rootpwn

Advisories

Microsoft Patch Tuesday: 972 CVEs, 113 Critical, 2 Exploited Zero‑Days

Microsoft’s September 2026 Patch Tuesday saw the release of security updates for 972 vulnerabilities, including 113 critical flaws and two zero‑days that had already been leveraged by attackers. The roll‑out underscores the ongoing urgency of patching across the Microsoft ecosystem and highlights the scale of the patching effort required to stay ahead of emerging threats.

On September 8, 2026, Microsoft rolled out its latest Patch Tuesday update, addressing a staggering 972 CVEs. Of these, 113 were classified as critical, and two zero‑day vulnerabilities had already been actively exploited in the wild.

Key Numbers

  • Total CVEs patched: 972
  • Critical vulnerabilities fixed: 113
  • Exploited zero‑days addressed: 2

The two zero‑day flaws, discovered early in the month, were tied to high‑profile attacks targeting Windows and Office components. Microsoft’s swift patching of these vulnerabilities demonstrates the company’s commitment to closing the exploitation window before attackers can pivot to new vectors.

Security teams should prioritize applying the latest updates across all affected systems—especially legacy Windows environments—since the patch set also includes numerous medium and low‑severity fixes that could otherwise be overlooked.

“Patch Tuesday is no longer a routine event; it’s a critical line of defense against emerging threats.”

With the patch release now available, organizations are advised to verify deployment across endpoints, validate that the patches do not disrupt business processes, and monitor for any post‑patch anomalies.

Patch Tuesday Zero-Day Microsoft Critical Vulnerabilities Security Updates

← All news