September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days
Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including two actively exploited Windows elevation-of-privilege zero-days added to CISA's KEV catalog.
Microsoft's September 2026 Patch Tuesday release addresses 974 vulnerabilities, one of the largest monthly batch sizes. Two of the flaws are actively exploited zero-days, and both are Windows elevation-of-privilege vulnerabilities. CISA added both zero-days to its Known Exploited Vulnerabilities catalog, subjecting them to federal patching deadlines. SOCRadar's report provides a breakdown of the patched vulnerabilities by category.
- September 2026 Patch Tuesday fixes 974 Microsoft vulnerabilities across product lines.
- Two actively exploited zero-days are Windows elevation-of-privilege flaws.
- Both zero-days were added to CISA's KEV catalog, triggering federal patching timelines.
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days Microsoft’s September 2026 Patch Tuesday release addresses 974 vulnerabilities, including two actively exploited zero-days. Both zero-days are Windows elevation of privilege flaws, and both were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Here’s a breakdown of vulnerability categories in this Patch Tuesday cycle: September 2026 Patch Tuesday vulnerabilities […]
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.