This Week in Change Risk — Week of Sep 7, 2026
Your weekly digest for change and risk managers. Written from primary sources, with a named limitation on every vendor and tool mentioned. This is operational context, not legal or compliance advice. Some outbound links may be affiliate links.
KEV additions this week
CISA added 10 CVEs to the Known Exploited Vulnerabilities catalog during the week of September 7. The two that matter most for Windows shops arrived September 8 straight out of Patch Tuesday: CVE-2026-81963, a link-following flaw in the Windows Update Stack, and CVE-2026-85880, a heap-based issue in the Windows Advanced Local Procedure Call subsystem — both elevation-of-privilege bugs Microsoft confirmed as exploited. The same September 8 batch added CVE-2026-75650 in Adobe Commerce and Magento Open Source, plus CVE-2026-86218, a static code-injection flaw in N-able N-central. September 9 brought a heavier edge-appliance day: CVE-2026-19490 in Citrix NetScaler ADC and Gateway (authentication bypass), CVE-2025-25249 across multiple Fortinet products, CVE-2026-20079 in Cisco Secure Firewall Management Center, and a Google Chromium V8 out-of-bounds write, CVE-2026-87491. The week closed September 10 with two MikroTik RouterOS entries, CVE-2026-86060 and CVE-2026-67277. Edge and identity infrastructure dominated again.
Cloud incidents worth noting
No hyperscaler ran a multi-region, change-freeze-grade P1 this week, but Cloudflare had a visibly busy few days worth flagging for anyone whose stack sits behind it. Its own status history lists increased errors on Cloudflare Workers AI and degraded Workers Cron Triggers on September 9, DNS update delays the same day, an issue editing Bulk Redirects on September 10, and both Workers VPC hostname route-resolution problems and Let’s Encrypt SSL certificate provisioning delays on September 11. None were platform-wide, but the SSL provisioning delay is the kind of thing that silently breaks a deploy: if your release pipeline waits on a freshly issued certificate, a provisioning backlog turns a green change into a stuck one. The change-management takeaway is to treat certificate issuance as a dependency in your rollout plan, not an afterthought, and to keep an eye on the AWS us-east-1 outage timeline as a reminder that the quiet weeks are for claiming deferred maintenance windows.
Vendor moves
Two vendor notes stood out, both with a caveat. Snyk shipped CLI fixes this week per its product updates feed, including a v1.1307 line that removed an unused experimental feature and restored exit-code-3 behavior for repositories with no supported manifest files. That exit-code fix matters if you gate a pipeline on Snyk’s return code — the earlier regression could have let a misconfigured scan pass silently, so anyone who pinned an affected version should confirm their CI still fails closed. On the compliance-automation side, Vanta’s product updates had no new release dated this week; the most recent notes remain the week of August 30, a reminder that a quiet changelog is not the same as a quiet product and that you should verify a claimed capability in a trial rather than assume the newest feature shipped. For teams weighing evidence platforms, our Vanta vs Drata vs Secureframe comparison names a concrete limitation of each.
Compliance & regulatory
The standing compliance clock for anyone touching card data is PCI DSS v4.0.1, whose future-dated requirements became mandatory earlier this year per the PCI Security Standards Council. The grace period that let organizations treat dozens of requirements as best-practice is over, and requirement 6.4.3 — inventory and integrity control of payment-page scripts — is the one that trips change teams most, because a routine front-end deploy can now introduce an unauthorized script and a compliance finding in the same push. The practical control is to wire script-integrity checks into your change process so a payment-page change cannot ship without an updated authorized-script inventory. The one weakness worth naming: the standard tells you what to control, not how, so the tooling and evidence trail are on you, which is exactly where the evidence-platform choice from this week’s comparison comes back into play.
Change-management community
The genuinely useful community thread this week was a Hacker News discussion of a crowdsourced tracker for what each Windows and Microsoft 365 update breaks. It is a fitting companion to a record Patch Tuesday: the value of a community-maintained known-issues list is that it surfaces the regression a vendor advisory buries or omits, which is precisely the input a Change Advisory Board needs before approving a broad patch rollout. The limitation, and the reason to read it critically, is that crowdsourced reports are unverified and skew toward the loudest failures, so treat the tracker as a lead for your own test-ring validation rather than as authoritative. The right move is to stage the patch in a representative ring, watch both the vendor advisory and the community tracker, and only then widen the change.
Chart of the week
KEV additions held at 10 this week, the third straight double-digit week after the mid-August step-up and comfortably above the eight-week average of about seven. The chart below pulls the count for the last eight ISO weeks live from the CISA catalog.

The pattern to watch is not any single week but the floor: the recent weeks have not dipped back to the three-to-six range that was normal in mid-summer. If double-digit KEV weeks are the new baseline, the emergency-change track that used to fire a few times a month is now a standing weekly load, and staffing the change risk score tool into your intake is how you keep triage consistent when the volume does not let up. This sits within the broader cybersecurity coverage on the site.
The newsletter
If you want this digest in your inbox every Friday — the KEV additions that carry a federal deadline, the cloud incidents that actually threaten a release, and one original chart — the Change Risk Intel newsletter is where it lands first. No fluff, primary sources only.
Recommended reading from this week and the archive:
- Vanta vs Drata vs Secureframe: Evidence Collection Compared
- Print Server Emergency Change: When a Utility App Turns Critical
- Compensating Controls Register: What Auditors Accept
Sources
- CISA — Known Exploited Vulnerabilities Catalog
- Qualys — Microsoft Patch Tuesday, September 2026 review
- Citrix — NetScaler ADC and Gateway security bulletin (CTX696939)
- Cloudflare — Incident history
- Snyk — Product updates
- Vanta — Product updates
- PCI Security Standards Council — PCI DSS v4.0.1
- Hacker News — Crowdsourced tracker for what each Windows/M365 update breaks
Published September 11, 2026.