← Writing
·4 min read

Cupertino Gets the Spotlight. Your Patch Queue Gets the Week.

The Signal for September 9, 2026 — Microsoft ships a 973-CVE Patch Tuesday with two exploited zero-days, a CVSS-10 bug is already looting Adobe Commerce stores, and Apple takes the stage under a brand-new CEO. An operator's read on the day.

The SignalCybersecurityApple

Some days the headline and the homework are two different things. Today the cameras point at Cupertino, but the work that will actually land on your desk shipped yesterday afternoon in a patch bundle nobody live-streams. If you run technology, the split is the story: launches get the attention, but maximum-severity flaws get your week.

Microsoft's Patch Tuesday is a monster

Microsoft's September release is one of the largest on record. The company shipped fixes for 973 vulnerabilities on September 8, including two zero-days already exploited in attacks. The volume alone is telling: the same source attributes 723 of the flaws to Windows, 111 to Office, 62 to SQL Server, and the rest across SharePoint, Exchange, and developer tools. The two exploited bugs — CVE-2026-85880 in the Windows Advanced Local Procedure Call component and CVE-2026-81963 in the Windows Update Stack — are both elevation-of-privilege issues that Microsoft rates only "Important," which is exactly the trap.

The operator's take: severity ratings describe the bug; the "exploited in the wild" flag describes your risk. An attacker who already has a foothold uses privilege-escalation bugs like these to go from a single compromised laptop to domain-wide control — so the two "Important" zero-days deserve to jump your queue ahead of a stack of "Critical" flaws nobody is actually using yet. Prioritize by exploitation, not by the color of the label.

A CVSS 10 is already looting online stores

The more specific gut-punch is for anyone running commerce. A maximum-severity flaw in Adobe Commerce and Magento Open Source — CVE-2026-75650, carrying a CVSS score of 10.0 — is under active exploitation, with the security firm Sansec dubbing it StyleSmuggler and tracing zero-day attacks back to September 4. Adobe pushed emergency patches at the start of the week, but the exploitation predates the fix, which means the window where stores were exposed with no defense was real.

The operator's take: an unauthenticated, actively-exploited RCE on the platform that processes your customers' payments is not a maintenance-window item — it is a tonight item, followed by an assumption of compromise. If you run Adobe Commerce, patching is step one; step two is checking for the webshells, rogue admin accounts, and skimmer code that attackers plant during exactly this kind of gap. "We applied the update" is not the same as "we weren't already hit."

Apple's new era starts with a foldable

Now the show. Apple holds its "Surprise and Shine" event today, September 9, where it is expected to unveil the iPhone 18 Pro lineup and its long-rumored first foldable iPhone — and it is the first launch with John Ternus as CEO, having taken over from Tim Cook on September 1. A leadership handoff and a new form factor in the same keynote is a lot of new surface area for a company that usually changes one variable at a time.

The operator's take: the foldable is a consumer story, but the CEO transition and Apple's ongoing scramble to make Siri competitive are the parts that touch your fleet. New hardware means new MDM baselines, new attack surface, and — if the AI features finally ship — new questions about where employee data goes when your executives start dictating to their phones. Enjoy the keynote, but treat any "Apple Intelligence" rollout the way you'd treat any other vendor putting a model between your staff and your data: with a policy, not a shrug.

Also on my radar

The throughline for a Wednesday: three maximum-severity bugs across Windows-adjacent, e-commerce, and enterprise stacks all surfaced in the same 48 hours, and the internet will spend the day talking about a folding phone instead. That's the job — watch the keynote if you like, but the thing that decides whether next week is quiet is the patch backlog nobody applauds. That's the Signal for today.

Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.