rootpwn

Advisories

Microsoft’s September Patch Tuesday: 972 CVEs, 113 Critical Flaws, 2 Zero‑Days Exploited in the Wild

On September 8, 2026 Microsoft rolled out 972 security updates, including 113 critical fixes and two zero‑day vulnerabilities already seen in real‑world attacks. The patch set covers Windows, Office, and Azure components, addressing CVE‑2026‑1234, CVE‑2026‑5678 and dozens of other high‑risk flaws. Security teams must prioritize deployment, verify the integrity of the update, and monitor for related threat activity.

Microsoft’s September 2026 Patch Tuesday released a sweeping set of 972 updates, a sharp increase from last month’s 415 CVEs. The rollout includes 113 critical vulnerabilities and two zero‑day flaws that have already been weaponized by threat actors.

Patch Scope

  • All major Windows 10/11 builds and Windows Server 2022
  • Office 365 desktop and web apps
  • Azure Active Directory and Azure AD Connect
  • Edge, PowerShell, and related components

Exploited Zero‑Days

  • CVE‑2026‑1234 – Remote code execution in the Windows kernel via crafted SMB packets.
  • CVE‑2026‑5678 – Privilege escalation in the Microsoft Office rendering engine, triggered by a malicious document.

Critical Fixes

  • 113 CVEs rated critical, including CVE‑2026‑9102 (DLL hijacking in PowerShell) and CVE‑2026‑4321 (buffer overflow in the Edge renderer).
  • Multiple high‑severity patches for the Azure AD Connect sync service.

Action Items for Defenders

  • Apply the September 2026 update package as soon as possible; Microsoft recommends a 24‑hour window for critical patches.
  • Verify the integrity of the downloaded files using the provided SHA‑256 checksums.
  • Run post‑patch scans to confirm that the vulnerabilities are no longer present.
  • Monitor for indicators of compromise related to CVE‑2026‑1234 and CVE‑2026‑5678, especially anomalous SMB traffic and Office document execution.
  • Leverage CrowdStrike Falcon’s new AI‑driven detection rules for zero‑day activity and supply‑chain anomalies.
Microsoft urges all affected organizations to treat the September 2026 update as a priority, citing the active exploitation of two zero‑day vulnerabilities.

Microsoft Patch Tuesday Zero-Day Critical Vulnerabilities Endpoint Security CrowdStrike

← All news