· artificial intelligence · 7 min read
Weekly AI and security roundup: the stories that mattered most, 8-17 September 2026
This week brought a wave of critical, actively exploited flaws from Cisco, SonicWall and Oracle, Microsoft's largest ever Patch Tuesday with two exploited zero-days, and a $60 billion Qualcomm-Amazon deal to build custom AI chips. Here are the five stories worth your attention from the past week.

We have not published our usual daily briefing this week, so here is a consolidated round-up of the AI and cybersecurity stories from 8-17 September that we think matter most for UK businesses, with links to the original sources so you can read further.
Lead story: Cisco patches two critical remote code execution flaws, one already under attack with a CISA deadline today
Cisco fixed two unauthenticated, critical severity flaws in its security appliances this week. The first, CVE-2026-76461, is a SQL injection vulnerability in the email parsing feature of Secure Email Gateway, rated 9.8 out of 10. It needs no login and no user interaction: an attacker simply sends a crafted email, and the appliance runs their SQL statements while processing it, giving root access to the underlying system. Cisco confirmed active exploitation and the US Cybersecurity and Infrastructure Security Agency set a remediation deadline of 17 September 2026 for federal agencies, which is today. The second, CVE-2026-20242, patched two days later on 16 September, sits in Secure Firewall Management Center’s External Database Access feature. It also scores 9.8 and lets an unauthenticated attacker run commands as root by sending a crafted, serialised Java byte stream to the device, no credentials required. It was one of 18 Secure Firewall flaws fixed in the same batch. More detail is available from Help Net Security’s coverage of the email gateway flaw, Rapid7’s exploitation analysis, and Cisco’s advisory for the firewall flaw.

Why this matters: both flaws need no credentials at all, and both sit in systems meant to protect the rest of your network, an email gateway and a firewall manager. If your business runs either Cisco Secure Email Gateway or Secure Firewall Management Center, treat this as urgent rather than routine, and check logs for signs of compromise even after patching, given exploitation of the email gateway flaw was already under way before the patch shipped.
Cybersecurity: Microsoft ships its largest ever Patch Tuesday, fixing 974 flaws including two exploited zero-days
Microsoft released its September 2026 Patch Tuesday updates on 8 September, its largest single monthly release on record, around 57% more than July’s previous record. More than 110 of the 974 fixes are rated Critical, and nearly 90% fall into three categories: privilege escalation, remote code execution and information disclosure. Two were already being exploited when the patches shipped: CVE-2026-85880, a heap buffer overflow in the Windows Advanced Local Procedure Call component that lets an attacker with low-privilege code execution escape a sandbox and reach System privileges, and CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack. The update spans Windows, Office, SQL Server, Exchange, SharePoint, Azure and developer tools. More detail is available from BleepingComputer’s coverage and Tenable’s technical analysis.

Why this matters: a record-sized patch batch makes prioritisation harder, not easier. Focus first on the two actively exploited zero-days and anything Critical on internet-facing or shared systems, then work through the rest on your normal cycle. If you use a managed IT provider, confirm this month’s patches are actually scheduled given the unusual volume, rather than assuming they will be picked up automatically.
Also in cybersecurity: SonicWall confirms pre-disclosure exploitation of its SMA1000 remote-access appliances
SonicWall disclosed on 1 September that two vulnerabilities in its SMA1000 secure remote-access appliances were being actively exploited before the public advisory even went out. CVE-2026-83548, a pre-authentication server-side request forgery flaw scoring a maximum 10.0, can be chained with CVE-2026-83549, an OS command-injection flaw in the management console, to run code on the device with no login at all. Because exploitation predates disclosure, SonicWall is telling customers not to rely on patching alone: it recommends checking for signs of compromise, changing all passwords, resetting authentication tokens, and in some cases re-imaging the appliance. Both CVEs are on the US CISA Known Exploited Vulnerabilities catalogue. More detail is available from Rapid7’s advisory and SonicWall’s own security notice.

Why this matters: SMA1000 appliances are usually exposed directly to the internet, because that is how they let staff work remotely, and the same design that makes them useful makes them a target. If your business or IT provider uses SonicWall SMA1000, patch it and actively check for compromise rather than assuming the patch alone has fixed things.
Cybersecurity: Oracle ships its largest ever security update, with one flaw already exploited
Oracle published its September 2026 Critical Patch Update on 15 September, its biggest security release to date: 673 new patches across 17 product families, 104 of them Critical and more than 240 exploitable remotely with no login. Oracle notes over 130 further flaws were quietly closed through bundled patches, pushing the effective total past 800 in a single release. Oracle E-Business Suite took the largest share with 159 patches, followed by Fusion Middleware with 153. Hong Kong’s government cybersecurity response team confirmed CVE-2026-64849, a remote code execution flaw, is already being exploited, and flagged seven further CVEs with public proof-of-concept exploit code. More detail is available from SecurityWeek’s coverage and Qualys’ technical review.

Why this matters: a release this size, spread across E-Business Suite, Fusion Middleware and dozens of other products, cannot realistically be applied everywhere at once. If your business runs any Oracle enterprise software, prioritise the products you expose to the internet or to less trusted internal networks first, and treat CVE-2026-64849 as urgent given it is already being used in real attacks.
AI and cloud: Qualcomm and Amazon strike a $60bn deal to build custom AI chips
Qualcomm and Amazon announced a partnership on 8 September to co-develop custom silicon for large-scale AI data centres, focused on AI inference workloads, along with optical connectivity technology supporting speeds up to 1.6 terabits per second. The agreement is linked to up to $60 billion in potential commercial transactions over its life. As part of the deal, Qualcomm issued Amazon a warrant to acquire up to 25 million Qualcomm shares at $161.26 each, a stake worth up to $4 billion that vests in stages tied to purchase milestones. The deal builds on Qualcomm’s recent push into the data centre market, including its acquisition of AI software firm Modular. More detail is available from Bloomberg’s report and CNBC’s coverage.

Why this matters: deals like this show cloud providers diversifying away from a single chip supplier to control cost and supply for AI inference, the workload that actually serves AI features to end users. Over time this kind of competition tends to bring down the cost of running AI workloads in the cloud, worth watching if inference costs are a meaningful part of your AI budget.
The takeaway
The clearest pattern this week is that attackers are moving faster than disclosure cycles: SonicWall and Cisco both confirmed exploitation that started before, or right alongside, the public advisory, and Oracle shipped its biggest ever patch batch with a flaw already in active use. If you run Cisco Secure Email Gateway, Secure Firewall Management Center, SonicWall SMA1000, or any Oracle enterprise software, treat patching as this week’s priority, not next month’s. If you run Windows, Office or Azure, get September’s record Patch Tuesday applied and check specifically for the two exploited zero-days. And on the AI side, the Qualcomm-Amazon chip deal is a reminder that the infrastructure race behind AI pricing is still very much underway, which should feed into how you plan AI costs over the next year. We can help you work through what applies to your business. Get in touch.
AI Agent based research and content, AI can do mistake, please help us to improve.