Advisories
Microsoft Patch Tuesday: 972 CVEs, 113 Critical, 2 Zero‑Day Exploits – Immediate Patching Urgently Needed
Microsoft’s September 2026 Patch Tuesday saw a massive rollout of 972 security fixes, including 113 critical issues and two zero‑day vulnerabilities that have already been leveraged by threat actors. The patches cover a broad range of products, from Windows Server and Office to Azure services. The most dangerous flaws affect remote desktop, SMB, and kernel components, enabling remote code execution and privilege escalation. Organizations must apply the updates without delay, verify integrity, and monitor for suspicious activity. Failure to patch exposes systems to active exploitation and could
Microsoft’s latest Patch Tuesday has delivered a staggering 972 fixes, of which 113 are classified as critical and two have already been weaponized by adversaries. The company’s rollout covers the entire Windows ecosystem, Office suite, and key Azure services, leaving no stone unturned.
What’s New
- 113 critical CVEs, including remote code execution in Remote Desktop Services and SMBv3.
- Two zero‑day exploits now patched: one in the Windows kernel that allows local privilege escalation, and another in the Windows Update Agent that can be triggered via a malicious update package.
- Additional fixes for Office macros, Edge browser, and Azure Active Directory.
Impact Assessment
- Remote code execution can give attackers full control over vulnerable hosts.
- Privilege escalation enables lateral movement and persistence across corporate networks.
- Exploited zero‑days have already been observed in the wild, targeting high‑profile enterprises.
Immediate Mitigation Steps
- Apply all available patches as soon as possible – do not delay for “maintenance windows” if the system is exposed to the internet.
- Verify the integrity of the updates via checksum or Microsoft’s signing certificates.
- Enable automatic updates on all Windows endpoints and Azure VMs.
- Use endpoint protection to detect exploitation attempts; look for unusual RDP or SMB activity.
- Conduct a quick vulnerability scan to confirm patches are in place.
Long‑Term Recommendations
- Implement least‑privilege controls to limit the damage of any potential breach.
- Deploy network segmentation and micro‑segmentation to contain lateral movement.
- Regularly review and harden remote access configurations.
- Integrate threat hunting to identify any post‑exploitation indicators.
“If you’re still running unpatched systems, you’re essentially handing attackers a green‑lit door,” said a senior analyst at RootPwn. “Patch now, monitor constantly, and treat the rest of the infrastructure as hostile.”