rootpwn

Advisories

Microsoft Unleashes 972 CVE Fixes on Patch Tuesday, Including 2 Exploited Zero‑Days and 113 Critical Flaws

Microsoft’s September 2026 Patch Tuesday update tackles 972 CVEs—two of which are actively exploited zero‑days and 113 critical vulnerabilities. The patch covers Windows, Office, and other Microsoft components, tightening defenses across the ecosystem. Security teams should apply the fixes immediately and monitor for any lingering exploitation attempts.

Microsoft’s September 2026 Patch Tuesday was a full‑throttle update, addressing a staggering 972 CVEs across its product line. The most pressing concerns were two zero‑days that had already seen active exploitation in the wild, and a hefty 113 critical vulnerabilities that could have serious impact if left unpatched.

What’s in the Rollout?

  • 972 total CVEs – ranging from low to critical severity.
  • 2 exploited zero‑days – actively used by threat actors to compromise systems.
  • 113 critical vulnerabilities – high‑risk flaws that could lead to remote code execution or privilege escalation.
  • Affected products include Windows 10/11, Windows Server, Office 365, Edge, and various Azure services.

Why It Matters

Zero‑days and critical flaws represent the most dangerous attack vectors. If left unpatched, they can allow attackers to execute arbitrary code, steal credentials, or pivot laterally across a network. The sheer volume of CVEs in this release underscores how rapidly the threat landscape evolves.

Immediate Actions for Security Teams

  • Prioritize the installation of the two zero‑day patches first.
  • Apply all critical vulnerability fixes as soon as possible.
  • Verify that all endpoints, servers, and cloud resources are running the updated versions.
  • Run post‑update scans to confirm that the vulnerabilities are fully remediated.
  • Update detection rules and threat intelligence feeds to reflect the newly patched state.
Microsoft urges users to apply the update immediately to mitigate the risk of exploitation.

Bottom Line

With 972 CVEs addressed, including two actively exploited zero‑days and 113 critical flaws, Microsoft’s September Patch Tuesday is a reminder that staying current is non‑negotiable. Apply the patches, verify the fixes, and keep your defenses tight.

Microsoft PatchTuesday ZeroDay CriticalVulnerabilities SecurityUpdates EndpointSecurity CVE Windows Office

← All news