Advisories
Microsoft Patch Tuesday 2026: 972 CVEs, 113 Critical, Two Exploited Zero‑Days
Microsoft’s September 2026 Patch Tuesday saw 972 vulnerabilities patched, including 113 rated critical and two zero‑days that were already in the wild. CrowdStrike’s latest security releases emphasize supply‑chain protection and AI‑driven SOC evolution, underscoring the need for rapid patching and advanced detection.
Microsoft rolled out its September 2026 Patch Tuesday updates, addressing a total of 972 CVEs. The patch set includes 113 critical‑severity flaws and two zero‑day vulnerabilities that had already been leveraged by threat actors.
Key Takeaways
- Scope: 972 CVEs patched across Windows, Office, and other Microsoft products.
- Critical Impact: 113 vulnerabilities rated critical, posing high risk to enterprise environments.
- Exploited Zero‑Days: Two zero‑days—one in Windows and one in Office—were confirmed in use by attackers before the patch release.
- Patch Availability: All affected systems received security updates by the end of September 2026, with optional rollouts for legacy platforms.
"The rapid emergence of these zero‑days highlights the importance of continuous monitoring and timely patching," said a CrowdStrike analyst.
In parallel, CrowdStrike announced several new security capabilities, including enhanced endpoint protection against supply‑chain attacks and the launch of an AI‑driven Agentic SOC. These developments reinforce the industry’s shift toward proactive defense and automated incident response.
Security teams should prioritize the application of the September 2026 patches, especially for systems exposed to the identified zero‑days, and evaluate their detection posture against the new CrowdStrike offerings.