Handler on Duty: Renato Marinho
Threat Level: green
Podcast Detail
SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10086.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
September 2026 Microsoft Patch Tuesday
https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320
Adobe Security Bulletins
https://helpx.adobe.com/security/security-bulletin.html
Security Advisory Ivanti Neurons for ITSM
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US
Fortinet Advisory
https://www.fortiguard.com/psirt/FG-IR-26-174
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Application Security: Securing Web Applications, APIs, and Microservices | Las Vegas | Sep 21st - Sep 25th 2026 |
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Wednesday, September 9th, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich and today I'm recording from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Undergraduate Certificate Program in Cybersecurity Fundamentals. Well today of course it's patched Tuesday and as you probably have heard there are a lot of vulnerabilities that got addressed today. So before I start diving into the individual vendors and what they reported I just want to sort of put out here that don't get despaired over all these different vulnerabilities and the numbers around them. What you really should be looking at is how many products that I actually run need patches. And then don't worry about individual patches, how severe they are, how likely they're going to get exploited. I think your time is really better spent to essentially just patch. And don't worry about all of these details because if you do you won't patch and that's really the last thing you want to do at this point given that we will likely talk tomorrow or later this week about first exploits being reported for the vulnerabilities being patched today. Including of course a couple of these surveys that we may talk about today. I'm trying to keep this podcast short and really focus just on a big picture here. We'll see where it turns out. I'm just starting to record it so I don't really know yet what I'll be exactly talking about. So of course we have to start with Microsoft patched Tuesday and Microsoft got a record 973 different vulnerabilities that they patched. 113 of them are rated critical. Interestingly there are only nine that don't require any user action. So these are these cloud vulnerabilities that Microsoft has already patched. Again big picture here a lot of office vulnerabilities. Outlook has a good number of critical remote code execution vulnerabilities here. There is a webp that image format vulnerability. That's something that shows up everywhere. Very big attack surface. So these are certainly some of the things that you want to focus on. But I think from a patch point of view you definitely want to patch office. You always patch office on patch Tuesday. So nothing really all that new here. And then look at the various services that are being patched here. I think I saw something with like the DNS service. That's always kind of interesting. But overall office is really sort of I think the focus here. The chromium vulnerabilities in Microsoft Edge. Well they already got patched beforehand. And well as long as you just update Edge you'll be good here. And we got Adobe. And with Adobe we got patches for 170 vulnerabilities. Which I think is also a record for Adobe. One of the vulnerabilities I talked about yesterday. And that's a vulnerability in Adobe Commerce. That one has already been exploited since late last week. And is now being patched. There's also a remote code execution vulnerability in Adobe ColdFusion. So that's the other product that's often exposed. And that's why I mentioned it here. We do have patches for Adobe Acrobat and Reader. But they are not code execution vulnerabilities. The most severe one is a privilege escalation issue. So I would rate that definitely lower. And again Adobe Acrobat and Reader. Big attack surface here. Because people often use it to open untrusted PDFs. The others are basically your Illustrator, Photoshop and similar products. If you run them, patch them. But I don't think the attack surface there is terribly large. So definitely not your top priority. If you need to prioritize. And Ivanti joined our patch Tuesday cycle here. There are two products really. The Endpoint Manager. And that particular vulnerability does require authentication. More critical are the vulnerabilities in neurons for ITSM. The "SM", I believe, stands for security management here. These vulnerabilities do allow remote code execution via deserialization. Some of these vulnerabilities do not require any authentication. And the issue with deserialization vulnerabilities is that it's often relatively easy to adapt old exploits to these new vulnerabilities. Once you have the gadget. Once you have it all set up for a particular product. Often it's really just a different endpoint that you need to reach. So definitely get this patched or at least make sure that the product isn't easily reachable. I don't run ITSM. So not sure exactly how exposed it usually is configured. And then we got Fortinet. Fortinet did address a single vulnerability in its Zerotrust product, ZTNA. And the reason I mention it is not because it's terribly severe. It's a machine in the middle issue due to bad certificate validation. But I mention it because, well, first of all, it's a security product. So you would expect a little bit better. And secondly, that kind of trust establishment. Well, that's sort of what Zerotrust is all about. So if Zerotrust doesn't validate certificates correctly, then I guess you shouldn't trust your Zerotrust product. And well, that's it for today. So let me know if you like that little bit more compressed format for these vulnerabilities. Or if you would like more details about specific vulnerabilities as they come up. I'm sure tomorrow we'll have additional bulletins and such that did not get covered today. Just because I didn't run into them. And secondly, well, we sort of run out of time. Thanks and talk to you again tomorrow. Bye. Bye.





