MSP Weekly
This week's news, matched to the services you sell. Select your offerings below to see where you sell the fix.
Issue: Week of 07 September 2026 · Last updated: 12 September 2026 14:19 UTC · Subscribe (RSS)
This week's standard client maintenance window
The KEV / critical set every client should patch on their normal cadence — package it as one scheduled window across the portfolio. This week's must-patch list → · why this sells →
My service offerings
Check the services you provide. We'll flag and float this week's items your services fix. Saved on this device only; no account needed.
Where your offerings are the answer this week
- VulnerabilityMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited▲ Your offering
Patch all customer estates for Microsoft's September 2026 release (974 CVEs). Prioritize the two CISA KEV zero-days; schedule the rest by risk and exposure per client stack.
Review client estates for the 19 CVEs in Microsoft's August 2026 Early Security Updates (12 Critical). None are exploited in the wild, so align with each client's normal patching cadence unless their risk profile demands otherwise.
- VulnerabilityKEV: CVE-2026-18577 — N-able N-central (N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability)▲ Your offering
N-able N-central CVE-2026-18577 (incomplete fix for CVE-2026-18556) is under confirmed active exploitation and gives full admin access. Patch every instance to 2026.3.1.7+ immediately, hunt for compromise, and tell every client you manage this for them.
- VulnerabilityPatch bundle: Adobe patch day 2026-08-25 — 38 CVEs across 7 bulletins, exploited in the wild▲ Your offering
Prioritize out-of-band deployment of the four exploited CVEs across client environments this week; schedule the other 34 fixes on the normal cycle.
- VulnerabilityKEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)▲ Your offering
Inventory every client FortiOS/FortiGate instance, map versions against Fortinet’s fixed builds, and schedule upgrades under the KEV window. Flag any appliance already known compromised or left on unsupported builds.
Confirm whether any clients run self-hosted Gitea; if they do, update them to 1.27.1 or later immediately. This KEV addition makes it a priority under BOD 22-01 / 26-04.
- VulnerabilityKEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)▲ Your offering
Check client inventories for self-hosted Metabase instances and patch CVE-2026-72898 to 0.51.5+ immediately; cloud Metabase tenants are unaffected.
- VulnerabilityKEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)▲ Your offering
Inventory every client with Cisco Secure Firewall Management Center; prioritize CVE-2026-20316—hard-coded credentials, unauthenticated remote access, actively exploited, now KEV. Patch or mitigate per Cisco, then check for unexpected logins on affected FMC instances.
- VulnerabilityKEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)▲ Your offering
Inventory clients with on-prem Arista VeloCloud Orchestrator; this is unauthenticated command injection under active exploitation with a KEV deadline. Patch immediately and review orchestrator hosts and managed Edges for signs of compromise.
Flag any client running self-hosted Tenable Security Center (6.6.0–6.8.0) and push the patch across the fleet; cloud-hosted Tenable.io/Tenable.sc-as-a-service clients aren't exposed.
- VulnerabilityKEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)▲ Your offering
Scan all client environments for Langflow deployments — it's often spun up ad hoc for AI prototyping and easy to miss in asset inventories — and patch or take exposed instances offline first.
Roll WordPress core updates (7.0.2/6.9.5/6.8.6) to all client sites this week and check web logs for exploitation attempts on CVE-2026-60137 and CVE-2026-63030, since exploitation started soon after disclosure.
- VulnerabilityKEV: CVE-2026-25089 — Fortinet FortiSandbox (Fortinet FortiSandbox OS Command Injection Vulnerability)▲ Your offering
Check every client's FortiSandbox deployment (4.4.x, 5.0.x) against this KEV pair — unauthenticated command injection with active exploitation means this jumps the patch queue across your book. Flag any instance reachable from the internet as an emergency ticket, not routine maintenance.
- VulnerabilityKEV: CVE-2026-46817 — Oracle E-Business Suite (Oracle E-Business Suite Improper Privilege Management Vulnerability)▲ Your offering
Inventory all client instances of Oracle E-Business Suite, flag any with Oracle Payments exposed to the network, and push the patch as emergency change — this is unauthenticated network exploitation, not a low-priority ticket.
Inventory which clients run on-prem SharePoint Server versus SharePoint Online — only the former needs emergency action for CVE-2026-58644. Push the other three exploited CVEs (2026-56155, 2026-56164, 2026-48561) across the fleet this week; the rest of the 1164 can wait for standard rollout.
Check every client running self-hosted Ignition and update past 8.1.53; the incorrect default permissions let any authenticated user create projects.
Check all client Next.js deployments and update to 15.5.24+ or 16.3.3+; most affected versions are still exposed.
CISA added CVE-2026-81578 and CVE-2026-82078 for PaperCut NG/MF to the KEV catalog: both are confirmed exploited in the wild. Check every client running on-prem PaperCut and ensure they are on the newest patched release.
- VulnerabilityAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell▲ Your offering
Check every client running self-hosted Adobe Commerce or Magento Open Source and push the update now; the zero-day is already being exploited in the wild.
- ClassBreach disclosure filing — 6 items in the last 90 days▲ Your offering
A filing evidences that an incident was material enough to disclose, not how it happened.
- ClassExploit campaign — 2 items in the last 90 days▲ Your offering
Counted from stories carrying no CVE of their own; the CVE-bearing exploit stories are the per-story items above.
- ClassRansomware / extortion claim — 1 item in the last 90 days▲ Your offering
A leak-site listing evidences an intrusion somewhere, and this class is evidenced to encrypt data and inhibit recovery. It does not name the platform that was hit, so the recovery play is named at the category level and no specific backup product is claimed.
- ClassSupply-chain compromise — 1 item in the last 90 days▲ Your offering
The compromise is at a supplier. What it evidences is third-party exposure, not a weakness in your customer's own estate.
Nothing this week names the services you selected. That is the week, not a gap in what you sell — the Coverage Demonstrator shows the worked cases and the 90-day record for every service.
For your client sectors
This week’s stories across all client sectors — pick your sectors in the header above to focus on the industries you serve.
How we write these. Every item names the control that fixes it and the service you offer to deliver it. We never flag a threat without its fix; revenue is a bonus, not the pitch.