Skip to content
feed: live
>_0dayNews
Briefing · 2026-09-07 to 2026-09-13

Week in Review: Sep 7-13, 2026

Record Microsoft Patch Tuesday, two CISA KEV batches, Metasploit absorbing five KEV CVEs, and BlueMoon exploit kit weaponizing zero-days. The gap between disclosure and active exploitation closed again.

tldr.txt
  • Microsoft Patch Tuesday (Sep 9): 974 CVEs patched, two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) added to CISA KEV immediately. Largest Patch Tuesday volume on record.
  • Two CISA KEV batches in three days: Sep 11 added Cisco FMC CVSS 10.0, Citrix, Fortinet PivotC2 RAT, and WatchGuard with ransomware activity. Sep 13 added MikroTik RouterOS, ScreenConnect (CVE-2026-84869), and JFrog Artifactory (CVE-2026-42018).
  • Metasploit released 16 modules including five targeting CISA KEV CVEs. Framework weaponization gap continues to narrow.
  • BlueMoon exploit kit: Chrome renderer plus Windows privilege escalation chain, attributed to espionage actors. Zero-days weaponized and in active use.
  • GitLab CVE-2026-85706 (CVSS 10.0 path traversal): exploited same day as patch release, KEV-listed September 12.
  • SAP CVSS 10.0 unauthenticated RCE in EPP (Sep 10): second CVSS 10.0 from SAP in 2026.

Seven days. Two CISA KEV batches. A record Patch Tuesday. Metasploit modules landing on KEV CVEs within days of listing. This week put numbers to a trend that has been building for months.

The patch cycle: 974 CVEs and two zero-days

Microsoft’s September Patch Tuesday on September 9 was the largest in the company’s recorded history: 974 CVEs across Windows, Office, Azure, and the rest of the portfolio. Two are confirmed exploited. CVE-2026-85880 and CVE-2026-81963, both Windows privilege escalation zero-days, were added to CISA KEV immediately after the advisory. Federal remediation deadline: September 22.

Volume at this scale is not a signal of improved security research; it reflects the surface area of a platform that has expanded faster than its security review process. 974 CVEs in one release cycle is a triage problem for every organization running Windows.

SAP’s September Patch Day (September 10) added another CVSS 10.0 to the week’s total: unauthenticated RCE in Extended Passport Processing. Second CVSS 10.0 from SAP in 2026.

Adobe closed the previously unpatched Magento zero-day alongside StyleSmuggler (CVE-2026-75650). Ivanti released September patches covering six critical RCEs in Neurons for ITSM and auth bypass flaws in Sentry and EPMM. No confirmed exploitation in those Ivanti products at time of publication; Ivanti’s track record means “not yet confirmed” should not be read as low urgency.

KEV: two batches in three days

CISA issued two KEV batches across the week. Both came with short federal deadlines.

September 11 batch. Cisco FMC CVE-2026-20079: CVSS 10.0, authentication bypass, no credentials required, root-level OS access. September 12 federal deadline. Subsequent Cisco Talos reporting identified three distinct threat clusters exploiting the flaw, including Qilin ransomware operators and state-sponsored actors. Fortinet CVE-2025-25249: confirmed exploited with PivotC2 RAT deployed as a post-exploitation payload. Patch shipped January 2026. Nine months. WatchGuard Firebox CVE-2025-14733: KEV-listed with confirmed ransomware gang activity.

September 13 batch. MikroTik RouterOS (September 13 deadline, already expired), ScreenConnect CVE-2026-84869 (September 14 deadline), and JFrog Artifactory CVE-2026-42018. The Artifactory case involved three CVEs chained to deploy a Rust-based backdoor. Attackers reached administrative control via the chain; the Rust backdoor persisted after initial access.

GitLab CVE-2026-85706: path traversal, CVSS 10.0, listed on KEV September 12. GitLab disclosed the patch on September 10. Confirmed exploitation the same day the patch shipped. KEV listing followed within 48 hours.

Exploit tooling: frameworks closing the gap

Metasploit released 16 new modules on September 12. Five of them target CVEs on the CISA KEV catalog: Cisco FMC, PaperCut, SonicWall, TeamCity, and Langflow. That is not a slow trickle from the open-source community. That is a systematic sweep of the current KEV list converted into ready-to-run attack code within the framework.

BlueMoon exploit kit chains a Chrome renderer compromise with a Windows privilege escalation zero-day. Attribution to espionage-aligned actors. Confidence: reported by threat intelligence firms, unconfirmed by a government attribution statement. The exploit chain is functional and in active use.

Chrome logged its seventh exploited zero-day of 2026 during this same week (September 9). That count now averages roughly one confirmed zero-day per month in Chrome across 2026.

Threat actor activity

Nightmare Eclipse appeared September 8 with zero-days targeting CrowdStrike, Nvidia, and Avast, then resurfaced September 11 with a Windows Defender zero-day via ShieldCrash. The threat actor is operating against security tooling specifically. Attribution: unconfirmed.

Check Point CVE-2026-85102 and CVE-2026-85103: two CVSS 9.8 VPN RCE flaws, both patched September 11. Dutch NCSC issued a warning September 13 about imminent exploitation. Confirmed active exploitation at the time of the NCSC warning.

The acceleration

The week’s numbers, condensed: record CVE volume from one vendor, two CISA KEV batches covering infrastructure from routers to CI/CD pipelines, exploit framework modules landing on KEV CVEs within days of listing, and two separate zero-day exploit chains in active use against endpoints.

The September 11 KEV batch had a September 12 federal deadline. One day. The Metasploit modules for some of those same CVEs appeared September 12. The window between disclosure and weaponized code in a public framework has compressed to the point that deadline and weaponization are now simultaneous events, not sequential ones. That is the condition defenders are operating in going into the rest of the quarter.

Sources