Patch Tuesday: record 974 CVEs, two exploited zero-days on CISA KEV, federal deadline September 22, SigRed-successor DNS RCE, 20 potentially wormable flaws      ShieldCrash: Nightmare Eclipse bypassed the ShieldBreak patch within hours of it shipping — third Defender EoP bypass, Windows fully patched still vulnerable      SAP OVERPASS CVE-2026-44756 CVSS 10.0: unauthenticated OS command execution with SAP admin privileges on any affected SAP kernel system      Patch Tuesday: record 974 CVEs, two exploited zero-days on CISA KEV, federal deadline September 22, SigRed-successor DNS RCE, 20 potentially wormable flaws      ShieldCrash: Nightmare Eclipse bypassed the ShieldBreak patch within hours of it shipping — third Defender EoP bypass, Windows fully patched still vulnerable      SAP OVERPASS CVE-2026-44756 CVSS 10.0: unauthenticated OS command execution with SAP admin privileges on any affected SAP kernel system     
CyberSipTM
Intelligence without the noise
Issue No. 126
September 9, 2026
3 items · past 24h
<5 min read
Today's picture

Microsoft's September 2026 Patch Tuesday addressed a record 974 CVEs including two exploited zero-days — CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack — both now on CISA KEV with a September 22 federal deadline, alongside a DNS Server RCE described as a SigRed successor and 20 potentially wormable flaws. Within hours of Patch Tuesday shipping, the researcher Nightmare Eclipse published ShieldCrash, demonstrating that today's fix for ShieldBreak CVE-2026-69414 is itself bypassable, the third consecutive Defender privilege escalation bypass from this researcher. SAP released an emergency update for OVERPASS, CVE-2026-44756 at CVSS 10.0, a memory corruption flaw in the SAP kernel's Extended Passport processing that allows an unauthenticated remote attacker to execute arbitrary OS commands with full SAP administrative privileges.

Today's intelligence
3 items
01 HighPatch TuesdaySeptember 2026
September Patch Tuesday: 974 CVEs, two exploited zero-days on CISA KEV, a SigRed-successor DNS RCE, and 20 potentially wormable flaws
CVE-2026-85880 (Windows ALPC EoP) and CVE-2026-81963 (Windows Update Stack EoP) were exploited before today. Both are now on CISA KEV with a September 22 deadline. Prioritize the DNS Server RCE for any organization running internet-facing Windows DNS. Apply the full update; those three patches come first.
Zero-day 1CVE-2026-85880
Windows ALPC EoP
exploited, CISA KEV
Zero-day 2CVE-2026-81963
Update Stack EoP
exploited, CISA KEV
first-ever zero-day
in this component
Fed deadlineSeptember 22, 2026
Also notableDNS Server RCE
(SigRed successor)
20 wormable CVEs
110+ critical
Total974 CVEs — record
Microsoft's September 9 Patch Tuesday is the company's largest ever at 974 CVEs, spanning Windows (723), Office (222), SQL Server (62), developer tools (22), SharePoint (16), Azure (12), and Exchange (9). Two vulnerabilities were already being exploited before the patches shipped. CVE-2026-85880 is a Windows Advanced Local Procedure Call elevation of privilege that lets a low-privileged local attacker reach SYSTEM through a link-following defect. CVE-2026-81963 is the same class of flaw in the Windows Update Stack, the component that installs Windows updates: the first zero-day ever found there across seven known flaws in that component since 2022. No attack chain details are public for either. Both are now on CISA KEV with a federal deadline of September 22. The DNS Server RCE described by researchers as a SigRed successor is the third priority: any internet-facing Windows DNS Server is a potential unauthenticated remote exploitation target, matching the scope that made SigRed a wormable-class advisory in 2020. The release also addresses 20 vulnerabilities assessed as potentially wormable and more than 110 rated critical.
Both exploited zero-days are post-access privilege escalation tools: second-stage techniques that convert user-level access into SYSTEM. The Windows Update Stack zero-day is particularly pointed: it targets the mechanism through which defenders apply patches. An attacker with existing access who exploits CVE-2026-81963 during a patch cycle could interfere with that application. The DNS Server RCE applies to anyone running Windows Server as a DNS resolver, which is most enterprise environments. Treat that patch with the same urgency as a wormable network flaw regardless of whether the server faces the internet directly.
  • Apply September Patch Tuesday updates. Prioritize the two KEV zero-days (CVE-2026-85880 and CVE-2026-81963) and the Windows DNS Server RCE. Federal deadline is September 22; treat that as an enterprise ceiling, not a target date.
  • For any internet-facing Windows DNS Server, deploy the DNS Server patch ahead of the general endpoint rollout. An unauthenticated remote RCE against a public DNS server warrants perimeter-patch urgency.
974 CVEs. Two exploited before today, both on CISA KEV. A wormable-class DNS Server RCE. Apply the full update — the zero-days and DNS patch come first. September 22 federal deadline.
02 HighShieldCrashNightmare Eclipse
ShieldCrash: Nightmare Eclipse bypassed the ShieldBreak patch within hours of it shipping — the third consecutive Defender EoP bypass from this researcher
Today's Patch Tuesday closed ShieldBreak CVE-2026-69414. Hours later, Nightmare Eclipse published ShieldCrash showing the fix is bypassable under specific conditions, with arbitrary file read as SYSTEM on the latest fully patched Windows. The series is now RoguePlanet → ShieldBreak → ShieldCrash. Apply today's patch regardless: ShieldBreak is closed. ShieldCrash is the next item to watch.
ShieldCrashBypass of today's
ShieldBreak patch
No CVE yet
ShieldBreakCVE-2026-69414
Patched today
ImpactArbitrary file read
as SYSTEM on
latest patched
Windows
SeriesRoguePlanet
ShieldBreak (bypass)
ShieldCrash (bypass
of bypass fix)
StatusNo patch yet
Microsoft notified
Today's Patch Tuesday included Microsoft's long-awaited fix for CVE-2026-69414, tracked in this brief's Still Watching section since Issue 113. ShieldBreak was itself a patch bypass for the prior RoguePlanet Defender flaw. Within hours of Patch Tuesday shipping, Nightmare Eclipse published ShieldCrash, a proof-of-concept showing that the ShieldBreak fix is bypassable under specific conditions. The researcher stated directly that Microsoft missed a code path where ShieldBreak can still be triggered. The PoC demonstrates arbitrary file read as SYSTEM on the latest fully patched Windows. No CVE has been assigned. Microsoft has been notified. Three prior Nightmare Eclipse series disclosures were exploited before patches arrived. Today's patch does close ShieldBreak's specific exploitation path; ShieldCrash is an adjacent path to the same underlying issue in the Microsoft Malware Protection Engine.
Organizations that applied today's Patch Tuesday to close ShieldBreak should understand the underlying Defender engine vulnerability is not fully resolved. The pattern across this series: each Microsoft fix addressing the specific technique demonstrated while leaving adjacent paths open, mirroring what played out with PaperCut's two emergency patches and the ProxyNotShell/ProxyShell cycle. The appropriate response is to apply today's patch, which closes ShieldBreak, keep behavioral detection rules for the series active, and treat ShieldCrash as the next patching priority the moment Microsoft publishes an advisory.
  • Apply today's Patch Tuesday update, which closes ShieldBreak CVE-2026-69414. Despite ShieldCrash, applying the fix removes a specific known exploitation path that has been public since Issue 113.
  • Monitor Microsoft's Security Response Center for a ShieldCrash advisory and CVE assignment. Apply the fix on the day it ships. Maintain behavioral endpoint detection specifically for CVE-2026-69414 and the Nightmare Eclipse series; signature-based detections for ShieldBreak will not catch ShieldCrash variants.
The fix shipped this morning. The bypass dropped this afternoon. Apply today's patch anyway — ShieldBreak is closed. ShieldCrash is the residue. Watch MSRC and patch it the day the advisory lands.
03 CriticalSAP OVERPASSCVE-2026-44756
SAP OVERPASS CVE-2026-44756 CVSS 10.0: unauthenticated attackers can run OS commands as the SAP admin user on any affected SAP kernel system
Memory corruption in SAP's Extended Passport processing. No authentication. No user interaction. Network-based. An attacker sends a crafted payload, triggers a heap overflow in the SAP kernel, and achieves OS command execution as the SAP administrative user — which means full access to every business process, database, and credential on that system. No exploitation confirmed yet. The window to patch before that changes is short.
CVECVE-2026-44756
CVSS 10.0
OVERPASS (Onapsis)
ComponentSAP kernel
Extended Passport
(EPP) processing
AttackUnauthenticated
Network-based
No interaction
ResultArbitrary OS commands
as SAP admin user
ExploitationNot confirmed yet
SAP released an emergency patch today for CVE-2026-44756, named OVERPASS by discoverers Onapsis. The flaw sits in the SAP kernel's Extended Passport (EPP) processing: EPP is the mechanism SAP systems use to propagate user identity between components. A missing boundary check in the EPP parsing code allows an unauthenticated attacker to trigger a heap overflow with a specially crafted network payload, achieving arbitrary OS command execution in the context of the SAP administrative user. That user has unrestricted access to the SAP application, its configuration, and its underlying database. No exploitation in the wild has been confirmed. SAP Note 3500180 contains the specific kernel and EPP component versions that include the fix.
SAP systems hold financial records, HR data, procurement workflows, and supply chain configurations for many large enterprises and governments. OS-command-level access to the SAP administrative account exposes all of it in a single exploitation step. The prior CVSS 10.0 SAP flaw this brief tracked (CVE-2026-58231, Issue 107), moved from advisory to confirmed exploitation at scale within days. Unauthenticated network-based SAP kernel flaws have a documented and short exploitation window. No confirmation today does not mean the window is wide.
  • Apply the SAP patch for CVE-2026-44756 immediately. Check SAP Note 3500180 for the specific kernel and EPP versions containing the fix. Treat this as an emergency patch given the unauthenticated network exploitation path and CVSS 10.0 rating.
  • As an interim network-layer control, restrict access to SAP system ports and the EPP endpoint to authorized application servers and client networks. OVERPASS requires network reachability to the EPP processing component; limiting that access reduces the exposed population while patching proceeds.
No auth. Network-based. OS commands as the SAP admin user. CVSS 10.0. The last CVSS 10.0 SAP flaw this brief tracked was confirmed exploited at scale within days of disclosure. Patch now. Restrict the EPP endpoint to trusted networks while you do.
Cross-source standouts
01
The Nightmare Eclipse series and the incomplete-patch problem: three bypasses of the same Defender vulnerability
RoguePlanet was the original Defender flaw. ShieldBreak bypassed its fix. ShieldCrash bypasses ShieldBreak's fix, arriving hours after the patch shipped. The same pattern has appeared across this brief's coverage: PaperCut's first emergency patch was bypassed before the second shipped; ProxyNotShell followed ProxyShell. What makes ShieldCrash distinctive is the timing: the researcher published the bypass the same day as the fix, suggesting the bypass path was already identified before the patch released. The operational response is unchanged: apply today's patch, which closes the specific ShieldBreak exploitation path, keep behavioral detection for the series active, and treat ShieldCrash as the next patching queue item the moment Microsoft assigns it a CVE.
02
974 CVEs and the triage problem: what to patch first when everything is marked urgent
A 974-CVE Patch Tuesday creates a prioritization problem that blanket urgency does not solve for teams with change management requirements and maintenance windows. The framework: prioritize confirmed exploitation first (CVE-2026-85880 and CVE-2026-81963), then wormable network-reachable flaws for your specific exposed services (the DNS Server RCE if you run external-facing Windows DNS), then critical-rated RCE against internet-facing components. Apply everything eventually, but triage based on exploitation status and your specific exposure. If your organization runs internet-facing Windows DNS, that patch goes before the endpoint rollout; it is the one item in this release that most directly resembles an imminent wormable threat.
Still watching
Days 3–7+
StyleSmuggler CVE-2026-75650 (Issue 125 · CVSS 10.0, Magento/Adobe Commerce, hotfix APSB26-146 released September 7) — apply composer patch VULN-39341 from repo.magento.com. Rotate encryption key and all derived credentials including payment gateway API keys. Run eComscan for the Linux backdoor.
Day 3
PaperCut CVE-2026-81578 / CVE-2026-82078 (Issues 119–122 · CISA KEV, education sector targeted, credential harvesting confirmed) — apply Emergency Patch Release 2. Restrict web access. Check Windows event logs for SAM hive extraction. Monitor for patch Release 3.
Day 7+
SonicWall SMA1000 CVE-2026-83548 / CVE-2026-83549 (Issue 123 · zero-day chain, no IoCs) — apply hotfixes 12.4.3-03526 or 12.5.0-02952. Consider re-imaging any internet-accessible appliance that was unpatched during active exploitation given history of persistent malware in prior SMA1000 campaigns.
Day 7+
GitLab CVE-2026-19478 (Issue 111/114 · confirmed exploited, no patch for 18.2–18.10 through mid-November 2026) — restrict /api/graphql. Hunt @gl_introduced in web logs. Patch available for 19.x and 18.11+ branches.
Day 7+