rootpwn

Advisories

Microsoft's September 2026 Patch Tuesday: 972 CVEs, 113 Critical, 2 Exploited Zero‑Days

On Patch Tuesday, Microsoft pushed 972 security updates, including 113 critical flaws and two zero‑day vulnerabilities that were actively leveraged in the wild. The patches cover Windows, Office, and Azure services, addressing remote code execution, privilege escalation, and data exfiltration risks. Security teams must deploy the updates immediately, validate coverage, and monitor for any lingering exposure, especially in legacy or exposed environments.

Microsoft’s September 2026 Patch Tuesday saw the company roll out a massive update suite: 972 individual CVEs, 113 of which were rated critical and two zero‑day exploits were confirmed in use by threat actors. The breadth of the patch set spans the Windows operating system, Office productivity applications, and a range of Azure cloud services.

Exploited Zero‑Days

Two high‑impact zero‑days were identified as being actively exploited prior to the release. Both vulnerabilities could be triggered via crafted documents or malicious network traffic, leading to remote code execution with system‑level privileges. The attacks leveraged previously unknown flaws in the Windows kernel and Office rendering engine.

Critical Vulnerabilities

Beyond the zero‑days, 113 critical bugs were addressed. These ranged from privilege‑escalation flaws that could allow an attacker to elevate a user account to SYSTEM, to data‑leak vulnerabilities that exposed sensitive information through improperly sanitized input. Several of the critical issues also impacted Azure services, raising the stakes for cloud‑based workloads.

Impact Assessment

  • Remote code execution on Windows 10/11 and Windows Server 2022.
  • Privilege escalation in Office 365 and Outlook on Windows.
  • Data exfiltration via Azure Blob Storage misconfigurations.
  • Potential lateral movement in enterprise networks if unpatched.

Mitigation Steps

  • Apply all available patches from the Microsoft Update Catalog or Windows Update immediately.
  • Verify that all affected components—especially legacy Office files and Azure services—are updated.
  • Enable Microsoft Defender Advanced Threat Protection to detect exploitation attempts.
  • Use CrowdStrike Falcon or a comparable EDR to monitor for suspicious activity post‑patch.
  • Conduct a quick audit of exposed services and enforce least‑privilege principles.
Microsoft urges organizations to treat these updates as critical and to validate coverage across all endpoints and cloud resources. Failure to patch could expose systems to active exploitation campaigns.

Bottom Line

The September 2026 Patch Tuesday underscores the relentless pace of vulnerability discovery and exploitation. With 972 CVEs, 113 critical flaws, and two zero‑days now fixed, the window for attackers has closed—provided defenders act swiftly. Patch, verify, monitor, and repeat.

Patch Tuesday Microsoft Zero-Day Critical Vulnerabilities Endpoint Security Remediation

← All news