Advisories
Microsoft September 2026 Patch Tuesday Fixes 972 Flaws, Including Two Actively Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday updates address 972 vulnerabilities, including two zero-day flaws under active exploit and 113 critical-severity bugs. Security teams are urged to immediately prioritize patching affected enterprise systems.
September 2026 Patch Tuesday Overview
Microsoft has released its September 2026 Patch Tuesday security bulletin, delivering updates for a total of 972 vulnerabilities across its software suite. The massive update reflects an ongoing effort to mitigate severe risks before malicious actors can widely weaponize them.
Critical Flaws and Active Zero-Days
At the top of the remediation checklist are two zero-day vulnerabilities currently being exploited in live attacks. In addition to these zero-days, the update includes patches for 113 critical-rated flaws, many of which facilitate remote code execution and unauthorized privilege escalation across enterprise environments.
Defensive Guidance
Organizations are advised to prioritize emergency patching for high-impact systems to close exposure windows against emerging threats.
With threat actors continually automating exploit discovery, delaying patches significantly increases the probability of compromise. Security administrators should rapidly test and deploy these updates across network environments.