Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure
Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure
Read Time:3 Minute, 31 Second

A crowded week of vulnerability disclosures and active attacks has left defenders with a prioritization problem, not merely a patch-count problem. Microsoft’s September release addressed 973 vulnerabilities, Chrome fixed 230 security issues, and major firewall and VPN vendors disclosed weaknesses with potentially severe consequences. Several bugs were already being exploited, while operational reports suggested that at least one major Windows update could disrupt Remote Desktop Services.

The practical message is clear: organizations need to sequence remediation around exploitation, exposure and asset importance. Treating every update as equally urgent can overwhelm change teams, but delaying internet-facing or actively exploited flaws can leave a direct path into the network.

Active exploitation should move to the front

Microsoft confirmed exploitation of two Windows elevation-of-privilege zero-days, CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update Stack. Although both are rated Important rather than Critical, attackers commonly use privilege-escalation bugs after gaining an initial foothold. Their real-world use should put them ahead of higher-scoring vulnerabilities that are difficult to reach or have no known exploitation.

Google also released Chrome 153 with a fix for CVE-2026-87491, a V8 out-of-bounds write vulnerability seen in attacks. The browser update included five Critical and dozens of High-severity fixes. Because browsers routinely process untrusted web content, enterprises should verify that managed endpoints actually reached the corrected build rather than relying only on an update policy being enabled.

Researchers also described the BlueMoon exploit kit, which combined Chrome and Windows vulnerabilities against government and defense targets. The campaign illustrates why endpoint patching must be coordinated across layers: closing the browser flaw, sandbox escape or privilege-escalation stage can break an exploit chain even if another component remains exposed.

Firewalls and VPNs remain high-value targets

Perimeter devices featured repeatedly. An active campaign exploited a critical FortiOS and FortiSwitchManager weakness to deploy PivotC2, a custom Node.js remote-access tool. Researchers reported large-scale scanning and device compromises, with the malware using outbound encrypted connections and attempting to recover stored VPN credentials.

Palo Alto Networks separately disclosed CVE-2026-0310, a high-severity PAN-OS buffer overflow that could allow unauthenticated root-level code execution on affected hardware appliances. Exploitation is considered complex and no attacks were reported at disclosure, but there is no workaround. Check Point also fixed two maximum-rated VPN issues capable of unauthenticated remote code execution, while MikroTik confirmed exploitation of a RouterOS remote-access flaw.

These products sit at trust boundaries and often hold credentials, routing information and visibility into internal networks. Patch urgency should therefore reflect their role, not only a numerical score. When immediate updates are impossible, teams should restrict management and administrative services to trusted sources, disable unnecessary exposure and intensify logging.

Availability problems complicate safe patching

Administrators reported Remote Desktop Services freezes on multiple Windows Server versions after September cumulative updates. The same update cycle repairs exploited zero-days and a critical RDS code-execution issue, creating a difficult operational tradeoff. Skipping the update may preserve stability while retaining known security exposure; installing it without testing could interrupt remote workloads.

A disciplined response is to test representative server roles quickly, stage deployment by business criticality and prepare a documented recovery path. Security and operations teams should make the exception decision together, with compensating controls and a short review deadline for any postponed systems.

A focused plan for the next patch window

  • Identify internet-facing firewalls, VPN gateways, routers and browsers affected by exploited vulnerabilities.
  • Patch or isolate those assets first, then verify versions and configuration after the change.
  • Hunt for new accounts, altered policies, unexplained outbound TLS traffic and stolen VPN credentials.
  • Use staged testing for updates associated with known availability problems, without turning testing into indefinite delay.

The volume of this week’s disclosures can obscure the most important distinction: some weaknesses represent immediate attack paths, while others are longer-term maintenance risks. Good patch management is not measured by how fast a team processes a list. It is measured by how effectively the team removes the routes attackers are most likely to use and checks whether those routes were already taken.

Source: Cyber Security News weekly bulletin.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure, use the discussion on Forum.

>> forum community

Comments

Leave a Reply