑77897 Power Automate / Power Automate Desktop 9.8 Critical / 8.5 High Elevation‑of‑privilege in workflow automation engine. same
CVE‑2026‑78449, CVE‑2026‑78450, CVE‑2026‑69530 Reliable Multicast Transport Driver (RMCAST) 9.8 Critical (all) Kernel‑mode RCE in the multicast transport stack. same
CVE‑2026‑69485, CVE‑2026‑69358, CVE‑2026‑80074, CVE‑2026‑68828, CVE‑2026‑83998, CVE‑2026‑78463, CVE‑2026‑77896, CVE‑2026‑80077, CVE‑2026‑69317 Remote Desktop Client (mstsc) 8.5‑9.8 Critical RCE and DoS via crafted RDP packets. same
CVE‑2026‑69292, CVE‑2026‑69338 Remote Desktop Gateway Service 8.5 High Elevation‑of‑privilege in gateway authentication. same
CVE‑2026‑69989, CVE‑2026‑69827, CVE‑2026‑77505, CVE‑2026‑69782 Windows DNS Server 9.8 Critical (69827, 77505) – remote code execution via DNS query parsing. same
CVE‑2026‑69621, CVE‑2026‑72944, CVE‑2026‑69509 Windows Fax Service 8.5 High Privilege‑escalation via malformed fax data. same
CVE‑2026‑69819 RPC Runtime Library 9.8 Critical RCE in the RPC runtime (kernel). same
CVE‑2026‑66302 Skype for Business / Lync 9.8 Critical RCE via crafted SIP/RTCP packets. same
CVE‑2026‑69854 Spring Cloud Azure 9.8 Critical Elevation‑of‑privilege in Azure Spring Cloud authentication flow. same
CVE‑2026‑67624, CVE‑2026‑77482, CVE‑2026‑67629, CVE‑2026‑67380, CVE‑2026‑62694, CVE‑2026‑62697, CVE‑2026‑62706, CVE‑2026‑62744, CVE‑2026‑67388, CVE‑2026‑67389, CVE‑2026‑67386, CVE‑2026‑67393, CVE‑2026‑67390, CVE‑2026‑67631, CVE‑2026‑67642, CVE‑2026‑68777, CVE‑2026‑77487 Microsoft SQL Server 8.5‑9.8 Critical Multiple RCE and privilege‑escalation bugs in the SQL engine (including buffer overflows in TDS handling). same

Why these matter:

  • All have CVSS ≥ 7 (most ≥ 9) and affect core Microsoft platforms that power Windows 10/11, Windows Server, Azure services, and Office 365.
  • Many target authentication or cryptographic flows (OAuth, token issuance, TLS‑related libraries).
  • Several are kernel‑mode RCEs (RMCAST, DNS, SCSI, UxTheme, OpenSSH, RPC) – the most dangerous class of bugs.

2️⃣ Actively‑exploited zero‑days & supply‑chain attacks (Priority 2)

CVE Component / ecosystem CVSS Exploit status Notes
CVE‑2026‑78133 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported (no public exploit yet, but security‑researcher alerts). Tenable plugin: https://www.tenable.com/plugins/nessus/343509
CVE‑2026‑78134 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343508
CVE‑2026‑78131 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343506
CVE‑2026‑78127 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343502
CVE‑2026‑78126 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343505
CVE‑2026‑78124 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343501
CVE‑2026‑78130 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343500
CVE‑2026‑78132 Linux kernel (Debian 12/14 – strongSwan) – local privilege escalation 9.8 Critical Active exploitation reported. Tenable plugin: https://www.tenable.com/plugins/nessus/343498
CVE‑2026‑76560 Nessus local plugin (Unix) – privilege escalation 7.5 High No public exploit, but flagged as “critical” by Tenable. https://www.tenable.com/plugins/nessus/343504

All of the above are kernel‑level privilege‑escalation bugs in the same Debian/strongSwan code path, indicating a coordinated discovery/exploitation campaign targeting Linux servers.


3️⃣ Massive ransomware campaigns / APT activity (Priority 3)

Campaign / Group Recent activity (Sept 2026) Ransomware type Notable victims / sectors Comments
Chaos (group) Blog post “evergenbio.com” – victim disclosed on Sept 6 2026. Ransomware (custom encryptor) Healthcare‑related SaaS provider (evergenbio). Indicates continued targeting of biotech/health‑tech.
Direwolf Multiple victims reported: eDental Solutions (dental), myLaurel (financial services), RTAD GOV MM (government), eAssist Dental Solutions. Ransomware (double‑extortion) Dental clinics, municipal government, financial services. High‑value data exfiltration, public leak threats.
Panzer Victim: Edacentrum (education). Ransomware (file‑encryption + data‑leak) University/college network. Shows education sector still in scope.
Krybit Blog posts list dozens of compromised domains (e.g., www.mestojilemnice.cz, automotoresrosedal.com.ar, sipresitalia.it, www.hsi.info, sunsea.co.th, resi.com). Ransomware‑as‑a‑service (website defacement + data theft) Various regional businesses (e‑commerce, travel, local services). Large‑scale “ransom‑the‑website” campaign.
APT‑style supply‑chain No explicit supply‑chain breach in the supplied data, but the Microsoft Patch Tuesday notes that many of the flaws were discovered by AI‑driven vulnerability discovery – a sign that nation‑state labs are automating vulnerability hunting. – – Not a ransomware event, but indicates increased state‑backed capability that may feed future APT campaigns.

These campaigns are noteworthy because they affect multiple organizations across health, finance, education, and public‑sector domains within a single week, and they employ double‑extortion tactics that amplify impact.


Quick take‑aways for defenders

  1. Patch immediately – the Microsoft September 2026 Patch Tuesday addresses > 900 CVEs; prioritize the critical authentication, graphics, kernel, and RCE bugs listed above.
  2. Hard‑enforce credential hygiene – CVE‑2026‑68850/83711/84003 demonstrate that compromised OAuth/refresh tokens can lead to full account takeover. Rotate secrets, enforce MFA, and monitor token‑issuance logs.
  3. Update Linux kernels – the series of CVE‑2026‑78xxx kernel privilege‑escalation bugs are actively exploited; upgrade Debian 12/14 (or apply back‑ported patches) without delay.
  4. Audit remote‑code‑execution surfaces – RMCAST, DNS Server, OpenSSH, and RPC runtime bugs give attackers kernel‑level code execution; restrict network exposure, use host‑based firewalls, and enable exploit‑mitigation features (e.g., CFG, ASLR).
  5. Monitor ransomware chatter – the Chaos/Direwolf/Krybit activity spikes suggest attackers are scanning for unpatched services (especially Exchange, Azure AD, and Windows graphics components). Deploy endpoint detection that can flag the known encryption payloads and watch for data‑exfiltration spikes.

References (selected)

These items represent the most consequential security events observed in the last week and should be the focus of immediate remediation and threat‑monitoring efforts.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster