Bg Shape
Image

Microsoft Emergency Patch, Revolut Breach & Cisco's Second Perfect 10 CVSS

Robert Kehoe
Chief Technology Officer
Published:
September 21, 2026

This week's Risk Radar: Microsoft rushes out an emergency fix after last week's record-breaking Patch Tuesday introduced two new bugs and broke production systems, Revolut discloses a breach rooted in a spoofed government email rather than a technical exploit, and Cisco scores another perfect CVSS 10 in a vulnerability already being exploited in the wild.

Microsoft's Emergency Out-of-Band Patch

An update on the record-breaking Microsoft Patch Tuesday we covered last week. Since then, it has emerged that while 974 CVEs were patched, two new vulnerabilities were introduced by the update itself. The patch also broke production systems worldwide, particularly Remote Desktop and hypervisor functionality, heavily affecting cloud users. Microsoft released an out-of-band patch on Monday to address both issues.

What to do:
Apply Microsoft's out-of-band patch as soon as possible, particularly on production systems or anywhere you have seen instability with Remote Desktop or hypervisor services since last month's update.

Revolut Breach: Authentication Is Not Authorization

Revolut suffered a breach that started with a process failure rather than a direct cyberattack. An employee received an email that appeared to come from a legitimate government domain and, believing the request genuine, disclosed sensitive customer information to the attacker. More than 680 high-net-worth individuals across Europe were affected, including well-known footballers, tennis players and business figures with sizeable incomes.

This is an important lesson for CISOs at banks, financial institutions, or any organisation holding significant amounts of PII: authenticating a request is not the same as authorising it.

What to do:
Put side-channel confirmation and senior management sign-off in place for any request that involves disclosing PII, regardless of how legitimate the sender appears.

Cisco Scores Another Perfect 10

Another vulnerability in Cisco's platform has scored a perfect CVSS 10. This one allows unauthenticated attackers to perform remote code execution. The affected product is Cisco Identity Services Engine (ISE), and Cisco has already confirmed the vulnerability is being actively exploited in the wild.

What to do:
Patch any ISE deployment in your organisation immediately. Cisco has confirmed active exploitation, so this cannot wait for a routine patch cycle.

Stay safe, and share this with your team.

Read Our Latest Blogs

Blog Image
Microsoft Emergency Patch, Revolut Breach & Cisco's Second Perfect 10 CVSS

Microsoft rushes an emergency patch after last week's update broke Remote Desktop and hypervisor stability, Revolut discloses a process breach affecting 680+ high-net-worth clients, and Cisco scores another perfect 10 CVSS.

Blog Image
8 SOC Platform Requirements for 24/7 Threat Monitoring

Evaluating a threat detection and response platform? Here are the 8 requirements for 24/7 monitoring, threat intelligence, and automated response.

Blog Image
Six Ransomware Groups That Emerged in 2026

67 new ransomware groups emerged in 2026, but only six are worth your attention. See how each operates, who they target, and what actually stops them.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Microsoft Emergency Patch, Revolut Breach & Cisco's Second Perfect 10 CVSS

Risk Radar
Vulnerabilities and Exposure
Data Security and Privacy
Robert Kehoe
Chief Technology Officer
September 21, 2026

This week's Risk Radar: Microsoft rushes out an emergency fix after last week's record-breaking Patch Tuesday introduced two new bugs and broke production systems, Revolut discloses a breach rooted in a spoofed government email rather than a technical exploit, and Cisco scores another perfect CVSS 10 in a vulnerability already being exploited in the wild.

Microsoft's Emergency Out-of-Band Patch

An update on the record-breaking Microsoft Patch Tuesday we covered last week. Since then, it has emerged that while 974 CVEs were patched, two new vulnerabilities were introduced by the update itself. The patch also broke production systems worldwide, particularly Remote Desktop and hypervisor functionality, heavily affecting cloud users. Microsoft released an out-of-band patch on Monday to address both issues.

What to do:
Apply Microsoft's out-of-band patch as soon as possible, particularly on production systems or anywhere you have seen instability with Remote Desktop or hypervisor services since last month's update.

Revolut Breach: Authentication Is Not Authorization

Revolut suffered a breach that started with a process failure rather than a direct cyberattack. An employee received an email that appeared to come from a legitimate government domain and, believing the request genuine, disclosed sensitive customer information to the attacker. More than 680 high-net-worth individuals across Europe were affected, including well-known footballers, tennis players and business figures with sizeable incomes.

This is an important lesson for CISOs at banks, financial institutions, or any organisation holding significant amounts of PII: authenticating a request is not the same as authorising it.

What to do:
Put side-channel confirmation and senior management sign-off in place for any request that involves disclosing PII, regardless of how legitimate the sender appears.

Cisco Scores Another Perfect 10

Another vulnerability in Cisco's platform has scored a perfect CVSS 10. This one allows unauthenticated attackers to perform remote code execution. The affected product is Cisco Identity Services Engine (ISE), and Cisco has already confirmed the vulnerability is being actively exploited in the wild.

What to do:
Patch any ISE deployment in your organisation immediately. Cisco has confirmed active exploitation, so this cannot wait for a routine patch cycle.

Stay safe, and share this with your team.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365