Enterprise Security Alert: Critical Vulnerabilities in Microsoft and SAP

- Microsoft patched 973 vulnerabilities, including two actively exploited 0-day flaws allowing SYSTEM-level privilege escalation.
- SAP's September Security Patch Day addressed critical flaws, including a public PoC for HTTP Request Smuggling in Commerce Cloud.
- A sophisticated smishing campaign targeting delivery services (BRT) highlights ongoing social engineering risks for employees.
- TYPO3 CMS released urgent updates to fix high-severity vulnerabilities affecting authenticated user access.
The current cybersecurity landscape for global enterprises has shifted into a phase of high volatility. Recent disclosures from national cybersecurity agencies, including Italy's ACN, reveal a concentrated effort by threat actors to exploit core infrastructure. From the ubiquitous Windows ecosystem to the backbone of corporate ERP systems like SAP, the attack surface is expanding, demanding an immediate shift in patching priorities for CTOs and CISOs.
The Microsoft onslaught: 973 vulnerabilities
Microsoft has released a massive security update addressing a staggering 973 new vulnerabilities. While the volume is high, the critical concern for international businesses lies in the two 0-day vulnerabilities that were already being exploited in the wild. These flaws are not merely technical glitches but gateways for attackers to seize total control of a compromised machine.
The first critical flaw, identified as CVE-2026-81963, resides within the Windows Update Stack. This is a particularly dangerous location for a vulnerability because the update mechanism itself operates with high privileges. The issue stems from a failure in link following—essentially, the system does not correctly resolve links before accessing files. A local authenticated attacker can exploit this to manipulate file system paths and elevate their privileges to the SYSTEM level, the highest possible authority on a Windows machine.
Simultaneously, CVE-2026-85880 targets the Windows Advanced Local Procedure Call (ALPC). This mechanism is vital for interprocess communication. Due to a heap-based buffer overflow during the handling of data structures, an attacker can alter the software execution flow. Like the update stack flaw, this allows a local user to jump from standard permissions to SYSTEM privileges, effectively bypassing all internal security barriers.
The scope of these updates is vast, covering everything from .NET and Visual Studio to Azure AI Language, Copilot Studio, and GitHub Copilot. For businesses integrating AI into their workflows, the inclusion of Microsoft's monthly updates is no longer a routine IT task but a critical business continuity requirement.
SAP Security Patch Day and the PoC threat
While Windows vulnerabilities often target the endpoint, the September SAP Security Patch Day highlights risks at the enterprise application level. SAP has released updates to resolve multiple vulnerabilities, including four rated as critical and four as high. The most pressing concern is CVE-2026-2332, for which a public Proof of Concept (PoC) is already available online.
This vulnerability is a classic example of HTTP Request/Response Smuggling, caused by the use of Jetty components susceptible to CRLF (Carriage Return Line Feed) Injection. In simple terms, the application fails to filter user-controllable input in URL parameters or HTTP headers. This allows an attacker to inject special characters that trick the server into modifying the structure of the HTTP response.
The impact is concentrated on SAP Commerce Cloud (Search and Navigation), but the ripple effect extends across the SAP ecosystem. Affected versions include various iterations of SAP NetWeaver, SAP ABAP Developer Tools, and the SAP Integration Suite. When a PoC is public, the window for patching closes rapidly, as script kiddies and sophisticated actors alike can weaponize the code with minimal effort.
The human element: Smishing and social engineering
Technical patches are only half the battle. A recent smishing campaign targeting the BRT courier service demonstrates how attackers bypass firewalls by targeting the human psyche. This campaign uses SMS messages to trick victims into believing a delivery has failed, urging them to reschedule via a malicious link.
The sophistication lies in the psychological layering. The victim is first asked to update their delivery address, creating a sense of legitimacy. Then, they are prompted to pay a nominal management fee. By keeping the cost low, attackers reduce the victim's suspicion, making them more likely to enter sensitive credit card details, including the CVV/CVC code.
The process concludes with a fake payment verification animation, mimicking a real online transaction to ensure the victim does not immediately realize they have been defrauded. For global companies, this serves as a reminder that corporate employees are often targeted through their personal devices, which can then be used as a pivot point into the corporate network.
Securing the web layer with TYPO3 CMS
Beyond the giants of Microsoft and SAP, open-source infrastructure remains a primary target. TYPO3 CMS, widely used for corporate content management, has released security updates to fix two high-severity vulnerabilities. If left unpatched, these flaws allow authenticated malicious users to gain unauthorized access to sensitive areas of the system.
While these require the attacker to already have some level of authentication, the risk of privilege escalation within a CMS can lead to full website defacement or the injection of malicious scripts (XSS) to steal administrator credentials. For businesses relying on open-source stacks, the lesson is clear: authentication is not a substitute for patching.
Critical infrastructure and the vulnerability map
When viewing these alerts collectively, a pattern emerges. Attackers are focusing on the 'plumbing' of the digital enterprise: update stacks, interprocess communication, HTTP headers, and content management systems. The goal is rarely a single crash but rather the elevation of privilege.
The transition from a local authenticated user to a SYSTEM administrator is the holy grail for an attacker, as it renders all other security software obsolete.
The diversity of the affected products—ranging from Azure Cosmos DB to SAP NetWeaver—suggests that the modern enterprise is only as strong as its weakest integrated component. A vulnerability in a secondary tool like a CMS can provide the initial foothold needed to launch an attack against the core ERP or cloud infrastructure.
Global implications for US and UK enterprises
For businesses operating in the USA and UK, these developments necessitate a rigorous adherence to vulnerability management frameworks. In the US, the emphasis on Zero Trust Architecture (ZTA) is particularly relevant here; assuming that a local user is already authenticated does not mean they should have a path to SYSTEM privileges.
UK firms, often operating under stringent GDPR and NIS2-aligned frameworks, must recognize that failing to patch known 0-days or critical SAP flaws could be viewed as a failure of 'reasonable security measures' during a regulatory audit. The availability of a public PoC for SAP vulnerabilities significantly increases the legal and operational urgency to deploy patches.
Furthermore, the rise of smishing campaigns underscores the need for comprehensive security awareness training that extends beyond the corporate laptop. As the boundary between personal and professional digital lives blurs, the 'human firewall' must be reinforced to prevent credential theft that could lead to the exploitation of the very Windows and SAP vulnerabilities mentioned above.
FAQ
What is the most urgent action for Windows users?
Prioritize the installation of the latest Microsoft security updates to mitigate CVE-2026-81963 and CVE-2026-85880, which allow SYSTEM-level privilege escalation.
Why is the SAP CVE-2026-2332 particularly dangerous?
Because a public Proof of Concept (PoC) exists, meaning attackers have a ready-made blueprint to exploit the HTTP Request Smuggling vulnerability.
How can employees protect themselves from the BRT-themed smishing?
Avoid clicking links in SMS messages regarding deliveries and never provide credit card details on sites reached via text message.
Does the TYPO3 vulnerability affect all users?
It specifically affects authenticated users, meaning an attacker needs some form of login access to exploit the high-severity flaws.
Sources: Acn (7) ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

