Podcast Detail

SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10086.mp3

Podcast Logo
Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Wednesday, September 9th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich and today I'm recording from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Undergraduate Certificate Program in
 Cybersecurity Fundamentals. Well today of course it's
 patched Tuesday and as you probably have heard there are
 a lot of vulnerabilities that got addressed today. So before
 I start diving into the individual vendors and what
 they reported I just want to sort of put out here that
 don't get despaired over all these different
 vulnerabilities and the numbers around them. What you
 really should be looking at is how many products that I
 actually run need patches. And then don't worry about
 individual patches, how severe they are, how likely they're
 going to get exploited. I think your time is really
 better spent to essentially just patch. And don't worry
 about all of these details because if you do you won't
 patch and that's really the last thing you want to do at
 this point given that we will likely talk tomorrow or later
 this week about first exploits being reported for the
 vulnerabilities being patched today. Including of course a
 couple of these surveys that we may talk about today. I'm
 trying to keep this podcast short and really focus just on
 a big picture here. We'll see where it turns out. I'm just
 starting to record it so I don't really know yet what
 I'll be exactly talking about. So of course we have to start
 with Microsoft patched Tuesday and Microsoft got a record 973
 different vulnerabilities that they patched. 113 of them are
 rated critical. Interestingly there are only nine that don't
 require any user action. So these are these cloud
 vulnerabilities that Microsoft has already patched. Again big
 picture here a lot of office vulnerabilities. Outlook has a
 good number of critical remote code execution vulnerabilities
 here. There is a webp that image format vulnerability.
 That's something that shows up everywhere. Very big attack
 surface. So these are certainly some of the things
 that you want to focus on. But I think from a patch point of
 view you definitely want to patch office. You always patch
 office on patch Tuesday. So nothing really all that new
 here. And then look at the various services that are
 being patched here. I think I saw something with like the
 DNS service. That's always kind of interesting. But
 overall office is really sort of I think the focus here. The
 chromium vulnerabilities in Microsoft Edge. Well they
 already got patched beforehand. And well as long
 as you just update Edge you'll be good here. And we got
 Adobe. And with Adobe we got patches for 170
 vulnerabilities. Which I think is also a record for Adobe.
 One of the vulnerabilities I talked about yesterday. And
 that's a vulnerability in Adobe Commerce. That one has
 already been exploited since late last week. And is now
 being patched. There's also a remote code execution
 vulnerability in Adobe ColdFusion. So that's the
 other product that's often exposed. And that's why I
 mentioned it here. We do have patches for Adobe Acrobat and
 Reader. But they are not code execution vulnerabilities. The
 most severe one is a privilege escalation issue. So I would
 rate that definitely lower. And again Adobe Acrobat and
 Reader. Big attack surface here. Because people often use
 it to open untrusted PDFs. The others are basically your
 Illustrator, Photoshop and similar products. If you run
 them, patch them. But I don't think the attack surface there
 is terribly large. So definitely not your top
 priority. If you need to prioritize. And Ivanti joined
 our patch Tuesday cycle here. There are two products really.
 The Endpoint Manager. And that particular vulnerability does
 require authentication. More critical are the
 vulnerabilities in neurons for ITSM. The "SM", I believe, stands for
 security management here. These vulnerabilities do allow
 remote code execution via deserialization. Some of these
 vulnerabilities do not require any authentication. And the
 issue with deserialization vulnerabilities is that it's
 often relatively easy to adapt old exploits to these new
 vulnerabilities. Once you have the gadget. Once you have it
 all set up for a particular product. Often it's really
 just a different endpoint that you need to reach. So
 definitely get this patched or at least make sure that the
 product isn't easily reachable. I don't run ITSM.
 So not sure exactly how exposed it usually is
 configured. And then we got Fortinet. Fortinet did address
 a single vulnerability in its Zerotrust product, ZTNA. And
 the reason I mention it is not because it's terribly severe.
 It's a machine in the middle issue due to bad certificate
 validation. But I mention it because, well, first of all,
 it's a security product. So you would expect a little bit
 better. And secondly, that kind of trust establishment.
 Well, that's sort of what Zerotrust is all about. So if
 Zerotrust doesn't validate certificates correctly, then I
 guess you shouldn't trust your Zerotrust product. And well,
 that's it for today. So let me know if you like that little
 bit more compressed format for these vulnerabilities. Or if
 you would like more details about specific vulnerabilities
 as they come up. I'm sure tomorrow we'll have additional
 bulletins and such that did not get covered today. Just
 because I didn't run into them. And secondly, well, we
 sort of run out of time. Thanks and talk to you again
 tomorrow. Bye. Bye.