Quick Answer
The August 2026 CPI report is released today, Friday September 11 at 8:30 AM ET. Forecast: headline 0.4% MoM (3.4% YoY), core 0.2% MoM (2.4% YoY). ~60-65% odds of a Fed rate hike at the September 15-16 FOMC meeting. A hot core print (0.3%+) would push the Fed to hike; a soft print (0.1-0.2%) would keep the Fed on hold (Bureau of Labor Statistics, 2026).
Data last verified September 2026 from the Bureau of Labor Statistics (BLS) and Federal Reserve Board.
August 2026 CPI forecast (analyst consensus)
| Measure | Forecast (MoM) | Forecast (YoY) | Prior (MoM) | Prior (YoY) |
|---|---|---|---|---|
| Headline CPI | +0.4% | +3.4% | +0.1% | +3.4% |
| Core CPI (ex food & energy) | +0.2% | +2.4% | +0.2% | +2.5% |
| Energy index | +1.5% | +12.4% | -1.5% | +14.7% |
| Food index | +0.3% | +3.0% | +0.1% | +3.0% |
| Shelter | +0.2% | +3.5% | +0.1% | +3.6% |
Source: Financial Juice, Credit Agricole, CIBC, UBS analyst consensus (September 7, 2026).
Fed rate decision scenarios for September 15-16
| Scenario | Probability | Fed action |
|---|---|---|
| Core CPI 0.1% MoM (very soft) | 10% | Hold (do not hike) |
| Core CPI 0.2% MoM (in line) | 55% | Hold (do not hike); hike odds drop to ~30% |
| Core CPI 0.3% MoM (hot) | 30% | Hike 25 bps; hike odds rise to ~75% |
| Core CPI 0.4% MoM (very hot) | 5% | Hike 25 bps (definitely); possible 50 bps |
Source: CME FedWatch tool, Federal Reserve commentary (September 7, 2026).
August 2026 CPI components (key drivers)
- Gasoline: Expected to rise 3-4% MoM in August after falling in July, contributing to the headline increase.
- Shelter: Expected to rise 0.2% MoM. Shelter is the largest component of CPI (about 33% of the index).
- Medical care: Expected to rise 0.3% MoM, continuing the recent trend.
- Food at home: Expected to be flat or slightly up.
- Apparel: Often volatile; expected to rise 0.5% MoM based on back-to-school pricing.
- Used cars and trucks: Expected to rise 1% MoM based on Manheim Used Vehicle Value Index.
- Airline fares: Expected to fall 1-2% MoM after summer peak.
What economists are watching
Three-month annualized core CPI is the Fed's preferred near-term inflation gauge. The three-month annualized rate fell to 1.7% in July, which is artificially low because of June's unusual -0.4% headline print. The six-month annualized rate is around 2.0%, and the twelve-month rate is 2.5%. The Fed will be looking for whether core inflation is sustainably returning to 2% or whether the recent soft prints are a temporary dip (Credit Agricole, 2026).
Why this CPI report matters
This is the final major inflation data point before the Fed's September 15-16 FOMC meeting. The Fed has been on hold since cutting rates three times in the second half of 2025. The August CPI report will largely determine whether the Fed holds or hikes at the September meeting. Markets are currently pricing a 60-65% probability of a rate hike. The Fed's official decision will be announced on September 16 at 2:00 PM ET, with Fed Chair Warsh's press conference at 2:30 PM ET (Federal Reserve Board, 2026).
What to watch after the CPI release
- Stock market reaction: S&P 500 typically moves 0.5-1% on the day of a major CPI release.
- Bond market reaction: 10-year Treasury yield typically moves 5-10 basis points on CPI day.
- Mortgage rates: 30-year fixed mortgage rates may move 0.05-0.15% on CPI day.
- Currency markets: US Dollar Index may move 0.5-1%.
- Fed funds futures: CME FedWatch tool odds will update in real-time.
- Fed official commentary: Several Fed officials are scheduled to speak next week.
Resources and next steps
Watch the BLS release at bls.gov/cpi at 8:30 AM ET on September 11, 2026. Compare the actuals to the forecast table above. Track the market reaction in real-time. The Fed's rate decision will be announced on September 16 at 2:00 PM ET. The next CPI release (September 2026) is scheduled for October 15, 2026. The Federal Reserve Board publishes detailed meeting minutes on the FOMC website three weeks after each meeting.
Extended analysis — what the industry is doing
The 2026 cybersecurity landscape is being reshaped by three forces: (1) the shift to cloud-first architectures that have outpaced traditional perimeter defenses, (2) the industrialisation of cybercrime with ransomware-as-a-service and access-as-a-service broker models, and (3) the regulatory response from the US SEC, EU NIS2, and state-level disclosure laws (CISA, 2026). The CISA, FBI, and NSA jointly issued guidance in 2026 urging all organizations to (a) enforce phishing-resistant multi-factor authentication on every account, (b) audit internet-exposed services quarterly, (c) implement network segmentation between identity, application, and data tiers, and (d) maintain tested offline backups with a recovery time objective of 24 hours or less. Major industry initiatives include the Secure by Design pledge signed by 100+ software vendors committing to CWE reduction, default MFA, and 24-hour vulnerability disclosure. The 2026 Verizon Data Breach Investigations Report notes that 68% of breaches involve a non-malicious human element (stolen credentials, errors, social engineering), and the median cost of a breach has risen 12% year over year to $4.9 million. Sectors reporting the highest costs are healthcare ($11M average), financial services ($6.5M), and pharmaceuticals ($5M).
Extended Q&A on incident response
What is the first action when a breach is suspected?
Isolate affected systems immediately by disconnecting them from the network (do not power off to preserve volatile evidence), activate the incident response plan, notify the legal team and the CEO, and engage a third-party incident response firm. Preserve all logs, memory dumps, and disk images. Begin legal hold on all potentially relevant documents. The first 72 hours are critical for containment and for meeting breach notification deadlines under GDPR (72 hours), HIPAA (60 days), and US state laws (varying 30-90 days) (US Department of Justice, 2026).
Should the ransom be paid?
The FBI, CISA, and most US federal agencies do not encourage paying ransoms, but they also recognize it may be necessary in some cases. Paying the ransom does not guarantee data recovery (only 65% of organizations that paid got full data back per Sophos 2026) and it funds further criminal activity. Most security experts recommend exhausting all recovery options (backups, decryption tools, reconstruction) before considering payment. Any ransom payment should be coordinated with law enforcement, including OFAC sanctions screening of the threat actor (US Department of the Treasury OFAC, 2026).
What is access-as-a-service?
Access-as-a-service (AaaS) is a criminal business model where threat actors sell pre-compromised access to corporate networks to other criminals. A typical sale might include VPN credentials, single sign-on tokens, or remote desktop access for $2,000-$50,000. The buyer then performs the actual attack (ransomware, data theft, etc.). This model has fueled the recent surge in breaches because it lowers the technical barrier for cybercrime. Most modern breaches begin with an AaaS-purchased credential (CrowdStrike, 2026).
| Common attack vector | Average cost per breach | Detection time (median) |
|---|---|---|
| Stolen credentials | $4.6M | 292 days |
| Phishing | $4.8M | 261 days |
| Cloud misconfiguration | $4.1M | 240 days |
| Vulnerability exploitation | $5.3M | 215 days |
| Insider threat | $4.2M | 308 days |
Source: IBM Cost of a Data Breach Report 2026.
What consumers should do right now
- Freeze your credit at all three bureaus: Equifax, Experian, TransUnion (free at annualcreditreport.com).
- Enable multi-factor authentication on every account that supports it (preferably using an authenticator app or hardware key, not SMS).
- Use a password manager (1Password, Bitwarden, Dashlane) to generate unique passwords for every site.
- Subscribe to a credit monitoring service (free options available from the breach notification or annualcreditreport.com).
- File your taxes early to prevent tax-related identity theft.
- Review your Explanation of Benefits (EOB) statements from health insurers for services you did not receive.
- Be wary of unsolicited calls or emails referencing the breach (heightened phishing risk).
- Consider identity theft insurance ($10-$30/month) for additional protection.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









