ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity1

September 2026 Patch Tuesday forecast: All we need is more time

AI summary · glm-5.3-flash

September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.

This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.

  • August 2026 Patch Tuesday fixed 398 CVEs (42 Critical), but only one was confirmed exploited in the wild
  • SharePoint CVE-2026-55040 and CVE-2026-63520 chained for authentication bypass and RCE in active exploitation
  • Exchange Server CVE-2026-62911 (CVSS 8.0) allows takeover of all user mailboxes and is considered ripe for exploitation
  • Microsoft Defender ShieldBreak CVE-2026-69414 has PoC exploit code; fix expected in September Patch Tuesday
  • Chrome update 152.0.7977.82/.83 fixed 12 CVEs including in-the-wild exploited CVE-2026-85046

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-55040
Authentication Bypass in Microsoft SharePoint Server

Microsoft SharePoint Server is affected by a weak authentication vulnerability (CWE-1390) that allows an unauthorized attacker to bypass a security feature over a network. Per the CVSS vector, exploitation requires no privileges and no user interaction with low attack complexity, so any unauthenticated attacker with network access to a vulnerable server can trigger it remotely. Impact to confidentiality and integrity is rated high (CVSS 9.1, critical), meaning the bypass effectively grants the attacker access that authentication should have prevented, with no direct availability impact. All organizations running on-premises Microsoft SharePoint Server are potentially affected; the source data does not specify affected version ranges or fixed builds, so defenders should consult Microsoft's advisory for those details. The flaw is under active exploitation: a public proof-of-concept is available on GitHub, attackers began exploiting it after the PoC went public, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-18 (EPSS ~40%, 99th percentile; ransomware association unknown).

Do: Apply Microsoft's security update for CVE-2026-55040 immediately, prioritizing internet-facing SharePoint servers, and comply with CISA BOD 26-04 and the agency's Forensics Triage Requirements, including checking for signs of prior compromise on SharePoint servers. Use the public GitHub proof-of-concept to validate patching and detection coverage, and restrict network exposure of SharePoint until all servers are updated.

9.151% KEV PoC ×2
  • Microsoft SharePoint Server
mass≈tens of thousands of internet-exposed SharePoint Server instances, within an installed base spanning hundreds of thousands of enterprise and government…
CVE-2026-62911
Capture-Replay Authentication Bypass in Microsoft Exchange Server

Microsoft Exchange Server contains an authentication bypass flaw (CWE-294) in which captured authentication material can be replayed, allowing an authorized attacker to elevate privileges over a network. Per the CVSS vector, the attack is network-based with low complexity but requires the attacker to already hold low privileges and some user interaction, and success yields high impact on confidentiality, integrity, and availability. Affected products include on-premises Exchange Server and Exchange Server Subscription Edition, though specific vulnerable version ranges are not specified in the available data. Public scans indicate nearly 22,000 Exchange servers remain exposed to the flaw following the August 2026 Patch Tuesday fixes. No in-the-wild exploitation, public proof-of-concept, or KEV listing is known; the bug was demonstrated at Pwn2Own (ZDI-26-534) and carries an EPSS estimate of 1.3% probability of exploitation within 30 days.

Do: Apply the Exchange Server security updates released in Microsoft's August 2026 Patch Tuesday (refer to Microsoft's advisory for the exact fixed builds) on all on-premises servers, prioritizing internet-facing systems running OWA, EWS, or ActiveSync. Until patched, limit network exposure of Exchange endpoints to trusted networks and monitor authentication logs for replay-style anomalies; per the scan data, roughly 22,000 servers still need the update.

8.01%
  • microsoft exchange server
  • microsoft exchange server subscription edition
large≈22,000 internet-exposed Exchange servers
CVE-2026-63520
Unauthenticated RCE in Microsoft SharePoint Server

CVE-2026-63520 is an improper input validation flaw (CWE-20) in Microsoft Office SharePoint, affecting on-premises SharePoint Server deployments. A remote, unauthenticated attacker can trigger the flaw by sending improperly validated input to the SharePoint service over the network; the high attack complexity (AC:H) indicates exploitation depends on specific conditions, but no privileges or user interaction are required. Successful exploitation results in arbitrary code execution on the server, with high impact to confidentiality, integrity, and availability — effectively full compromise of the SharePoint host. Organizations running self-hosted SharePoint Server are in scope; SharePoint Online/Microsoft 365 is not listed in the affected products. The issue is patched as of Microsoft's Patch Tuesday (headlines mark it FIXED), with Rapid7 analysis and a researcher-disclosed exploit chain available, but there is no public PoC, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS puts exploitation probability at 2.9% (86th percentile).

Do: Apply Microsoft's Patch Tuesday security updates for SharePoint Server as soon as possible, prioritizing internet-facing farms, since the flaw requires no authentication and grants code execution. As interim mitigation, restrict network exposure of SharePoint front-ends (VPN/WAF/reverse proxy rules) and verify all farm servers receive the update. Monitor vendor advisories and the Rapid7 analysis for details on the vulnerable code paths, since no public PoC or in-the-wild exploitation has been confirmed yet.

8.13%
  • Microsoft SharePoint Server (Office SharePoint, on-premises)
masshundreds of thousands of on-prem SharePoint Server installations (>1M enterprise users)
CVE-2026-65801
SSRF Privilege Elevation in Microsoft Exchange Online

CVE-2026-65801 is a server-side request forgery (CWE-918) in Microsoft's cloud-hosted Exchange Online service that an unauthorized attacker can reach over the network without credentials or user interaction. A crafted request causes Exchange Online server components to issue requests toward internal service endpoints, and the scope-changed CVSS 3.1 vector (S:C with high confidentiality, integrity, and availability impact) indicates the resulting privilege elevation extends beyond the initially targeted component. A successful attacker gains elevated privileges within the Exchange Online service, potentially enabling broader access to mailbox data and service functionality. All organizations with mailboxes hosted in Exchange Online are in scope; because this is a flaw in Microsoft's managed service, customers cannot patch it themselves and depend on Microsoft's service-side remediation. Exploitation has not been publicly confirmed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.

Do: Monitor the MSRC advisory for CVE-2026-65801 and the Microsoft 365 admin center Message Center for Microsoft's service-side fix and remediation timeline; no customer-side patch or version upgrade applies. Until remediation is confirmed, review Exchange Online audit logs (Unified Audit Log) for anomalous privilege changes or unusual server-side activity, and report any suspected exploitation to MSRC.

10.0<1%
  • Microsoft Exchange Online (hosted cloud service) Microsoft-managed cloud service; no customer-deployed version numbers apply (none provided in the data)
masshundreds of millions of mailboxes across Microsoft 365 tenants (the entire hosted Exchange Online service is in scope)
CVE-2026-65816
Unauthenticated Privilege Elevation Flaw in Microsoft Azure Arc

Microsoft Azure Arc contains a use of incorrectly-resolved name or reference (CWE-706) that allows an unauthorized, unauthenticated attacker to elevate privileges over a network. The flaw is triggered through network access alone, with no privileges, user interaction, or complex conditions required, as reflected in its maximum CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope-changed metric indicates the attack crosses a security boundary, so an attacker who reaches the vulnerable component could gain elevated privileges with high impact on confidentiality, integrity, and availability. Organizations that have enrolled on-premises or multicloud resources into Azure Arc are affected; the source data provides no specific affected version ranges, and the CPE product entry also references Azure Web Apps while the description names Azure Arc. There is currently no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.5% 30-day exploitation probability (43rd percentile), indicating no confirmed in-the-wild exploitation.

Do: No fixed version numbers are included in the source data, so consult Microsoft's advisory and the September 2026 Patch Tuesday release for the Azure Arc update and apply it promptly when published. In the meantime, inventory Azure Arc-enabled servers and other enrolled resources, restrict network exposure of Arc agent and management endpoints to trusted management paths, and monitor Microsoft's advisory for changes to exploitation status. Given the maximum CVSS score but no PoC or KEV listing yet, treat this as a high-priority patch rather than an emergency, and escalate if Microsoft confirms active exploitation.

10.0<1%
  • Microsoft Azure Arc
  • Microsoft Azure Web Apps (listed in CPE product data; description names Azure Arc)
large≈ hundreds of thousands of Arc-enrolled machines across enterprise tenants (deployment-pattern estimate; exact counts not in source data)
CVE-2026-69414
Local Elevation of Privilege in Microsoft Defender Malware Protection Engine

CVE-2026-69414, publicly dubbed 'ShieldBreak', is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Microsoft Malware Protection Engine (MMPE) that powers Microsoft Defender, rooted in improper access control and improper privilege management (CWE-284/CWE-269). It is triggered locally: an attacker who already holds low privileges on the machine needs no user interaction (AV:L/AC:L/PR:L/UI:N) to trip the engine's flawed access checks, and successful exploitation yields high impact to confidentiality, integrity, and availability. News coverage reports public PoCs released under the 'ShieldBreak'/'ShieldCrash' names demonstrating SYSTEM-level access on Defender-protected Windows systems, including claims that the shipped patch can be bypassed and arbitrary files read as SYSTEM. Because MMPE ships as the scan engine inside Microsoft Defender, effectively every Defender-protected Windows 10/11 endpoint and server is potentially affected, though the source data specifies no affected engine version ranges. There is no confirmed in-the-wild exploitation (EPSS 0.6%, absent from CISA KEV), but given the public PoC claims, defenders should assume working exploit code exists.

Do: Ensure Microsoft Defender and its Malware Protection Engine are fully up to date by installing the latest antimalware platform and security intelligence (definition) updates via Windows Update, WSUS/SCCM/Intune, or Defender for Endpoint, and verify the installed engine version against Microsoft's advisory since PoC reports claim the initial patch can be bypassed. Given the local, low-privilege attack path, prioritize hosts where untrusted users or code run locally, such as shared servers, RDS/terminal hosts, and developer workstations. Monitor Microsoft and researcher channels for follow-up engine updates or revised guidance addressing the reported patch bypass.

7.8<1%
  • Microsoft Malware Protection Engine (used in Microsoft Defender)
masshundreds of millions of Windows endpoints (MMPE is bundled with Microsoft Defender, the default antimalware on modern Windows)
CVE-2026-69555
Incorrect Authorization in Microsoft Azure Arc Enables Network Privilege Escalation

Microsoft Azure Arc, the service used to manage on-premises and multi-cloud servers from Azure, contains an incorrect authorization flaw (CWE-863) in which permission checks fail to properly restrict what an unauthorized party may do. Per the CVSS vector, the flaw is exploitable over a network with no privileges or user interaction required, and exploitation changes the security scope, allowing an unauthorized attacker to elevate privileges with high impact on confidentiality and integrity. Any organization that has enrolled servers or other resources with Azure Arc is potentially exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only about a 0.4% probability of exploitation within 30 days.

Do: Apply Microsoft's fix as soon as it is released (expected with the September 2026 Patch Tuesday updates) and check Microsoft's advisory for affected Azure Arc components and agent versions. Until then, review and minimize permissions granted to Arc-enabled resources and restrict network reachability to Arc management endpoints. Monitor Microsoft's advisories for updated agent packages and redeploy them promptly to enrolled servers.

10.0<1%
  • Microsoft Azure Arc
mass≈1M+ Arc-enabled servers (Azure Arc is Microsoft's broadly deployed hybrid/multi-cloud management service)
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
Full article841 words · extracted from helpnetsecurity.com · click to collapse

UPDATE: September 2026 Patch Tuesday is now live

The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: 42 rated Critical, 355 rated Important, and 1 rated Moderate. But despite the high number, again only one vulnerability was confirmed actively exploited in the wild, and two more were publicly disclosed ahead of the released patches. AI has been good at discovering vulnerabilities, but so far, the associated overwhelming threat utilizing AI has been slow to surface.

Last month I provided a deep dive and step-by-step patch management approach to dealing with the Patch Apocalypse created by AI vulnerability discovery. To summarize, the focus was on a methodology to prioritize an overwhelming number of patches to provide the highest risk reduction during overall deployment. While I didn’t call it out specifically, the greatest challenge we face in testing and deploying patches is time.

There was an article posted by Igor Sahknov, Microsoft’s Corporate Vice President for Azure Networking which talks about the collapse of the patch window and how network controls can help mitigate the threat and reduce risk. Per Igor, ‘The objective is not to avoid patching. The objective is to create a meaningful layer of defense during the period when patching has not yet been completed.’ He proposes using the network as a control plane to buy more time while patch operations take place which dovetails nicely with a risk-driven remediation system to drive down exposure during critical times.

You never know which CVEs will appeal to threat actors, so it is important to methodically deploy all updates from not only Patch Tuesday but also updates released throughout the month. There were many CVEs called out for exploitation in August, and I would like to bring some to your attention. First off, SharePoint was in the news with respect to CVE-2026-55040 and CVE-2026-63520. These two vulnerabilities are being chained for authentication bypass and then remote code execution to actively exploit SharePoint servers. Fixes were released in July and August Patch Tuesdays respectively, but if you are behind in your patch cycle you are potentially vulnerable to threat actors using these chained exploits.

Second, CVE-2026-62911, an Exchange Server elevation of privilege vulnerability is ripe for exploitation. Also released on August Patch Tuesday, this vulnerability carries a CVSS of 8.0 and is one of the rare CVEs rated Critical that is not known exploited. Per Microsoft ‘The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.’ And finally, there were a handful of CVEs which Microsoft took care of for us in their cloud operations. CVE-2026-65816 and CVE-2026-69555 both in Azure Arc, and CVE-2026-65801 in Exchange Server Online were all rated Critical and carried a CVSS of 10.0. The CISA Known Exploited Vulnerabilities (KEV) list is useful if you want to stay on top of the most targeted vulnerabilities and these have all been added in the last two months.

Several products reach end of support next month, so plan accordingly. October Patch Tuesday will see the final updates for Windows 11 Version 24H2 Home and Professional editions, ESU support for Server 2012 and 2012 R2, and finally, ESU support for Exchange Server 2016/2019. Follow Microsoft’s recommendations on upgrades for these products, or implement mitigations which will protect systems until you can remove, replace or upgrade them.

Microsoft announced they are working on a fix for CVE-2026-69414 which is an elevation of privilege vulnerability which can grant system privileges. This vulnerability, known as ‘ShieldBreak’, exists in the malicious software engine of Microsoft Defender. It has been publicly disclosed and also has PoC exploit code available. This fix is one to look for next week.

September 2026 Patch Tuesday forecast

  • The large volume CVE trend will continue. With no sign of a slowdown in reported CVEs, I wouldn’t be surprised to see the entire portfolio updated again – from the oldest OS to the newest Office app.
  • Adobe just released a set of seven updates on August 25th. With Patch Tuesday so early this month we may get a break with only a few new releases for the Creative Cloud.
  • I wouldn’t be surprised if Apple released a set of OS updates on Patch Tuesday. They seem to be falling into a monthly rhythm with the last set of updates back in mid-August.
  • Yes, there will be a weekly update for the Chrome Browser next week. Be aware that this week’s update – 152.0.7977.82/.83 addressed 12 CVEs and Google reported CVE-2026-85046 is exploited in the wild.
  • We should get a break next week from Mozilla. They released major security updates for all their products on September 1st. Here’s the complete list.

We’re moving into the third month of the Patch Apocalypse based on the growth of patches and CVEs. Will the trend continue and this become business as usual? Time will tell.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/04/september-2026-patch-tuesday-forecast/