rootpwn

Advisories

Microsoft Patch Tuesday 2026: 972 CVEs, 113 Critical, 2 Exploited Zero‑Days

Microsoft’s September 2026 Patch Tuesday saw the release of 972 security fixes, including 113 critical issues and two zero‑days that had already been weaponized. The updates span Windows, Office, and other key Microsoft products, underscoring the urgency for rapid patch deployment across all environments.

Microsoft rolled out a comprehensive patch set on September 8, 2026, addressing 972 CVEs in total. The update package includes 113 critical vulnerabilities, the majority of which impact core Windows and Office components. Two of the most severe flaws were already being exploited in the wild, prompting an immediate response from the security community.

Key Highlights

  • 972 total CVEs – a mix of low, moderate, and high severity issues.
  • 113 critical vulnerabilities – spanning Windows OS, Windows Server, Office suite, and Azure services.
  • 2 zero‑days in active exploitation – affecting Windows Explorer and Office Word processing engines.
  • Patch deployment timeline: initial release on 8 Sep 2026 with phased rollouts for legacy systems.

Microsoft’s advisory stresses that the zero‑day flaws could allow remote code execution via crafted documents or malicious file attachments. The patches also address numerous privilege escalation and information disclosure bugs that could aid lateral movement within an enterprise.

“We urge all organizations to apply the September 2026 updates immediately, prioritizing critical fixes and zero‑day mitigations,” Microsoft’s Security Response Team noted.

Security teams should verify that all endpoints—desktop, server, and cloud—receive the updates. For environments still running older Windows versions (e.g., Windows 7 or 8.1), Microsoft recommends moving to supported platforms or applying the extended security updates where available.

In addition to the patch rollout, Microsoft released detailed guidance on remediation steps for each critical CVE. The guidance includes configuration changes, registry edits, and optional mitigations for systems that cannot be patched promptly.

RootPwn will continue monitoring the post‑patch landscape for any new exploits or related indicators of compromise. Stay tuned for deeper dives into the zero‑day vectors and how they were leveraged in real‑world attacks.

Microsoft Patch Tuesday Zero-Day Critical Vulnerabilities Security Updates Windows Office

← All news