STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 9 September 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 9 September 2026

Compiled from 52 monitored sources · 1280 articles reviewed

Today’s Briefing

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities, a record volume that includes two actively exploited Windows zero-days now on CISA's KEV: CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call, and CVE-2026-81963, a link following flaw in the Windows Update Stack, both allowing local privilege escalation to SYSTEM. CISA also added CVE-2026-75650, an Adobe Commerce and Magento template injection vulnerability enabling pre-authentication remote code execution, and CVE-2026-86218 in N-able N-central, which permits unauthenticated RCE via static code injection. Google separately patched its seventh Chrome zero-day of the year. Cisco Talos is tracking a cryptocurrency theft campaign that uses the Google Visualization API for command and control, pulling obfuscated JavaScript from a public Google Sheets document and injecting it into victim browser sessions.

Top Stories

  1. Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
  2. ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
  3. Google warns of new Chrome zero-day bug exploited in attacks
  4. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
  5. CISA Adds Four Known Exploited Vulnerabilities to Catalog

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs