Cybersecurity Radar — 2026-09-09
Microsoft has released its largest Patch Tuesday ever, addressing a record-breaking 966–974 vulnerabilities, including two actively exploited zero-days. Simultaneously, attackers are actively leveraging critical flaws in N-able N-central and MikroTik RouterOS to achieve remote code execution and device hijacking. Federal agencies have been issued an emergency deadline of September 11, 2026, to patch newly added CISA Known Exploited Vulnerabilities.
Cybersecurity Radar — 2026-09-09
🔴 Critical Alerts
Microsoft September 2026 Patch Tuesday: Record 966+ Flaws & Two Zero-Days Microsoft released security updates for a record-breaking number of vulnerabilities (reported between 964 and 974 CVEs depending on the source count), including two actively exploited zero-day vulnerabilities. The zero-days, identified as CVE-2026-81963 and CVE-2026-85880, are privilege-escalation flaws being exploited in the wild. Additionally, 20 potentially wormable vulnerabilities were addressed, alongside 58 flaws deemed more likely to be exploited.
CISA Emergency Deadline: September 11, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This addition requires Federal Civilian Executive Branch (FCEB) agencies to apply fixes by September 11, 2026. Private sector organizations are strongly advised to follow this timeline given the active exploitation status.
N-able N-central Unauthenticated RCE (CVE-2026-86218) N-able has issued its fourth hotfix in five weeks for a critical vulnerability in N-central that allows unauthenticated remote code execution. Attackers are actively leveraging this flaw to plant backdoors. The vendor's statements regarding exploitation have been conflicting, necessitating immediate verification and patching for MSPs and IT service providers using N-central.

Threat Landscape
MikroTik RouterOS "MikroTrick" Exploit Chain CERT Polska has warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS. These flaws can be combined into an exploit chain codenamed "MikroTrick," allowing full control of devices without authentication if remote SSH access is enabled. Identified CVEs include CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060.
Active Exploitation of Enterprise RCEs and Supply Chain Risks Remote code execution vulnerabilities across multiple enterprise platforms are being rapidly exploited. Threat actors are combining these with credential-harvesting malware and ongoing supply chain breaches. Organizations are facing urgent requirements to boost monitoring for lateral movement and session hijacking as attackers pivot from initial access to deeper network compromise.
Thomson Reuters C-Track Platform Breach Global information and technology company Thomson Reuters disclosed a breach affecting its C-Track court case-management platform. This incident highlights the ongoing targeting of legal and judicial infrastructure by threat actors seeking sensitive case data.
Vulnerabilities & Patches
Android September 2026 Security Update Google released Android security updates resolving 180 vulnerabilities, including dozens of critical-severity flaws that enable Remote Code Execution (RCE) attacks. Users and enterprise administrators must prioritize these updates to mitigate risks associated with mobile device compromise.
Adobe Commerce Zero-Day Attackers are actively leveraging an Adobe Commerce zero-day vulnerability to achieve RCE. This flaw is part of a broader campaign targeting e-commerce and enterprise platforms for immediate financial gain or data exfiltration. Specific CVE details for this Adobe flaw were not explicitly numbered in the brief but are confirmed as active in-the-wild threats.
Wormable Vulnerabilities in Microsoft Updates In addition to the two zero-days, Microsoft's September update addresses 20 potentially wormable vulnerabilities. These flaws allow malware to spread automatically across networks without user interaction, representing a significant risk for large-scale ransomware or botnet deployment.

Breaches & Incidents
Thomson Reuters C-Track Breach As noted in the threat landscape, Thomson Reuters confirmed a breach of its C-Track platform. While specific scope details were limited in the initial report, the compromise of a court case-management system raises severe concerns regarding the integrity of legal proceedings and the exposure of privileged client information.
Ongoing Supply Chain Compromises Daily recaps indicate that supply chain breaches remain a persistent vector for initial access. Attackers are compromising software updates and third-party integrations to bypass traditional perimeter defenses, leading to widespread credential harvesting and backdoor installation across multiple sectors.
Industry & Policy
Ransomware Acceleration in APAC Group-IB’s 2026 data highlights a significant acceleration of ransomware campaigns across the APAC region. The report emphasizes that traditional response plans are failing under pressure, prompting the release of a new 5-pillar framework designed to improve resilience against rapid encryption and data exfiltration tactics.
AI’s Growing Role in Cyberattacks Data breaches continue to surge in 2026, with artificial intelligence playing a growing role in cyberattacks. "Malicious insider" incidents are also on the rise, suggesting that AI tools are being leveraged not just by external adversaries but also by insiders to evade detection and automate data theft.
What to Watch
- September 11 Deadline: Monitor compliance with the CISA KEV deadline for FCEB agencies; private sector adoption of this timeline is expected to accelerate.
- Router Botnets: Watch for increased DDoS activity or lateral movement originating from unpatched MikroTik devices compromised via the "MikroTrick" chain.
- Wormable Malware: Be alert to new malware variants attempting to exploit the 20 wormable vulnerabilities patched by Microsoft, particularly in unpatched Windows environments.
Reader Action Items
- Patch Immediately: Apply Microsoft’s September 2026 updates immediately, prioritizing the two zero-days (CVE-2026-81963, CVE-2026-85880) and any systems exposed to the internet.
- Update Network Gear: Verify that all MikroTik RouterOS devices are updated to mitigate the "MikroTrick" exploit chain, specifically disabling remote SSH access if updates cannot be applied instantly.
- Review N-able Instances: MSPs and IT providers must verify they have applied the latest hotfixes for N-able N-central to prevent unauthenticated RCE exploitation.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.