Some days the headline and the homework are two different things. Today the cameras point at Cupertino, but the work that will actually land on your desk shipped yesterday afternoon in a patch bundle nobody live-streams. If you run technology, the split is the story: launches get the attention, but maximum-severity flaws get your week.
Microsoft's Patch Tuesday is a monster
Microsoft's September release is one of the largest on record. The company shipped fixes for 973 vulnerabilities on September 8, including two zero-days already exploited in attacks. The volume alone is telling: the same source attributes 723 of the flaws to Windows, 111 to Office, 62 to SQL Server, and the rest across SharePoint, Exchange, and developer tools. The two exploited bugs — CVE-2026-85880 in the Windows Advanced Local Procedure Call component and CVE-2026-81963 in the Windows Update Stack — are both elevation-of-privilege issues that Microsoft rates only "Important," which is exactly the trap.
The operator's take: severity ratings describe the bug; the "exploited in the wild" flag describes your risk. An attacker who already has a foothold uses privilege-escalation bugs like these to go from a single compromised laptop to domain-wide control — so the two "Important" zero-days deserve to jump your queue ahead of a stack of "Critical" flaws nobody is actually using yet. Prioritize by exploitation, not by the color of the label.
A CVSS 10 is already looting online stores
The more specific gut-punch is for anyone running commerce. A maximum-severity flaw in Adobe Commerce and Magento Open Source — CVE-2026-75650, carrying a CVSS score of 10.0 — is under active exploitation, with the security firm Sansec dubbing it StyleSmuggler and tracing zero-day attacks back to September 4. Adobe pushed emergency patches at the start of the week, but the exploitation predates the fix, which means the window where stores were exposed with no defense was real.
The operator's take: an unauthenticated, actively-exploited RCE on the platform that processes your customers' payments is not a maintenance-window item — it is a tonight item, followed by an assumption of compromise. If you run Adobe Commerce, patching is step one; step two is checking for the webshells, rogue admin accounts, and skimmer code that attackers plant during exactly this kind of gap. "We applied the update" is not the same as "we weren't already hit."
Apple's new era starts with a foldable
Now the show. Apple holds its "Surprise and Shine" event today, September 9, where it is expected to unveil the iPhone 18 Pro lineup and its long-rumored first foldable iPhone — and it is the first launch with John Ternus as CEO, having taken over from Tim Cook on September 1. A leadership handoff and a new form factor in the same keynote is a lot of new surface area for a company that usually changes one variable at a time.
The operator's take: the foldable is a consumer story, but the CEO transition and Apple's ongoing scramble to make Siri competitive are the parts that touch your fleet. New hardware means new MDM baselines, new attack surface, and — if the AI features finally ship — new questions about where employee data goes when your executives start dictating to their phones. Enjoy the keynote, but treat any "Apple Intelligence" rollout the way you'd treat any other vendor putting a model between your staff and your data: with a policy, not a shrug.
Also on my radar
- SAP's own CVSS 10 landed the same day. SAP's September Patch Day includes CVE-2026-44756, a memory-corruption flaw in SAP Extended Passport Processing rated 10.0 — if you run NetWeaver, this belongs on the same emergency list as the Microsoft and Adobe fixes.
- The clock is federal now. CISA added last week's N-able N-central flaw (CVE-2026-86218, CVSS 10.0) to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by September 11 — a hard deadline that private operators should borrow as their own.
- Android's turn. Google's September Android bulletin fixes multiple critical System flaws that allow remote code execution with no user interaction — worth a nudge to your fleet management before the weekend.
The throughline for a Wednesday: three maximum-severity bugs across Windows-adjacent, e-commerce, and enterprise stacks all surfaced in the same 48 hours, and the internet will spend the day talking about a folding phone instead. That's the job — watch the keynote if you like, but the thing that decides whether next week is quiet is the patch backlog nobody applauds. That's the Signal for today.
Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.