Transcript
Todd got lonely without me last month, so I'm back. I know, I missed you, Chris. We have a big lineup. We've seen yet more records being broken here. Microsoft had yet another record-breaking month for CVE counts. In fact, they've doubled their record high from July, which was 470. This month, it's 973. So they did a 2x on that. They decided that upping their record for all time by 2x wasn't enough. They had to do it again. So that's definitely an interesting thing there. We're going to talk about a few things with that, though. The patch apocalypse, definitely continuing. But it's not all doom and gloom. If we approach this from the right perspective, we should be able to manage it. So we're going to talk about some news. Todd found a really good article that's actually talking about the vulnerability surge and some of the observations of that, that are more outlining things that we could do better, not necessarily that we have to do excessively more, just we have to do better at certain things. So there's a couple of things like that that we'll talk about that make the insurmountable increases in vulnerability counts and exploits not as daunting as you might think. And then we're going to get into the bulletins and releases and go through the between the patch Tuesdays. And by popular request, we have a new key takeaway slide for you guys that we're going to be interested in getting your input on towards the end of the presentation. So without further ado, let's jump into the news. Adobe and Microsoft were first up yesterday. But we did get a late arrival from Google Chrome towards the end of the day. Todd, that was like eight o'clock last night, wasn't it? Or was it later? No, it was around then when it dropped finally. They didn't put the CVEs in right away because there were 230, but they at least put the information up about the patch coming out. So that was good. And there was a zero day there. So all of our content had gone out already before that had dropped. And we weren't sure we were going to see Chrome yesterday, but it did come in late. And there was one additional zero day. So the images you're seeing don't include that, but the content we're going to go through in the slide deck, we did get that captured. So you will get both that CVE and the total information for Google Chrome. So starting off in the news, first up, a dark reading article. And this one is about that AI vulnerability surge that we were talking about. It is a really good read. It's about some research. It's actually more from probably the developer side of perspective of this, but definitely a good kind of way to take a step back and look at this. There was a bunch of research pulled in from a company called Echo about the number of vulnerabilities being reported across different areas. So you can see that it's got some good stats on the like a year over year comparison between June 24 to June 26. That's 145% increase over those last two years. So a significant amount of vulnerabilities were discovered in June by itself. And then they also go on to talk about annual numbers. 2023, there were just shy of 31,000. And at the end of 25, there was just shy of 50,000. And this year we are well on track to surpass that 50,000. So the vulnerability counts are absolutely increasing, especially when we have months where Google resolves 900 vulnerabilities like back in June, or Microsoft resolves 900 vulnerabilities, almost a thousand like we had yesterday. So yeah, 50,000 vulnerabilities, that's nothing. The thing that they're finding from their research is a lot of this is going to be noise. There are some acceleration in the frequency of releases from vendors like Google, Mozilla, we're down to basically all your browsers are updating every week with security fixes. There is a faster response time for zero day exploits. So yes, we absolutely need to figure out how we get into more of a continuous mode of vulnerability remediation for certain applications and get capabilities ready to go at a moment's notice when we need to respond to a zero day. Those are definitely things that we want to be able to do. It doesn't mean that every single vulnerability has to be addressed in a short period of time. Most of these vulnerabilities are never going to be exploited. So there's still, it feels like there's this massive surge, and there is, but doing the right activities will help us to get this into a manageable state. What they were finding from a number of other areas is things like a lot of the influx of vulnerabilities in containers. So if your organization is deploying containers, Kubernetes or anything like that, they're finding that a lot of the vulnerabilities are in libraries that aren't even being used. So this is just a, there's some general hygiene things that we can do to significantly decrease the attack surface of parts of our infrastructure like containers. By cleaning that up, you could be removing, I think they said as much as 56%, yes, nearly six out of 10 of container vulnerabilities were stemmed from packages, utilities, and development tools that were not needed in production. So coming from a vendor, as Ivanti over the years has turned on more and more sophisticated scanning tools within our CI CD pipeline, our engineers had to go in and triage and look at all that. And they found parts of code and tools that were used possibly in the dev process, but aren't needed in production. And other libraries that weren't even being used by our software at all. So those types of things can be removed from the production code that's delivered, especially when you're dealing in a container environment. So those types of activities can help us significantly reduce that attack surface. Prioritizing certain applications like the browsers in a software remediation perspective to happen more frequently, but keeping the majority of activities into that monthly maintenance period or that routine maintenance update every month makes it so you can move faster on the things that need to go more frequently and still not overwhelm yourself with trying to bring everything all the time constantly. So there's different things you can look at to optimize for this new frontier model accelerated world that we're living in. So just some good suggestions on what to look at across your organization. Now, that doesn't mean we've solved everything because there's definitely some other areas that are still very challenging. Network edge devices, probably one of the most challenging. I was reading up on, I again, not a hundred percent sure about the pronunciation on this, but QILIN, Q-I-L-I-N, they're a nation state funded threat actor that specializes in network edge devices as their entry point. They exploit that, they'll purchase credentials for the target to get identities for internal, and then they predominantly use Lulbin, living off the land binaries to execute their attacks. The hardest part of what to control in that is those network edge devices. You can lock down other tools with some basic controls like app control or privilege management. I can lock down PowerShell, I can lock down WMIC, I can lock down a number of different tools that are used by that living off the land lateral movement strategy. But that network edge is definitely one of the challenging areas. When you look at stats about how long it takes to exploit a vulnerability, when you look at the average software vulnerability, now, I think these came from 2024 reports. I didn't see an updated report since then from, I think these came out of Google if I remember the source correctly, but they were showing about a five day average time to exploit for software vulnerabilities in general. If you segment that down to network edge devices, the average time to exploit was negative seven days, meaning the average exploit for that type of vulnerability on network edge devices occurs seven days before a patch becomes available. That means there's more zero day vulnerabilities than end day vulnerabilities for that type of class of device. So we need to figure out where those rough edges are in our attack surface and figure out how to speed that up. One of the ways that we're looking at trying to help customers out with our own VPN technology, we've had a number of conversations with customers and it takes on average 45 minutes per device to be able to back up all the configs, run the scripts needed to update, do the update itself, test everything and move on to the next VPN appliance. Well, that's a significant amount of time that people have to be in the loop and doing that. So we're doing a few things strategically internally, we're trying to figure out how to do more frequent releases using subsets of code that don't require a full stack update to the VPN appliance and also make it so that the rules are not affected for most updates. So that makes it so that some updates will be only needing two to three minutes and will have a minimal impact on potential configurations for the environment. The other thing we're looking at is how to take our own technologies, like if you're familiar with the Avanti Neurons bots, taking that and creating a runbook that knows how to update that VPN appliance so it can be fully automated with a human basically just pulling the trigger or observing it if anything goes wrong. So looking at how you can use technologies to automate updates of those more complicated technologies more frequently. So just a couple of things as we were looking at that article and trying to take the massive amount of things happening and boil it down to a more manageable state. The next article, this was another good find. The Chrome Web Store extensions caught a number of extensions that were stealing crypto and browser data. So if you have not seen or heard about this yet, it's definitely one thing to look at. It's definitely looks like it's targeting a lot more for the end users, things like stealing your session tokens and account data for all of your cryptocurrency wallets. But also from credentials and form entries for websites, for social media apps, things like that. So definitely something to take a look at. Well, they put a list of the extensions that were confirmed to have delivered this malware. And the report is that this could have been happening as far back as 2024. Majority of these extensions were introduced without this malware to begin with. And then over time, this malware got introduced through there. Now, I had never personally gone through and tried to look and say, hey, what's all being used across my enterprise or what are the different ways to be able to go in and try to block these specific ones. But a quick AI search gave me a few suggestions of how to use either the Google Admin Console or Intune or Group Policy to be able to push out configurations to block those. And specifically, you're going to want these extension IDs to do that blocking. So a great article to give you a good list of known extensions that you definitely want to block in your environment. If you haven't done that before, again, a quick AI search on how to identify and block Chrome plugins across your organization will get you to some good information on how to get started on that. The next one, speaking of the Lulbin, the living off the land binaries across your environment, Microsoft is taking some proactive action. Unfortunately, this one will take a beloved, very long running tool out of our environment. And in fact, that process has already started. WMIC is being removed from Windows. This was already removed from Windows 11 24H2 and 25H2 as well as from the Windows 11 beta builds released this week. This, yeah, I believe, yep, August 18th. Oh, so back in August, it was being removed from there. So just to make sure, if you haven't already been observing or seeing this, expect that WMIC is going away. Now, there's a number of tools like the WMI com APIs, .NET libraries, and other scripting languages like PowerShell, where you can do all of those other things that WMIC can do. Those tools just make it easier to lock down and enforce restrictions on that to take a very commonly low-hanging fruit accessible tool out of the bag of threat actors. So be aware of that. And if you haven't already, start looking at alternatives to replace the functionality you might be using intentionally in your environment. Last thing that I wanted to touch on real quick, in my blog post yesterday, I covered a number of vulnerabilities that were identified and added to the CISA node-exploited vulnerabilities list. So the CISA KevList had several updates since last August. And a few of these are ones like this first one was a patch that released in August and was added to the CISA KevList the same day it was disclosed. It has still been seeing activity, so definitely if you have not already, make sure that you get your OSs up to date for the latest. Another vulnerability that was first resolved back in April was added to the CISA KevList on August 18th because there were a number of active exploits occurring. So again, another one that you wanna make sure to identify and get resolved across your environment. This next one was from Microsoft SharePoint. The original patch came out in July Patch Tuesday. In August, Rapid7 posted an article and shortly after that, exploitation started happening with that vulnerability. There was another vulnerability that was resolved in August. The two of these are used in a chain. Both of them need to be resolved to fully plug that attack chain. Otherwise, if one or the other are available, they could still chain it with something else to achieve what they were doing. But with those two CVEs combined, there was exploitation enough to add, make sure that both of those were added to the August 11th list. This one is a blast from the past, 2019. Microsoft SQL Server vulnerability released back in July of 2019 was re-added to the CISA KevList in August, late August 26th, because of renewed evidence of active exploitation. So this six-year-old vulnerability is seeing some renewed targeting from threat actors. So definitely another one that we, leaving software, old software there and available has its dangers. Threat actors will find and utilize that even years later. The last one here on the Microsoft list came up in a few different ways that is just a rising concern. It does not have current known exploitation. It does not have, it's not been added to the KevList, but the, not only Microsoft, but other sources were kind of pointing to this one as a, you know, potentially one that threat actors could take advantage of. It's an ideal target. It was a public disclosure back in August, which increases that risk. But again, all of these have patches available and should be able to be resolved unless you've got some type of dependency that's preventing that. In which case you'll want to look into mitigations to make sure that you're reducing that risk. Google Chrome, this one came out on September 3rd and was added to the CISA KevList on September 4th. So that plus the zero day from yesterday puts us up to seven Chrome zero days for the year and definitely ensures that, you know, or reinforces that strategy of keeping up with browsers on a more frequent basis. So those were the top news articles that we wanted to cover. Just going to take a look at the chat history real quick to make sure there's no immediate questions. I think we're good, Chris. Okay, perfect. All right, I'm going to go back to the slide deck then. Come on, stop sharing, start sharing. Okay, so next up we do have this month's content now. Microsoft did have two zero day exploits that were added yesterday. So the first one, node exploitive vulnerability this one is a elevation of privilege vulnerability in advanced local procedure call, ALPC. Base score of a 7.8 on CVSS, rated important on a severity scale. Affected systems Windows 10 and up and server 2012 and up. In this case, the attacker could elevate their privileges to system level. So included in the OS update for this month but definitely one that drives the urgency of the OS update to make it a high priority this month. The next one is another elevation of privilege. The pair of them were both elevation of privilege this month. Also a 7.8 on the CVSS scoring and important for severity is actively being exploited. This one only affects the Windows 11 and server 2025 OSs. Also allows the attacker to gain full system privileges if they exploit this. So two zero days, both in the OS this month definitely drives the priority up there. Something you wanna take a look at to make sure that you get those plugged as quickly as possible. On the Linux front, we've got three notables to take a look at. The first one is CVE-2026-74752. This is a STTP cookie authentication vulnerability. Ubuntu and the kernel CNA scored it at a 9.8 while Red Hat and Amazon scored it as more of a 7.0 on a local high complexity vector. So there's a little bit of a variance there in how different vendors were assessing that. In this case, it's unfixed on the LTS kernel branches below 7.1. You wanna update to 7.1.10 or later to make sure that you get this one resolved. It was introduced back in 2.6.24. So roughly an 18-year-old vulnerability. This has been a more common occurrence since the frontier models have been introduced in and they're finding a lot of really old vulnerabilities that have been out there for a very long time. So that one definitely is one that there's a little bit of urgency on because it's been out there and available for so long. And the overall risk is higher, again, depending on which platform you're on. If the kernel CNA is scoring it at a 9.8, unless Red Hat and Amazon are doing some additional things to mitigate that, I would probably lean towards the kernel CNA as being the better authority. But as we've talked about many times, CVSS and vendor severity typically don't include additional real-world risk factors. So this one I would definitely treat towards a higher risk. The next one, CVE-2026-74746. This is a net filter flow table vulnerability. Affects kernels 5.13 and later. Fixed on all seven stable branches that name a fix. So you can see the different stable branches there that they list out. In the interim, you can remove the flow table offload from the NF tables rule set. If you know your way around the Linux environment and have the ability to mitigate that, otherwise getting your Linux kernel updated is the recommended course of action. And the last one is a pair, actually. Looks like 74743 and 74744. These are... Mac VLAN device did not inherit the headroom and tailroom requirements of the device underneath it. Okay, so we've got an inheritance issue there. And the second bullet covers the difference between the two, because they are somewhat related in different environments up the top of the second column. That was what I was looking for. So both matter on container hosts, where Mac VLAN and IP VLAN are the usual ways to give a container its own Mac address on the physical network. So the way this is being inherited is not behaving correctly. So the mitigation in this case is to do the update. There was no fix for 5.10 or 5.15. So these branches are affected and unfixed. So you need to make sure to go up to the later branches to resolve this one fully, it looks like. There is a fourth one here this time. Oh, they gave us a fourth one. That's not typical of them. So 202680557, kernel ceph-client. This is an out-of-bounds read. Looks like they've got it fixed in specific branches there. Branch update on every kernel ceph-client, not only the OSD hosts, and treat the three as one scheduling unit. So it looks like update is the only option in this case. There's no additional mitigations available. All right. So we've got three updates from the Avanti side this month. There was an update for Avanti's endpoint mobile manager, or manager mobile. One CVE resolved there. For the ITSM side, there were several being resolved. And for Avanti Sentry, there was one vulnerability as well. If I remember the notes correctly, the ITSM side, if you're on the cloud platform, these were already resolved for you last week. That's correct. Or no, yeah, was it last week or was it back in the end of August? That was last week, I think. For those of you running the on-prem ITSM, you do have to apply an update. So the other two are both on-prem. So that is the Avanti updates for this month. Lifecycle awareness. We do have a lifecycle event next month. So Windows 11 Home and Pro 24H2 is coming to a close. Next month is your last update. And on the Windows 11 Enterprise and Education Editions, that will be November 23H2 is coming up on its end of life. Now, Todd, there were a couple others that you had mentioned in your forecast last week. We have Server 2012 ESU, 2012 and 2012 R2 ESU. Next month is the end of year three, correct? That's correct. Wow. Haven't heard anything from Microsoft that they're extending it either. So we'll see. Yeah. I mean, we might see some extensions in specific cases like we saw for 2008, but those were not mainstream availability. That had to have been for somebody very large and very important. But we mere plebs did not get access to those continued 2008 ESU updates. Server 2012 and 2012 R2, we're expecting the same thing. Last month, that's it. After that, no additional extensions available. So make sure you've got it removed or additional mitigations are in place. And then, not sequel, exchange. Yeah, Exchange Server 2016 and 2019. Next month as well. So that was also extended support coming to a close on those. So if you're running either Server 2012, 2012 R2 or Exchange 2016 and 2019, ESU is done after next month. All right. Long-term service branch. We're out to January 27 before we come up on that Server 2016 LTSC. So if you haven't already and you know you're going to be running 2016 longer, make sure that you've got your ESU coverage in place because that will be starting its three-year ESU coverage. There's a lot of development tools that were updated this month. And there were servicing stack updates for 2012, 2012 R2 and Windows 10. So if you've got development teams within your organization, there's a number of tools that they may have to update some things for. And the Spring Cloud Azure update that was released as well. So there's a number of different tools that may need some manual steps or some updates on the development stack. All right, Todd, over to you for the bulletins and releases. All right, thanks, Chris. Let's talk about the massive release that came out yesterday. Chris did mention that there was the Chrome update that dropped late in the day. I'll grab the information here. So 153 version being promoted to the stable branch for desktop, in case you're wondering. 230 security fixes, the one zero day that Chris mentioned is in here. CVE-2026-87491 is known exploited. And you can see in the list here, there were five critical vulnerabilities, 41 high, 133 medium and 51 low. So there's a link included here to that particular update. So if you want to read about it and see all the vulnerabilities there. Again, this one dropped late in the day yesterday, so we didn't include it in our infographic. Moving on to the Adobe updates that we support. We had Adobe Photoshop, eight vulnerabilities there. All listed here, none of those known exploited. Oh, I didn't change the number from resolving seven to eight. I'll double check that. No exploits on this one. We had an update for Illustrator as well. Three vulnerabilities all rated critical here. No exploits here as well. It's good to know. Adobe Animate from the Creative Cloud side also had an update. Only one vulnerability, Only one. remote execution, but not known exploited here as well. Finally, we had our updates for Adobe Acrobat. Quite a few vulnerabilities, 32 addressed in here, both Acrobat and Acrobat Reader. I know we're all regular users of that, so you definitely want to make sure you get these updated in your environment. Again, Bulletin 26141, no known exploited vulnerabilities here as well either. Good for all those that there aren't any, but you definitely want to make sure you keep on top of those. Moving into the Windows 11 update. Chris did mention the one CVE, 81963 is known exploited. I have it highlighted in red down below there. There were a total of 717 vulnerabilities. I didn't think I'd ever be saying that. Seventy-five critical and 642 important were updated across all of these KBs, and there are four KBs across the list here. I have them listed here, and as a matter of fact, we have the links in here as well. If you go through our slide set and you want to easily access all these KBs, nice to be able to do that from these slides. There were some known issues, and actually it's the one we've been carrying forward for many, many, many months. Basically, this is just really a reporting error on Windows Server 2025, so you've seen this for a long, long time. This has to do with the change that they made around a remote code execution vulnerability back in 2025. You can read about that here, but this one's been around for a long, long time. I don't think it's anything that's going to get resolved. It's basically just a reporting error. On Windows 10, the long-term service branch and its associated servers, 666 vulnerabilities reported here, 70 critical, and 596 important. Chris covered the known exploited vulnerability earlier, 85880. If you want to see a complete list of CVEs, definitely go off to the security update guide. As far as known issues, similar to what we just saw on the previous version. Again, it's only on Server 2022. It's not across all the others, so just be aware of that one. Moving on to Office, we did see 105 vulnerabilities addressed across the Microsoft Office suite. Again, officially, Office 2016 has reached end of support, but they're continuing to crank out the updates for these. That's why the asterisks on all these different versions. Under the Office line, there's also Office Online Server. Be aware of that one. Make sure you get that patched if you're not keeping up with that one. Again, 105 vulnerabilities, 21 critical, and 84 important listed there. On the click-to-run or the online Office versions covered under 365 apps, we have Office 2019, long-term service channel 2021, long-term service channel 2024, and, of course, the Office 365 for Mac and Office for Android got updates. Two additional vulnerabilities that are unique to these, the other 105 are shared with the previous one that I mentioned. Number of critical and up-to-critical, 21 critical, 86 important vulnerabilities in this particular one were resolved. Again, these are coming out today from us as far as patches go. They'll be in the content feed here shortly because usually the Office updates take an extra day to process. On the SQL Server side, saw updates across all versions of SQL Server, including SQL Server Management Studio 22. There were 63 vulnerabilities addressed here, five critical and 58 important. We haven't seen any known issues with this for a while, but in digging through, there were quite a few that were introduced across all versions of SQL Server. Unique to the latest one, SQL Server 2025-CU8, there's an issue with link server queries. I captured kind of the essence of what Microsoft has reported here. There is an entire KB article that I've listed here as well to deal with what's happening with this failure and how to do some workarounds. They did not say that this is something they're going to resolve from what they fix. It just has to do with a configuration problem and a privileges issue, sorry. The second one is an access issue. This one is unique to this particular version of SQL Server. It doesn't happen on the other versions. You can see down below here with my second kind of purple looking bullet there. All the SQL Server versions have the link issue that's mentioned up above. So you might run into that one. Only this particular Server 2025-CU8 has this access issue. And there is a KB article on this one as well with some workarounds. And in this case, Microsoft is working on a fix for this issue. So again, if you're doing your SQL Server updates, be aware that these particular known problems have been reported by Microsoft. On the SharePoint server side, this is an important update, not a critical one this month. Only SharePoint server subscription edition. They didn't talk about any of the other versions of SharePoint this month. There were no updates for those. 16 vulnerabilities here. Again, none of these are known, exploited, or publicly disclosed, but there is definitely a SharePoint server for subscription edition. Exchange server this month. We did see updates across the board for subscription, Server 2019-CU14 and 15, and Exchange server, the old one, 2016-CU23, up to the 23rd edition of this one. Nine vulnerabilities were addressed as part of this update. And again, this month, we saw some known issues with Exchange server, particularly on Exchange server SE. There was an issue with the calendar. They talk about a workaround here. There is, it's pretty extensive. If you go in and take a look at this particular KB article, I have about the published calendar. They have a number of steps you have to go through to get this resolved, but be aware this issue exists. And as you can see down below here, it does show that it does exist on Exchange server 2019, both of the CUs there, and Exchange server 2016 as well. Also on Exchange server SE, there is a problem with the API. If you're running in a hybrid environment with the on-premise versions of Exchange server, so be aware of this. They do have a KB for this as well that talks about how to go in and correct any issues with the graph API and to make it work properly in a hybrid mode. So just be aware of this when you go through and do your updates this month if you run into any problems there. We did see an update for the .NET framework as well, versions 3.5 through 4.8.1, spread across lots of KB articles. Only one's vulnerability, CVE-2026-69522, not known, exploited, or publicly disclosed. But if you are gonna be updating your .NET framework, there is this one vulnerability you have to take a look at. Only rated important. Moving to between the Patch Tuesdays. We did have a lot of updates, as you can imagine here during the patch apocalypse. To those of you who are new to this, I've continued to lump these together into security updates with CVEs. The number in parentheses are the number of patches that were released during the month between Patch Tuesdays. We have a lot of security updates without CVEs where the manufacturer will mention that it is a security update, but they don't list specifically what they've fixed. And I couldn't quite squeeze it on the page, so I got a single one-liner here where we had some non-security updates as well this month. Getting into the CVEs themselves, we did have Adobe Illustrator, two versions, 2025 and 2026, updated to address the same vulnerability. Citrix Workspace app with three vulnerabilities. And by the way, for most of these, the date of the release is included in the bulletin number or we include it in the bulletin. So you can see here that Citrix Workspace, for example, was on the 14th of August in this case. There was an intermediate release as part of Oracle Java did release their out-of-sync or their monthly update, as they call it, their security updates for Java, which generated a lot of updates for all the third parties that also support Java. So in this case, we have Azul Zulu with a monthly release addressing four vulnerabilities for version 25. And these are all the long-term service branch versions, by the way, 8, 11, 17, 21, and 25, for those of you who are very familiar with Java. So there were updates from Azul for all of those. We also saw the Amazon Coreto updates coming out as well. They're not currently releasing 25, but we have 8, 11, 17, and 21. Obviously a lot of overlap with what Oracle has done. These particular releases don't always include every single CVE that Java was released by Oracle, but most of the times they do. We did have some massive updates from Chrome. Chris was talking about keeping your browsers up to date. We see here that back on the 20th, they released seven vulnerabilities. On the 25th, on the new 152 version, they addressed 327 vulnerabilities. Not too long thereafter, on September 1st, again, a continuation of version 152, 26 vulnerabilities. So definitely a lot of updates there on the browser side. And here we get into the actual Oracle releases. You can see that version 25, they had five vulnerabilities they addressed, 21, four vulnerabilities, 17 and 11, four vulnerabilities respectively as well. And over here on the last slide, we have Java 8, the oldest one that's still in long-term service, four vulnerabilities addressed there. The Red Hat OpenJDK that runs on Windows, they have the updates for these. Again, just 17 and 21 versions where they address three vulnerabilities in each one of those. Splunk Universal Forwarder had five vulnerabilities addressed back on August 20th. PaperCut had a couple of updates, two vulnerabilities each. PyCharm, those of you who are using PyCharm, updates as well. Apache Tomcat, those of you with web servers out there, version 9, 10 and 11 all had updates with the same set of vulnerabilities addressed in each one of those. Go Language Update, 1.27 came out back on the 20th as well, six vulnerabilities addressed there. Foxit PDF Editor, the series of editors as well as reader addressing the same vulnerability there. IntelliJ IDEA, you'll notice that a lot of times I'll include our queue numbers here where it has an A on the end. This is the ARM version, okay? So we support both x86, x64 and ARM, depending upon what the applications support themselves. So in this case, IntelliJ IDEA had six vulnerabilities. The Firefox browser updates, again, a large series of updates here, 57 for version 154, 29 when 155 came out. A couple of ESR versions, 140.14, 140.15, you can see 31 and 11 vulnerabilities respectively there. 153 when it first came out on ESR forum, 52 vulnerabilities. Secondary, they released again here September 2nd with 24 vulnerabilities. Thunderbird often tracks very closely with the Firefox releases in terms of the number of vulnerabilities. Here we see the latest version, Thunderbird 155 had 30 vulnerabilities, 154 when it came out had 55. I've included the links here, so you can go in and dig into depth on each one of these if you wanna look at the actual list of vulnerabilities and what they included. The ESR versions of Thunderbird as well, their long-term service versions, 31 for 140.14, 153.1.1 already out in ESR, 52 vulnerabilities there. Finally, getting to the end of the Windows list between the Patch Tuesdays, we have a workstation update that addressed two vulnerabilities and VirtualBox coming out from Oracle supports 21 vulnerabilities there. That came out back on the 19th of August. So it's a mouthful, but there are a lot of updates you need to keep track of between the Patch Tuesdays. So definitely wanna keep up with that. Moving on to the Apple side, we did have several updates from Apple with CVEs as well. We did have an OS update, 26.6.2 that addressed 28 vulnerabilities there and no specific updates for Sonoma and Sequoia, but most of these vulnerabilities were related to the website. So when they did a Safari update for these, you'll see there's a lot of overlap between that Tahoe release of 28 vulnerabilities and the 21 vulnerabilities that came out specifically for Sonoma and Sequoia in Safari itself. So you'll definitely wanna make sure that you apply that on top of those operating systems. Moving on to Google Chrome for the Apple side. Obviously, essentially the same number of vulnerabilities. Usually they have a different number for the Apple release, but the vulnerabilities overlap very closely with the releases that we're doing on Windows. You can see here for Chrome, there were actually five updates that came out throughout between the Patch Tuesdays on this. The Firefox browser, same number of vulnerabilities addressed there as well. You might be wondering why there's an ESR version 115 for Apple, but there's not one for Windows. The Windows ones are on actually much older operating systems. They're still supporting Windows 7, believe it or not. And that's usually what the 115 version targets on the Windows side, which we don't support. So you'll see 140, 31 vulnerabilities there, version 153, 52 vulnerabilities. Again, these ESR versions that are released throughout the month. You can go in and take a look at each one of these in detail at the links I have provided. Finally, we have the Firefox ESR 1.53, and then the Thunderbird releases. ESR versions of Thunderbird as well. Again, an overlap with what we just talked about on Windows. We did, of course, see Microsoft Edge updates throughout the month. Seven vulnerabilities associated with the one that came out on the 28th. There was a Microsoft Teams update as well that addressed six vulnerabilities, an Adobe Illustrator update. Finally, WatchGuard mobile VPN had one vulnerability that was addressed on the Windows side. We also released a patch for the Mac side. There was an update as well for the Windows side, but there was no vulnerability associated with that one. With that, Chris, let's jump back to the key takeaways that everybody was asking for. Yeah. This was a request a couple of months ago when we were talking about what type of new content you guys wanted to see or how we wanted to clean up or streamline things. Getting a key takeaway slide was one of those requests. We played around with a few different formats, and this one came out as the cleanest, best way to represent this. Definitely looking for some feedback from you-all on if you like that. But this is definitely going to give you the breakdown of everything we talked about. It shows the weight of CVEs discovered this month. You've got Microsoft, Adobe, and Chrome vulnerabilities in there. It calls out where we've got zero-day exploits. You can see that they are color-coded, the different cards there. That's trying to draw your attention to the most risky, the reds are the cards that you want to be most concerned about because those include the zero-days. There was the six CVEs exploited since August. That was part of the blog post that we talked about before. Again, one of those things that has been out there for a little while, may still be something for some of you, but not as high, so that's why it wasn't colored red. It's slightly lighter color, but gives you a general overview of everything. By the indications there, I'm feeling pretty good about what we've pulled together for that. Let's try this for the next couple of months then, I think, Todd, and we'll see if that helps people. If you're in a pinch and you can't catch us live, you can always grab the deck, go straight to this slide first and get the highlights, and then go back and drill down deeper as you need to. I was looking through the Q&A and it looks like Richard and Long have taken good care of you guys there, and we've got responses to everything in the Q&A. From what I'm seeing in the chat. I saw the question there about the preview patch, Chris, that was breaking the cursor and a couple of other odds and ends. I would assume that they fixed that in the final release that just went out yesterday. I would just double-check on that. But yeah, those preview patches, they're not perfect. That's why they're called a preview. They're trying to give you a heads-up on what's coming in. Apparently, they screwed up a little bit this month and had a couple of issues in it. They said, well, the new patch is coming out. If you don't like it, just uninstall it. There was a couple of news articles on that that came out this month. That's about all I have to say on the preview side. Got it. I created this tracker early this year to start to get a handle on what was all happening with CLAWD and the frontier models, and what it was doing from an overall patching perspective. It's been interesting to see this evolve over the course of this year. But I just updated it based on yesterday's information. Because if you look at a couple of the data points here, this one is probably, out of all of this, one of my favorite charts in here so far, gave us a really good idea of the month-to-month, what did we really have to worry about? And again, historically, the Windows OS was always the most important thing. That was always the thing that drove the most challenges that we had, and why Patch Tuesday, for the last 20 years, has been the center and starting point of all of our monthly patch maintenance. Starting in February and April this year, we started to see those frontier models coming in, and suddenly Microsoft was not the most scary thing out there. And then June hit, and we saw multiple kind of astounding, record-breaking releases from Google, from Microsoft. July hit, and Microsoft blew us all away with the 470 CVEs, their highest ever, which was almost a 2x over their previous high, which was October, the prior year. And then we have September this year, with the very large Windows OS update of 723, and 973 total, right, Todd? Was it 973? Yeah, 973. That was right. So Microsoft did not want to be outdone by Google, so they topped Google's previous 913 result in a single month with their 973 now. So it's a race now to see who can set the best records. But as you can see, we definitely have kind of a steady stream of vulnerabilities coming out on a much more frequent basis as well. But you can see that we're kind of hanging around on a new plateau here. It's jumping every once in a while, but we definitely have a new significantly higher threshold that we're seeing. The other one that I'm keeping an eye on as we wrap up the year is the exploits. So this is just focused on a handful of applications here, the 11 product families that I was tracking here that pretty much everybody's got in their environment. If we expand this out, in our risk-based vulnerability management platform, I was on a call with Glenn, who's our subject matter expert on that product area, and we were going through some of the details around that. And across the broader vulnerability Intel database, right now we're seeing roughly a 20% acceleration in the number of exploits in 2026 compared to prior years. So patch-wise, our content team and other data that we're seeing is showing about a 40% acceleration in the number of patches being released by vendors. And we're seeing a roughly 20% increase in the number of exploits that we're seeing from vendors. So that was just a couple of highlights here that I wanted to leave you all with as we wrap up today. We're definitely continuing to keep an eye on the trends here and want to share as much information with you all as possible. But that definitely is a couple of the key highlights that just came up that I thought I'd share some updates on. The conversation around a tracker like this being made available in either the Avanti website or directly in product has definitely come up. This right now is based on... So when it comes to AI interactions, we've got to be very careful. Because of AI hallucinations and other things like that, until something has been refined quite a bit, we have to be very cautious about that. So even like me, even quoting this in a blog or something else like that, there's specific ways to cite that as a personal prompt that I used in that AI interaction with this tool to make sure we've got the right quality guardrails on that before we could share it generally. But absolutely something that we've been thinking about how to make data like this more generally available. But yeah, we'll be keeping an eye on and trying to take a look at how to do things like this in product, especially going forward. We've got a lot of AI features that'll be coming in and a lot of ways that you'll be able to do AI-generated reporting and natural language prompt interactions and being able to dig into the data within product experience like Patch Intelligence and get additional insights like this from those datasets. So we absolutely definitely want to focus on increasing that. And on that note, we're going to go ahead and wrap up. And looking forward to seeing you all again next month in October. Should be interesting. Cybersecurity Month will probably have some interesting things coming out from a number of sources. So we'll see what we can find for interesting research or other things that might be coming out and keep you all informed. Thanks, everyone. And we will talk to you all next month. Thanks, everybody. See you next month.