- Actively exploited zero-day allowing privilege escalation.
- Critical remote code execution flaw in Windows Shell with CVSS 9.8.
- Critical DNS weakness in Windows Server and Windows 10, likely to be exploited.
- Actively exploited zero-day allowing privilege escalation.
ThreatNoir Morning Brief — September 9
Morning Review in IT Security — September 9, 2026
September 9, 2026 marks a watershed moment in software security as Microsoft releases an unprecedented volume of patches, while attackers continue to exploit critical infrastructure vulnerabilities. The day's security landscape reflects both the accelerating pace of vulnerability discovery and the mounting pressure organizations face in managing remediation efforts.
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corporation has issued updates addressing at least 974 security vulnerabilities across its Windows operating systems and other software products, representing by far the largest single patch batch the company has ever released. The company attributes this surge in vulnerability discovery partly to artificial intelligence tools that are accelerating the identification of security flaws. However, security experts caution that many organizations already struggle with the resource-intensive work of testing and deploying such massive quantities of fixes on a monthly basis. Source: Microsoft Plugs Nearly 1,000 Security Holes
Patch Tuesday Sets Another Record With 974 CVEs
This month's Patch Tuesday release has shattered previous records with 974 Common Vulnerabilities and Exposures addressed in a single update cycle. According to Microsoft's assessment, attackers are already actively exploiting two of these vulnerabilities, while an additional 58 flaws carry elevated risk of exploitation in the near term. This concentration of high-risk patches underscores the urgency with which organizations must prioritize their remediation strategies. Source: Patch Tuesday Sets Another Record With 974 CVEs
Hackers Breach F5 BIG-IP APM Devices to Deploy Linux Rootkit
Threat actors have successfully compromised F5 BIG-IP APM devices to deploy a sophisticated Linux rootkit capable of intercepting PHP file loading and injecting fileless web shells directly into system memory. This technique allows attackers to maintain persistence without writing malicious code to disk, significantly complicating detection and remediation efforts. The exploitation leverages CVE-2025-53521, targeting organizations that have not yet applied critical security updates to their application performance monitoring infrastructure. Source: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
September 2026 represents a landmark month for security patching as Microsoft delivers its largest security update release to date, substantially exceeding previous record-breaking months. The update encompasses critical fixes designed to protect organizational environments from emerging and actively exploited threats. This comprehensive release reflects the intensifying arms race between security researchers and threat actors, with organizations now facing the dual challenge of managing unprecedented patch volumes while addressing already-exploited zero-day vulnerabilities. Source: Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
The convergence of record-breaking patch volumes, actively exploited vulnerabilities, and sophisticated attacks on critical infrastructure signals an inflection point in the threat landscape. Organizations must act with urgency to prioritize remediation of the two actively exploited vulnerabilities and the 58 additional high-risk flaws while simultaneously addressing the broader challenge of patch management at unprecedented scale.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Actively exploited vulnerability in Microsoft products.
- Actively exploited vulnerability in Microsoft products.
- Exploited RCE vulnerability used for initial access
- PoisonedRefreshName given by ESET to the rootkit
- Critical vulnerability in Adobe Commerce allowing arbitrary code execution, actively exploited.
- Zero-day Windows Update Stack Elevation of Privilege Vulnerability, actively exploited.
- HEVC Video Extensions Remote Code Execution Vulnerability.
- Zero-day Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability, actively exploited.