After 17 years without built-in voice communication for full teams, Riot Games is rolling out team-wide voice chat in League of Legends starting with Patch 26.20. The feature launches first in North America and Oceania, with other regions like Korea, Brazil and Latin America potentially following depending on how the rollout goes. Players need an Honor level of 3 or higher to speak, though anyone can listen, and Riot is also introducing customizable 'voice skins' along with improved noise cancellation and connection stability.
Microsoft has issued the KB5122878 update for Windows 10 Enterprise LTSC and machines enrolled in the Extended Security Updates program, bumping systems to build 19045.7725 (or 19044.7725 for LTSC 2021). The update bundles this month's Patch Tuesday security fixes plus smaller changes covering Secure Boot certificate rollout, a time-zone correction for Morocco, and diagnostic and compatibility tweaks.
Microsoft's latest Patch Tuesday release addresses 966 vulnerabilities, its largest batch ever, including 105 rated Critical and two zero-days already being exploited in the wild. The count excludes 204 additional flaws Microsoft patched earlier in the month across products like Azure AI Language, Copilot Studio, and Entra ID.
Microsoft has shipped the September 2026 Patch Tuesday cumulative updates KB5124008 and KB5122880 for Windows 11 versions 25H2/24H2 and 23H2. The update patches roughly 1,000 vulnerabilities catalogued in recent months and is mandatory, installable via Windows Update or the Microsoft Update Catalog. Since 25H2 shares its codebase with 24H2, both versions receive identical fixes and features.
Microsoft is set to release its largest patch Tuesday yet, fixing more than 650 security vulnerabilities in Windows, according to sources. This follows a summer of escalating patch counts—around 200 in June, 570 in July, and nearly 400 in August—driven by AI models from Anthropic and OpenAI that are uncovering software flaws far faster than before.
ConnectWise disclosed a new security flaw in its ScreenConnect remote access platform affecting file transfer behavior in both cloud and on-premises deployments. The vulnerability has no CVE identifier yet and no official patch, though the company says a fix is coming later this week. In the meantime, ConnectWise published manual mitigation steps requiring administrators to disable file transfer permissions across user roles.
N-able released N-central 2026.3 Hotfix 4 on Saturday to fix CVE-2026-86218, a maximum-severity remote code execution bug that lets unauthenticated attackers run code on unpatched, internet-exposed servers. Shadowserver counts nearly 1,500 exposed N-central instances, mostly in the US and Europe, while security firm Huntress suspects the flaw, along with two related authentication-bypass bugs, may already have been exploited as a zero-day in at least one customer breach.
MikroTik simultaneously released RouterOS 7.23.4, 7.24.2 and 6.49.21 on September 3, 2026, each flagging an unspecified 'important security update' without disclosing details. A security researcher reverse-engineered the binary diffs across versions and identified two exploitable flaws: a low-exponent RSA signature forgery leading to an mtget buffer overflow, and an SSH authentication bug where a username value of -2 grants a read-only session elevated privileges, enabling full command execution on the router.
Security firm Rietta rolled out an emergency hotfix across its client base on July 29, 2026, after a Ruby on Rails ActiveStorage vulnerability—later named KindaRails2Shell and tracked as CVE-2026-66066—jumped from an unrated update to a 9.5/10 CVSS severity score within hours. The flaw, discovered by researchers at Ethiack, allows arbitrary file read and remote code execution through variant processing in Active Storage, a core Rails component used in Rails 8 and newer.
HPE has released patches for CVE-2026-73749, a critical buffer overflow in ArubaOS-CX that lets unauthenticated attackers send malformed packets to a daemon to gain elevated code execution. The bulletin also lists 23 other vulnerabilities, several rated high severity, affecting management and web modules across multiple AOS-CX release branches. One vulnerable version has already reached end of maintenance but still received a fix due to the severity of the flaw.
Plex is urging all users to immediately update Plex Media Server to version 1.43.3 and Plex Desktop to version 1.115.0, both released earlier this year, to fix multiple unspecified security vulnerabilities. The company emailed affected customers directly and said CVE identifiers have been requested but not yet published, though the flaws are known to impact Media Server v1.43.2 and earlier.
Shadowserver has identified nearly 22,000 internet-exposed Microsoft Exchange servers that remain unpatched against CVE-2026-62911, a high-severity authentication bypass flaw affecting Exchange Server 2016, 2019, and Subscription Edition. Most vulnerable systems are located in the United States and Germany, where officials say roughly 85% of on-premises Exchange servers remain exposed despite Microsoft releasing a fix in August 2026.