Blackpoint Cyber Threat Notice: September 2026 Patch Tuesday Updates

Overview 

Microsoft 

Microsoft’s September 2026 Patch Tuesday addressed more than 950 vulnerabilities, its largest release to date, including two elevation-of-privilege zero-days confirmed as exploited in the wild. 

CVE-2026-81963 | CVSS 7.8 High | Elevation of Privilege vulnerability impacting Windows Update Stack 

  • Improper link resolution before file access (“link following”) allows an authenticated attacker to elevate privileges locally to SYSTEM. 
  • Microsoft confirmed exploitation in the wild. This vulnerability is typically leveraged in post-compromise activity, where an attacker with existing access uses the flaw to gain full administrative control. 

CVE-2026-85880 | CVSS 7.8 High | Elevation of Privilege vulnerability impacting Windows Advanced Local Procedure Call (ALPC) 

  • A flaw in the ALPC subsystem, which handles internal messaging between Windows processes, provides an authenticated attacker with a reliable path to local privilege escalation. 
  • Microsoft confirmed exploitation in the wild. 

Specific details related to exploitation have not been released; likely in an attempt to provide time for updates to occur.  

The increase in recently disclosed vulnerabilities is very likely tied to Microsoft’s use of AI-powered vulnerability discovery system to identify more security vulnerabilities.  

SAP 

SAP released 19 new Security Notes as part of its September 2026 Security Patch Day, including two critical, unauthenticated vulnerabilities affecting core kernel components used across the majority of SAP deployments. 

CVE-2026-44756 (OVERPASS) | CVSS 10.0 Critical | Memory corruption vulnerability impacting SAP Extended Passport (EPP) Processing 

  • Missing boundary validation during deserialization of EPP data allows an unauthenticated, remote attacker to trigger memory corruption, enabling arbitrary command execution with administrative privileges, credential harvesting, and modification of SAP data and binaries. 
  • No public exploitation has been confirmed at the time of writing. The unauthenticated network attack vector, administrative-level impact, and maximum CVSS score make this the highest-priority SAP vulnerability this cycle. 

CVE-2026-58240 (S4GET) | CVSS 9.8 Critical | Missing authentication vulnerability impacting SAP NetWeaver Message Server 

  • The Message Server does not sufficiently validate the authenticity of application server components during registration, allowing an unauthenticated attacker with network access to register a rogue component and perform unauthorized actions across the SAP landscape. 
  • No evidence of active exploitation has been reported at this time. 

Adobe 

Adobe released an emergency, out-of-band fix for a critical zero-day affecting its e-commerce platforms. 

CVE-2026-75650 (StyleSmuggler) | Critical | Arbitrary code execution vulnerability impacting Adobe Commerce and Magento Open Source 

  • Adobe confirms this vulnerability is being actively exploited to deploy backdoors on vulnerable servers. Researchers have observed exploitation used to install a backdoor disguised as legitimate NTP traffic, as well as a separate PHP web shell deployed by an unrelated threat actor. 
  • Affects Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9. 

Cisco 

Cisco disclosed a critical, unauthenticated remote code execution vulnerability affecting Nexus 9000 Series data center switches. 

CVE-2026-20212 | CVSS 9.8 Critical | Remote code execution vulnerability impacting Cisco Nexus 9000 Series Switches with Silicon One ASICs 

  • Two TCP ports (43210 and 43211) tied to the Silicon One integration are reachable within the default Layer 3 VRF, allowing an unauthenticated, remote attacker to send crafted input and execute code with root privileges. Exploitation can also crash the affected process and cause the switch to reload. 
  • Cisco has not identified public exploitation or proof-of-concept code at this time, but released both a permanent fix and a temporary Live Protect mitigation given the severity and reach of the vulnerability. 

What is Blackpoint doing? 

As the threat landscape shifts, Blackpoint stays ahead by building and deploying real-time detections tuned to the latest adversary tradecraft. When threats are identified, Blackpoint takes decisive action by hunting down and actioning every associated IOC across customer environments before attackers can establish a foothold or move laterally. 

Recommendations 

  • Immediate Action: Apply the SAP, Microsoft, Adobe, and Cisco patches referenced above, prioritizing SAP OVERPASS/S4GET and the Adobe StyleSmuggler hotfix given their unauthenticated attack paths and confirmed exploitation. 
  • Apply the Adobe Commerce/Magento hotfix immediately and rotate all administrator, API, OAuth, database, and SSH credentials given confirmed in-the-wild exploitation. 
  • Restrict internet exposure of SAP ICM and Message Server ports; SAP kernel services should not be directly reachable from the internet. 
  • Apply Cisco’s infrastructure access control list (iACL) workaround or Live Protect shield on Nexus 9000 switches with Silicon One ASICs until the fixed NX-OS release can be deployed. 
  • Deploy Microsoft’s September updates promptly, prioritizing the two exploited elevation-of-privilege flaws even though they carry an Important rather than Critical rating. 
  • Review authentication and registration logs for anomalous activity against SAP Message Server instances, and monitor for unexpected local privilege escalation on Windows endpoints. 

References 

DATE PUBLISHEDSeptember 8, 2026
AUTHORAndi Ursry

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY