Oct 2026: Monthly Security Bytes

Welcome to our LGA Monthly Security Bytes!

Here, you’ll find bite-sized security developments and practical insights to help you stay ahead of day-to-day security operations.

Security Gaps Across the Systems Businesses Rely On

Recent vulnerabilities affecting Microsoft and SAP environments are a timely reminder that security gaps can emerge across everyday business systems.

These vulnerabilities may affect identity services, operating systems and critical applications, with risks including privilege escalation and remote code execution.

We recommend keeping affected systems up to date with the latest security patches and maintaining continuous monitoring for unusual activity.

Key Security Updates
1. Microsoft Vulnerabilities Expose Core Enterprise Systems

Microsoft’s September updates address critical vulnerabilities across Windows, Office, SQL Server and Azure, including risks of privilege escalation and remote code execution.

Microsoft 365, Azure, Windows, Entra ID, and SQL Server services connected within a secure cloud infrastructure, highlighting enterprise cybersecurity and data protection.

Critical vulnerabilities were identified across several Microsoft products:

  • Microsoft Azure and Entra ID
  • Windows Operating System and Core Services
  • Microsoft Office, Outlook, Word and PowerPointMicrosoft SQL Server
  • Windows Hyper-V
  • Windows DNS, DHCP, RRAS and Remote Desktop
  • Microsoft Dynamics 365
  • Microsoft Copilot Studio, Fabric and Power Automate


Among the highest-rated vulnerabilities are CVE-2026-83711 (CVSS 10.0) affecting Microsoft Azure Active Directory B2C, CVE-2026-70352 (CVSS 10.0) affecting Azure AI Language, and CVE-2026-83941 (CVSS 9.9) affecting Entra ID.

Additional CVSS 9.8 vulnerabilities affect Windows and Microsoft Office components, including flaws that could enable remote code execution.

Recommended Action: Review affected Microsoft environments and prioritise security updates based on exposure and business criticality.

SAP security dashboard with cybersecurity monitoring and data protection.
2. Critical SAP Vulnerabilities Put Business-Critical Applications at Risk

Multiple critical SAP vulnerabilities could enable arbitrary command execution, credential theft, data manipulation and unauthorised access.

Critical Vulnerabilities were identified across SAP Products:

  • SAP Extended Passport (EPP) Processing
  • SAP NetWeaver Message Server
  • SAP Cloud Application Programming Model (CAP)
  • SAP NetWeaver SAP GUI for Java


Key vulnerabilities include CVE-2026-44756 (CVSS 10.0), CVE-2026-58240 (CVSS 9.8), CVE-2026-76969 (CVSS 9.4), and CVE-2026-66768 (CVSS 9.0). Successful exploitation could impact the confidentiality, integrity and availability of affected SAP environments.

Recommended Action: Prioritize security updates to reduce exposure to unauthorised access, data compromise and disruption to critical business applications.

Patching Is Important. Visibility Is What Comes Next.

Turn Vulnerability Updates Into Ongoing Protection

With our 24/7 Security Monitoring, you gain continuous visibility across your environment to identify and address threats that patching alone may not catch.