Between 27 August and 9 September 2026, the Cyber Security Agency of Singapore told organisations here to patch two products immediately and a third promptly, and listed the critical items in Microsoft's monthly patch set; its June advisory on FortiGate credentials still stands. In the week of 10 September, the security press reported ransomware groups exploiting two firewall products, one of them nine months after its patch shipped. If your business runs any of that software, this is the week the gap between "a patch exists" and "we applied it" became a fact about your cyber insurance as well as your security.

The Answer in 60 Seconds On 9 September 2026 CSA issued three alerts in one day: four SAP vulnerabilities scored up to 10.0 out of 10 with the instruction "Patch immediately" (CSA alert AL-2026-119), a PostgreSQL flaw that lets a database user who holds replication rights but is not a superuser run code as the server's operating-system account (CSA alert AL-2026-120), and Microsoft's September patch set with three critical items scored 9.9 or higher (CSA alert AL-2026-116). Two weeks earlier it was Apache Tomcat at 9.1 (CSA alert AL-2026-112). On 9 and 10 September the US agency CISA added six vulnerabilities to its list of flaws under active exploitation, five of them in network equipment - a Fortinet product line, a Citrix NetScaler gateway, a Cisco firewall manager and MikroTik routers - and the sixth in the Chromium browser engine (CISA, 9 September 2026).

The insurance question is not whether to patch. CSA has answered that. The question is what a patch you did not apply does to a claim, and the answer sits in two documents: the proposal form you signed and the wording you were issued. One published Singapore SME cyber proposal form defines "Neglected Software" as exploitation of a vulnerability in software after its support has ended, or "when the software is unpatched 45 days after a patch has been made available", and its first page states that a failure to disclose material facts means "the policy issued may be void" (Chubb Insurance Singapore, Cyber ERM SME proposal form). Of two other published wordings, one mentions patching only as a cost its betterment exclusion carves back, and the other carries no patching clause at all. The clause is in some documents and absent from others, so the document that governs your business is the one to read this week.

The Sourced Detail

What CSA told you to do this fortnight

CSA's alerts are short and they use verbs. The SAP alert of 9 September 2026 covers four vulnerabilities (CVE-2026-44756 at CVSS 10.0, CVE-2026-58240 at 9.8, CVE-2026-76969 at 9.4 and CVE-2026-66768 at 9.0) that allow arbitrary command execution, credential theft and the deletion of tenant data, and its summary line ends "Patch immediately" (CSA AL-2026-119). The PostgreSQL alert covers CVE-2026-6471, a missing-authorisation flaw in logical decoding that affects every version before 18.6, 17.11, 16.15, 15.19 and 14.24, and tells administrators to update "promptly" (CSA AL-2026-120). The monthly Microsoft alert lists the critical items by CVE, including an Azure AD B2C and an Azure AI Language flaw both scored 10.0 and an Entra ID flaw at 9.9 (CSA AL-2026-116). The Tomcat alert of 27 August covers CVE-2026-65182, an unauthenticated bypass of security constraints across the 9, 10 and 11 release lines (CSA AL-2026-112).

The FortiGate advisory is a different kind of instruction. On 22 June 2026 CSA reported that a threat actor had leaked the credentials of over 70,000 FortiGate devices worldwide after brute-force and credential-stuffing attempts against internet-facing firewall and VPN portals, and told organisations to check whether they were in the leaked dataset, terminate every active administrative and VPN session, reset the passwords and enable multi-factor authentication on every administrator and VPN account (CSA advisory AD-2026-007). A patch does not fix a stolen password. The advisory is about the second half of the same discipline: what runs at your edge, and who can log in to it.

CISA's catalogue tells you which flaws attackers are using right now. Its additions of 9 September 2026 were a Fortinet buffer overflow, a Citrix NetScaler authentication bypass, a Chromium V8 flaw and a Cisco Firewall Management Center authentication bypass, each added "based on evidence of active exploitation"; on 10 September it added two MikroTik RouterOS flaws (CISA, 9 September 2026; CISA, 10 September 2026). The same pages state the rule CISA applies to US federal agencies and encourages every organisation to adopt: fix first the catalogued flaws "on publicly exposed assets that grant total control of the asset post-exploitation". For a small business that is a one-line vulnerability policy: the internet-facing device that hands an attacker total control of itself gets patched before anything else.

What the press reported the same week shows the cost of the interval. Cisco Talos, as reported by BleepingComputer on 10 September 2026, found the Cisco Firewall Management Center flaws exploited by three separate threat clusters, with Qilin ransomware deployed in some of the attacks (BleepingComputer, 10 September 2026). The same outlet reported CISA's confirmation that a WatchGuard Firebox flaw patched in December 2025 is now exploited in ransomware attacks, nine months after the fix shipped (BleepingComputer, 10 September 2026). And GreyNoise, reported the same day, traced a campaign that used hundreds of AI agents to build and launch exploits against a print-management product, compromising at least 440 installations at 395 organisations in 48 countries in under two weeks (BleepingComputer, 10 September 2026). The attacker's cost of finding you has fallen to the price of compute. The interval between a patch and your applying it is the whole of your exposure.

Why this lands on small businesses

CSA's own numbers say where the infections are. Its Singapore Cyber Landscape release of 30 June 2026 reports 284,300 pieces of infected infrastructure detected in Singapore in 2025, a 142 per cent increase on 2024, driven in part by consumer Internet-of-Things devices "with weak security configurations or unpatched firmware"; it puts reported ransomware cases at 165 in 2025 against 159 the year before, and states that small and medium enterprises "continued to be disproportionately affected due to comparatively lower cybersecurity maturity and limited resources" (CSA, 30 June 2026). The same release names two things an SME can use: the Cyber Resilience Centre, which offers cybersecurity health checks and recovery assistance after an incident, and the CISOaaS programme, under which eligible SMEs receive up to 70 per cent co-funding for cybersecurity advisory services.

The Singapore yardstick: what Cyber Essentials requires

Singapore has a published standard for what a small organisation does about updates, and CSA-appointed certification bodies certify against it. The Cyber Essentials mark, in its April 2025 second edition, states at clause A.7.4(a) that the organisation "shall prioritise the implementation of critical or important updates for operating systems and applications (e.g., security patches), obtained from official or trusted sources ... as soon as feasible", and, in the operational-technology column of A.7.4(c), that for known exploited vulnerabilities "the organisation should perform updates as soon as possible, factoring in when it is safe and appropriate to do so" (CSA, Cyber Essentials mark, April 2025). The same document's asset-inventory clause, A.2.4, expects the inventory to record each asset's end-of-support date, which is the field that tells you a product has left the patch cycle altogether.

Certification is valid for two years, and CSA funds first certifications for SMEs and non-profits incorporated in Singapore at S$250 to S$725 depending on the number of endpoints and the focus area, with the support available to 6 February 2028 (CSA, Certification for the Cyber Essentials mark). The mark matters here for a reason beyond security: it is a dated, third-party record that your update practice met a published standard.

The PDPA yardstick: what "reasonable security arrangements" has meant in practice

If the unpatched system holds personal data, a second document applies before any insurance does. Section 24 of the Personal Data Protection Act requires an organisation to protect personal data in its possession or under its control by making reasonable security arrangements to prevent unauthorised access, collection, use, disclosure, copying, modification or disposal (PDPA 2012, section 24). The Personal Data Protection Commission decides what "reasonable" meant after the fact, and its published decisions are specific.

In Ezynetic Pte. Ltd. ([2025] SGPDPCS 2), a Singapore software-as-a-service provider to licensed moneylenders was hit by ransomware on or about 24 June 2024 and the personal data of 190,589 individuals was exfiltrated and posted for sale (PDPC, Ezynetic Pte. Ltd. [2025] SGPDPCS 2). The Commission found that the attacker "exploited a vulnerable web service application" to take the system administrator account, that the account's password was "p@ssword1 or Password@1", and that the organisation "did not perform any periodic vulnerability assessment or penetration testing of its infrastructure". It quoted its own checklist: organisations should, as a basic practice, periodically conduct web application vulnerability scanning and assessments after deployment. The financial penalty was S$17,500, and the Commission also directed the organisation under section 48I to obtain CSA's Cyber Trust mark certification for its rebuilt network (same decision). Read that direction carefully. The regulator's remedy for a vulnerability that was never scanned for was a CSA certification.

What the insurance documents say

Now the two documents that decide the claim. The first is the proposal form. Chubb Insurance Singapore's published pre-priced proposal form for its SME cyber product defines "Neglected Software" as "exploitation of a vulnerability in software after support for that software has ended or been withdrawn; or when the software is unpatched 45 days after a patch has been made available" (Chubb Insurance Singapore, Cyber ERM SME proposal form, definitions). The same form's qualifying questions ask whether remote access to your network and email requires multi-factor authentication, whether backups of mission-critical data are protected by MFA, offline segmentation or immutable storage, whether endpoint protection runs on laptops, desktops and servers, and whether an email security solution is in place. Its first page sets out the duty of disclosure: you must disclose "every matter within your knowledge that is material to the insurer's decision", and if you are unsure whether a matter is material, disclose it, because otherwise "the policy issued may be void" (same form, page 1).

The second document is the wording, and here the documents differ. AIG Asia Pacific Insurance's published CyberEdge wording for Singapore contains no neglected-software or end-of-life exclusion; the one place patching appears is a carve-back in its betterment exclusion, which allows "the patching or updating of [a] component of the Company Computer System required to resolve a Security Failure" where the bricking-recovery cover is purchased (AIG Asia Pacific Insurance, CyberEdge policy wording, Singapore). QBE's published Asia Pacific Cyber and Data Security wording carries no patching clause either; what it does make a condition precedent to the insurer's liability is the observance of its claim-notification, insured's-duties and claim-procedure provisions (QBE, Cyber and Data Security policy wording).

Three published documents, three different treatments of the same fact. A patch you did not apply is a fact about your risk twice over: at the point you answered the proposal form, where the duty of disclosure applies to it, and at the point of a claim, where a definition like the 45-day one sets the terms on which the loss is paid. Which of the two applies to you, and how, is written in your own documents and nowhere else.

Three clocks, one week of alerts

CSA's clock says "immediately". Cyber Essentials says "as soon as feasible" for critical updates, and its operational-technology column says "as soon as possible" for known exploited vulnerabilities. One published proposal form's clock runs 45 days from the day the patch is available (Chubb Insurance Singapore, proposal form definitions). A week of CSA alerts is therefore a dated list: for every product on it that you run, the patch the alert points to is already available, so the 45-day clock is already running, and the WatchGuard case shows what nine months on that clock looks like.

Common Mistakes

  1. Reading the alert as an IT matter and the policy as a finance matter. The two documents describe the same fact. The person who owns the patch schedule and the person who signed the proposal form are looking at one risk from two sides.
  2. Answering the proposal form from memory. The qualifying questions - remote-access MFA, protected backups, endpoint protection, email security - are answered from the system record, and the duty to disclose every material matter reaches the patches you know you have not applied, whether or not the form asks.
  3. Counting only servers. Five of CISA's six additions this week are network equipment: firewalls, a remote-access gateway, a firewall manager and routers. The internet-facing device that hands an attacker total control of itself is the one the catalogue tells you to fix first.
  4. Treating a stolen password as a separate problem from patching. CSA's FortiGate advisory is a credential advisory for a firewall product. Reset, then enable MFA, is part of the same discipline as update.
  5. Keeping software past its end of support because it still works. The neglected-software definition starts with support ending, not with a patch being missed. A product with no vendor has no patch to apply.
  6. Assuming every wording says the same thing. Of three published documents, one defines neglected software at 45 days (the published proposal form), one mentions patching only as a cost its betterment exclusion carves back, and one says nothing about patching at all. Your own wording and form decide your case.

What This Means for Your Business

If your business runs any software on this fortnight's CSA list, the list is your work order and the alert dates are your evidence trail.

For a software or SaaS company. The Ezynetic decision is your sector's precedent: a SaaS provider, an unscanned web application, a default-grade password, a regulator's penalty and a direction to certify with CSA. Periodic vulnerability scanning of what you expose to the internet is the PDPC's stated basic practice, and the date of your last scan is the fact the Ezynetic decision turned on.

For a business with a firewall appliance and remote access. CISA's list this week names flaws in Fortinet, Citrix NetScaler, Cisco Firewall Management Center and MikroTik RouterOS products, and its WatchGuard Firebox entry now carries a ransomware flag; if your edge device is one of these, check its version against the catalogue entry. Follow CSA's FortiGate steps for credentials and MFA even if your device is another brand, because the method is the same.

For a business that outsources its IT. The duty of disclosure on the proposal form is yours, not your provider's. Ask the provider for the patch log and the end-of-support list in writing, and keep both with the policy documents. Cyber Essentials certification, funded for SMEs, gives you a dated third-party record that the practice met a published standard.

For all of the above. Read your own proposal form and wording for the words "patch", "unpatched", "unsupported", "end of life" and "neglected". If they are there, note the clock they set. If they are not, note that too, and bring the question to your renewal.

Questions to Ask Your Adviser

  1. Does my current wording, or the proposal form I signed, define neglected or unsupported software, and what clock does it set?
  2. If a breach traces to a vulnerability whose patch was available before the incident, which part of the cover responds and which does not?
  3. What did I declare about patching, MFA and backups on the proposal form, and does my current practice still match those answers?
  4. Would a Cyber Essentials or Cyber Trust certification change how the risk is assessed at renewal?
  5. Does the policy respond to a regulator's investigation and directions, such as the PDPC's direction in the Ezynetic case, or only to the financial penalty?
  6. If my IT is outsourced and the provider missed a patch, does my policy respond to my loss, and does the provider's cover respond to theirs?
  7. Which of my internet-facing systems would the insurer regard as the ones that grant total control if compromised, and are they on this month's alert list?

Related Information

Published 11 September 2026. Source verified 11 September 2026.