Security News Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Apr 24, 2016
7,838
6
83,851
8,389
55
The Netherlands
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.

The approximate number of bugs in each vulnerability category is listed below:
  • 438 Elevation of Privilege Vulnerabilities
  • 19 Security Feature Bypass Vulnerabilities
  • 258 Remote Code Execution Vulnerabilities
  • 173 Information Disclosure Vulnerabilities
  • 56 Denial of Service Vulnerabilities
  • 16 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count vulnerabilities released by Microsoft on Patch Tuesday itself.

Therefore, today's total does not include 204 flaws fixed earlier this month, including vulnerabilities in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge (Chromium-based), Microsoft Fabric, and Power Automate.
 


Hi, this headline deserves caution: the quoted figures may be accurate, but the supplied excerpt does not identify the two exploited zero-days or provide Microsoft’s official release data. The practical response is still straightforward—install September’s Windows security updates promptly, especially on internet-facing and business systems.

What the numbers actually mean​

The 966 total is BleepingComputer’s Patch Tuesday counting method, according to the quoted article. The additional 204 vulnerabilities fixed earlier in the month are excluded, so adding every figure seen in September can produce misleading comparisons.

Likewise, 258 remote-code-execution flaws does not mean all 258 can compromise an ordinary Windows PC remotely without interaction. Exploitability depends on the affected product, configuration, privileges, network exposure and whether user interaction is required.

The most important part is the report of two vulnerabilities already being exploited. Their CVE identifiers, affected products and fixed-version boundaries are absent from the excerpt, so those details cannot responsibly be inferred from the headline alone.

Recommended action​

  1. Install the September 2026 cumulative security update through Windows Update or your organization’s normal patch-management system.
  2. Restart when requested, then open Windows Update and confirm there is no failed or pending security update.
  3. In managed environments, prioritize internet-facing servers, exposed services, domain infrastructure and privileged workstations, then proceed through the tested deployment rings.
  4. Administrators should check Microsoft’s September Security Update Guide for the two exploited CVEs, affected products, known issues and any mitigation required where immediate installation is impossible.
  5. Do not download supposed “Patch Tuesday fixes” from links in email, adverts or third-party download sites. Use Windows Update, Microsoft Update Catalog or established enterprise tooling.

The record-sized count makes a dramatic headline, but vulnerability totals are a poor severity meter. Active exploitation, exposure and the affected component matter much more than raw arithmetic—966 is not a reason to panic, but it is an excellent reason not to postpone patching.
 
ZDI: The September 2026 Security Update Review
Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should be posted within a couple of hours after the release.
Adobe Patches for September 2026

For the first part of the August release, Adobe released 10 bulletins addressing 172 unique CVEs in Adobe ColdFusion, Acrobat Reader, Commerce (two bulletins), Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate, and Adobe Photoshop Mobile.

Clearly, the priority here is the Commerce bug currently under active attack. Campaign Classic and ColdFusion also clock in with a deployment priority of 1. The Acrobat Reader should also be a priority. It contains 32 CVEs, including many code execution bugs, and PDFs are a favorite of attackers. The Experience Manager has plenty of CVEs being patched and also rates a deployment priority of 2.

Besides the one bug in Commerce, none of the other Adobe bugs receiving patches this month are listed as publicly known or under active attack at the time of release.
Microsoft Patches for September 2026

It’s a new record release from Microsoft, but, again, that seems to be the new normal. As always, counting this beast is tricky, but I see 972 new CVEs rolling out from Redmond this month. As with last month, only a single CVE is listed as being under active attack, so that’s something, I suppose. As for the products affected by this release, we have Windows and Windows components, Office and Office Components, Azure and Azure Components, .NET and Visual Studio, Active Directory, Copilot Studio, Dynamics, Edge (Chromium-based), DHCP Server and Client, DNS Server, Exchange Server, Teams for Android, OpenSSH, Remote Desktop Client and Server, Skype for Business, Biometric Service, SQL Server, Windows Hello, Xbox, and Defender. Along with the external and Chromium bugs being documented this month, this drives the total CVE count to a staggering 997. Of these new CVEs, 114 are rated Critical, with the rest being rated Important.
Looking Ahead

The next Patch Tuesday will be on October 13. Assuming I survive the fun that is Pwn2Own Ireland, I’ll be back then to give you my full thoughts on the release – no matter how large it may be. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!