CrewCrew
FeedSignalsMy Subscriptions
Get Started
Cybersecurity Radar

Cybersecurity Radar — 2026-09-13

  1. Signals
  2. /
  3. Cybersecurity Radar

Cybersecurity Radar — 2026-09-13

Cybersecurity Radar|September 13, 2026(2h ago)3 min read9.3AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

Microsoft’s September 2026 Patch Tuesday has concluded with a record-breaking release of over 960 vulnerabilities, including two actively exploited zero-days and a "SigRed successor," forcing immediate patching prioritization. Simultaneously, a critical GitLab path traversal flaw (CVE-2026-85706) is being actively probed in the wild, while the EU Cyber Resilience Act’s new vulnerability reporting mandates officially took effect on September 11.

Cybersecurity Radar — 2026-09-13


🔴 Critical Alerts

1. Microsoft Patch Tuesday: Record CVE Count & Active Zero-Days Microsoft released security updates for a record-breaking number of vulnerabilities in September 2026, with counts reported between 964 and 974 depending on the tracker. This release includes two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. Both are privilege escalation flaws being used in the wild. Additionally, analysts have identified a "SigRed successor" among the patched bugs, raising concerns about wormable risks. IT teams are urged to prioritize these patches immediately due to active exploitation.

Microsoft Patch Tuesday September 2026
Microsoft Patch Tuesday September 2026

2. Critical GitLab Path Traversal (CVE-2026-85706) A critical vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) is currently witnessing active in-the-wild probes. Identified as CVE-2026-85706, this path traversal issue has a CVSS score of 10.0. It allows an unauthenticated user to read arbitrary files from the GitLab server under certain conditions via the repository commits API. Affected versions include all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Probes began as early as September 11, 2026.

GitLab Vulnerability
GitLab Vulnerability

tenable.com

tenable.com


Threat Landscape

Active Probing of GitLab Infrastructure Following the disclosure of CVE-2026-85706, threat actors have rapidly moved to exploit or probe vulnerable GitLab instances. watchTowr reports that scanning and probing activity started within hours of disclosure, targeting the repository commits API to exfiltrate sensitive files. This rapid weaponization highlights the critical need for immediate patching of GitLab servers exposed to the internet.


Vulnerabilities & Patches

1. Check Point VPN Remote Code Execution Check Point has released patches for two critical VPN vulnerabilities: CVE-2026-85102 and CVE-2026-85103. These flaws could potentially lead to remote code execution (RCE). Organizations using Check Point VPN solutions are advised to apply these updates immediately to mitigate the risk of unauthorized access.

Check Point Security
Check Point Security

2. Android September 2026 Security Update Google’s Android security updates for September 2026 resolve 180 vulnerabilities. The update includes dozens of critical-severity flaws. Users and device manufacturers are encouraged to roll out these patches to protect against potential local privilege escalation and remote code execution attacks.

Android Update
Android Update

securityweek.com

securityweek.com

securityweek.com

securityweek.com


Breaches & Incidents

Thomson Reuters C-Track Breach Disclosure Global information and technology company Thomson Reuters has disclosed a breach affecting its C-Track court case-management platform. While specific details on the scale and data exposed are still emerging, this incident underscores the ongoing risk to legal and judicial infrastructure platforms. This was highlighted in Check Point Research's latest threat intelligence report for the week of September 7th.


Industry & Policy

EU Cyber Resilience Act Reporting Requirements Take Effect As of September 11, 2026, the EU Cyber Resilience Act’s vulnerability reporting requirements are now in effect. Software vendors are now legally required to report actively exploited flaws within as little as 24 hours. This regulation significantly increases the compliance burden for vendors operating in or selling to the EU, necessitating robust software bill of materials (SBOM) and incident response processes.


What to Watch

  • Post-Patch Instability: Monitor Windows Server environments (2019, 2022, 2025) for Remote Desktop Services (RDS) failures following the September Patch Tuesday installations, as initial reports indicate connectivity issues requiring hard resets in some cases.
  • GitLab Exploitation Escalation: Watch for confirmed data exfiltration incidents stemming from CVE-2026-85706 probes, particularly in unpatched enterprise environments.
  • EU CRA Compliance Audits: Expect early enforcement actions or compliance inquiries from EU regulators regarding the new 24-hour reporting mandates for software vendors.

Reader Action Items

  1. Patch Immediately: Apply Microsoft September 2026 updates, prioritizing CVE-2026-81963 and CVE-2026-85880 due to active exploitation. Also, upgrade GitLab instances to versions 19.1.8, 19.2.6, or 19.3.2 immediately.
  2. Check Point VPN Updates: Verify that all Check Point VPN devices are updated to address CVE-2026-85102 and CVE-2026-85103.
  3. Review EU CRA Readiness: If your organization sells software in the EU, review your incident response playbook to ensure you can identify and report actively exploited vulnerabilities within the mandated 24-hour window.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QWhich threat actors are exploiting the GitLab flaw?
  • QHow severe is the new SigRed successor vulnerability?
  • QAre there workarounds for the Check Point VPN RCE?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.