Cybersecurity Radar — 2026-09-11
Microsoft has released its largest-ever Patch Tuesday update, addressing a record 974 vulnerabilities, including two actively exploited zero-days. Simultaneously, CISA has issued an emergency directive requiring federal agencies to patch critical flaws in Cisco, Citrix, and Fortinet products by September 12, 2026. Google also patched a sixth Chrome V8 zero-day exploited in the wild, marking a surge in browser-based attacks.
Cybersecurity Radar — 2026-09-11
🔴 Critical Alerts
CISA Emergency Patch Deadline for Network Infrastructure The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch (FCEB) agencies are required to apply patches by September 12, 2026. Private sector organizations are strongly urged to prioritize these updates immediately given the active exploitation in the wild.

Chrome V8 Zero-Day Actively Exploited Google has released an emergency update to patch a critical vulnerability in the Chrome V8 JavaScript engine (CVE-2026-11645). The flaw allows arbitrary code execution inside the sandbox via a crafted HTML page and is being actively exploited in the wild. This marks the sixth Chrome zero-day exploited this year. Users should update to the latest version immediately.

Threat Landscape
Ransomware Payments Hit Multi-Year Low Despite Rising Attacks New data from Group-IB, Chainalysis, and Check Point indicates that while ransomware attacks have risen in 2026, payment rates have dropped to a 23% multi-year low. Organizations are increasingly refusing to pay due to improved resilience and law enforcement interventions, though attacks continue to accelerate across the APAC region.

Boston Scientific Cyberattack Impact Persists Medical device manufacturer Boston Scientific announced it is unlikely to meet its 2026 sales and profit forecasts due to the lingering effects of a cyberattack that occurred in August 2026. While key systems have been restored, the operational disruption continues to impact financial performance, highlighting the long-tail economic damage of healthcare sector breaches.
Vulnerabilities & Patches
Microsoft September Patch Tuesday: Record 974 CVEs Microsoft has addressed a record-breaking 974 vulnerabilities in its September 2026 Patch Tuesday release. This includes two zero-day vulnerabilities (CVE-2026-81963 and CVE-2026-85880) that were actively exploited in the wild. The update also fixes 119 critical flaws, with security teams advised to prioritize updates for Windows Server and Exchange environments.

Android Security Update Patches 180 Flaws Google’s September Android security bulletin resolves 180 vulnerabilities, including dozens of critical-severity flaws. These updates are rolling out to Pixel devices and other OEMs, addressing issues that could allow for remote code execution or privilege escalation.
Breaches & Incidents
Thomson Reuters C-Track Platform Breach Global information services firm Thomson Reuters disclosed a breach of its C-Track court case-management platform. The incident affects legal professionals and court systems using the platform for case management. Details on the specific data exposed remain under investigation, but the breach underscores risks in specialized legal-tech infrastructure.
Industry & Policy
Federal Patching Mandate for KEV Catalog Items In addition to the immediate deadline for Cisco/Citrix/Fortinet, CISA continues to enforce strict timelines for federal agencies to patch all items in the KEV catalog. This regulatory pressure is driving faster remediation cycles across government sectors, with non-compliance potentially triggering audit findings.
What to Watch
- Post-Patch Exploitation: Monitor for increased exploitation attempts against Windows Server and Exchange following the massive September Patch Tuesday release, particularly targeting unpatched legacy systems.
- Browser-Based Attacks: With six Chrome zero-days exploited in 2026, expect continued focus on client-side exploits via malicious websites and drive-by downloads.
- Healthcare Sector Resilience: As Boston Scientific demonstrates, healthcare breaches have prolonged financial impacts; watch for similar long-term earnings warnings from other medical device manufacturers hit by recent ransomware campaigns.
Reader Action Items
- Patch Immediately: Apply Microsoft September patches (especially for Windows Server/Exchange) and Google Chrome updates today. If you use Cisco, Citrix, or Fortinet products, verify you are not exposed to the newly KEV-listed vulnerabilities before the Sept 12 federal deadline.
- Review Ransomware Response Plans: Given the rise in attacks despite lower payments, ensure your offline backups are tested and your incident response plan accounts for long-term operational disruption, not just data recovery.
- Audit Legal-Tech Vendors: If your organization uses Thomson Reuters C-Track or similar case-management platforms, request breach status updates from your vendor and monitor for suspicious activity in user accounts.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.