BaltimoreCyber Brief
All briefs
14 September 2026·4 min read

Patch Tuesday just got heavier, and your browser is still a frontline risk

KEVPatch ManagementEndpoint Security

In 30 seconds

  • CISA added CVE-2026-85706 to the Known Exploited Vulnerabilities catalogue. That means exploitation is confirmed, not theoretical. Treat it as a patch-now item.
  • Microsoft's September 2026 Patch Tuesday is unusually large. You need a clear, risk-based patch order, not a best-efforts queue.
  • Google is still patching exploited Chrome zero-days this year. If your browser update and control posture is "whatever the user has", that is a gap you can close this week.

Why it matters

For regulated Channel Islands organisations, the common failure mode is not "we did not know". It is "we did not patch fast enough, and we could not prove what was exposed". This week's mix is a practical reminder to keep your asset inventory, patch SLAs, and emergency change process tight, especially for internet-facing services and endpoints used for email, banking, and client portals.

CVE-2026-85706: the KEV signal

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 11 September. For those less familiar, CISA is the US Cybersecurity and Infrastructure Security Agency, and their KEV catalogue is a public register of software flaws confirmed to be actively exploited in the wild. It is not a theoretical risk list. Every entry means someone, somewhere, is already using that vulnerability to break into organisations. The reason it matters outside the US is simple: attackers do not respect borders. If the affected product is in your estate, especially anything internet-facing, patch or mitigate immediately and then validate the fix took effect.

September Patch Tuesday: a capacity planning problem

Microsoft's September release is unusually large. For organisations that run Microsoft heavily, and that is most of the Channel Islands, this is not background noise. It is a capacity planning problem. You need to triage, test, deploy, and then verify, not just "install updates and hope". The organisations that handle this well are the ones with a repeatable process, clear ownership, and a short list of systems that always get patched first. Internet-facing first, then identity, then endpoints.

Chrome zero-days: browsers are the front line

Google has now patched its seventh exploited Chrome zero-day this year. That is not a Chrome-specific problem. It is a signal that browsers are a primary attack surface. For regulated firms, the question is whether browser updates are centrally enforced and whether risky extensions and unmanaged browsers are blocked. If staff can install any browser, run any extension, and updates happen "when they happen", that is a gap that can be closed quickly with policy and configuration, not new tooling.

Questions to ask your team this week

  1. 1.Do we have a live list of internet-facing systems and who owns patching each one?
  2. 2.For this week's KEV CVE, can we confirm where it exists in our estate, and whether it is already mitigated or patched?
  3. 3.What is our patch prioritisation rule when Patch Tuesday is large, and how do we evidence completion for audit?
  4. 4.Are Chrome and Edge updates centrally enforced, and do we block risky extensions and unmanaged browsers?

One thing to do this week

Run a 60-minute patch triage session: confirm whether CVE-2026-85706 exists anywhere in your estate, patch or mitigate it immediately, then agree the top 10 patches from this month's Microsoft release based on exposure. Internet-facing first, then identity, then endpoints.

Sources

  • CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" (11 September 2026):
    cisa.gov
  • BleepingComputer, "Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days":
    bleepingcomputer.com
  • BleepingComputer, "Google patches seventh Chrome zero-day exploited in attacks this year":
    bleepingcomputer.com

Want to discuss anything from this week's brief?

Join the conversation on LinkedIn