Microsoft just broke its own record. September's Patch Tuesday addressed 974 vulnerabilities, smashing past July's previous high of 570 and making this the largest single Patch Tuesday release in the programme's history. The headline numbers: 104+ rated Critical, 723 affecting Windows alone, and two zero-days already under active exploitation in the wild before today's fix landed. Both exploited flaws are elevation of privilege bugs, one in the Windows Update Stack, one in Windows ALPC, and both are now on CISA's Known Exploited Vulnerabilities list. With 2026's year-to-date total already past 2,600 CVEs, more than double the previous full-year record set in 2020, volume alone isn't a strategy. Patch by exposure, not by count. Prioritise the two actively exploited zero-days first, then work through Critical severity issues on anything internet-facing or tied to Windows Update infrastructure. If you need help triaging this release or want a clearer view of what's actually exploitable in your environment, get in touch. #PatchTuesday #CyberSecurity #VulnerabilityManagement
Microsoft Patch Tuesday Breaks Record with 974 Vulnerabilities
More Relevant Posts
-
Microsoft’s September Patch Tuesday addressed hundreds of vulnerabilities, and security researcher Nightmare Eclipse says one Defender flaw can still be reached through a new bypass. The researcher released ShieldCrash, a proof-of-concept that allegedly bypasses Microsoft’s fix for ShieldBreak (CVE-2026-69414). According to the disclosure, an attacker who already has local code execution could trick Microsoft Defender into reading protected files with SYSTEM privileges, potentially exposing data that a low-privileged process normally couldn’t access. 🔎 Nightmare Eclipse claims ShieldCrash was successfully tested against Windows 11 25H2 and Windows Server 2025, including systems running the September 2026 patches. The disclosure adds another chapter to an ongoing series of Windows Defender findings from the researcher, following RoguePlanet and ShieldBreak. ⚙️ For defenders, the case highlights an important part of vulnerability management: deploying a patch is followed by validation, monitoring for bypass techniques, and tracking new research around the same attack surface. Source: Cybernews — “Vengeful researcher bypasses Microsoft’s Patch Tuesday fix with new Windows zero-day” https://lnkd.in/eWrrE5bE #CyberNews #Cybersecurity #Microsoft #Windows11 #ZeroDay #MicrosoftDefender #VulnerabilityResearch #PatchTuesday #CyberDefense
To view or add a comment, sign in
-
-
Microsoft's September Patch Tuesday set a new record: 974 vulnerabilities patched in a single release — the biggest batch in the history of their update program. The detail behind the number: • 723 of the flaws sit in Windows itself • 114 are rated critical • Two zero-days were already being exploited in the wild — including CVE-2026-81963, a link-following flaw in the Windows Update Stack that lets an attacker swap a system component for an imposter • CVE-2026-69829 is a critical remote-code-execution flaw in the Windows Shell (CVSS 9.8) The uncomfortable takeaway for any business running Windows: the attacker's timeline no longer matches the patch cycle. A critical vulnerability disclosed on Tuesday can be an active exploit by the weekend. Patch fast, prioritize the exploited CVEs first, and make sure your update pipeline can actually keep up. The patch window is now one of the most valuable assets in your stack. #cybersecurity #patchmanagement #infosec #Windows
To view or add a comment, sign in
-
974 patches. 2 exploited zero-days. 20 wormable flaws. Microsoft's September update is the largest on record. For healthcare IT, the challenge isn't the volume it's applying critical fixes without disrupting clinical operations. Wormable vulnerabilities don't wait for maintenance windows. Three questions worth asking this week: Which of these CVEs are actually exposed in our environment? Is our SLA for actively exploited flaws measured in hours or weeks? Who decides when security urgency and clinical uptime conflict? Patch counts will keep rising. Prioritisation has to keep pace. #Cybersecurity #HealthcareIT #CISO #PatchManagement
To view or add a comment, sign in
-
There’s a considerable amount of work behind a patch release covering 966 vulnerabilities, especially for teams already managing a backlog. Our intelligence team explains where to start in this week’s summary, with the vulnerabilities already being exploited taking immediate priority. Worth reading if you’re responsible for managing cyber risk.
𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗽𝗮𝘁𝗰𝗵𝗲𝘀 𝟵𝟲𝟲 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀. September’s Patch Tuesday leaves security teams with a substantial workload. This week’s summary explains where to focus first: • Two Windows zero-days already being exploited. • Critical flaws in Windows SSTP and DHCP Server. • Active exploitation of Chrome and Citrix NetScaler. 𝗥𝗲𝗮𝗱 𝘁𝗵𝗶𝘀 𝘄𝗲𝗲𝗸’𝘀 𝘀𝘂𝗺𝗺𝗮𝗿𝘆: https://lnkd.in/eJVzZSdB 𝗨𝗻𝗱𝗲𝗿𝘀𝘁𝗮𝗻𝗱 𝗼𝘂𝗿 𝗶𝗻𝗱𝗲𝗽𝗲𝗻𝗱𝗲𝗻𝘁𝗹𝘆 𝘃𝗲𝗿𝗶𝗳𝗶𝗲𝗱 𝘀𝗰𝗼𝗿𝗶𝗻𝗴 𝗺𝗼𝗱𝗲𝗹: https://lnkd.in/eAPqtiVV 𝗙𝗼𝗹𝗹𝗼𝘄 𝘂𝘀 𝘁𝗼 𝘀𝘁𝗮𝘆 𝗮𝗵𝗲𝗮𝗱 𝗼𝗳 𝗲𝗺𝗲𝗿𝗴𝗶𝗻𝗴 𝘁𝗵𝗿𝗲𝗮𝘁𝘀. #CyberThreatIntelligence #VulnerabilityManagement #CyberRisk
To view or add a comment, sign in
-
-
𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗽𝗮𝘁𝗰𝗵𝗲𝘀 𝟵𝟲𝟲 𝘃𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀. September’s Patch Tuesday leaves security teams with a substantial workload. This week’s summary explains where to focus first: • Two Windows zero-days already being exploited. • Critical flaws in Windows SSTP and DHCP Server. • Active exploitation of Chrome and Citrix NetScaler. 𝗥𝗲𝗮𝗱 𝘁𝗵𝗶𝘀 𝘄𝗲𝗲𝗸’𝘀 𝘀𝘂𝗺𝗺𝗮𝗿𝘆: https://lnkd.in/eJVzZSdB 𝗨𝗻𝗱𝗲𝗿𝘀𝘁𝗮𝗻𝗱 𝗼𝘂𝗿 𝗶𝗻𝗱𝗲𝗽𝗲𝗻𝗱𝗲𝗻𝘁𝗹𝘆 𝘃𝗲𝗿𝗶𝗳𝗶𝗲𝗱 𝘀𝗰𝗼𝗿𝗶𝗻𝗴 𝗺𝗼𝗱𝗲𝗹: https://lnkd.in/eAPqtiVV 𝗙𝗼𝗹𝗹𝗼𝘄 𝘂𝘀 𝘁𝗼 𝘀𝘁𝗮𝘆 𝗮𝗵𝗲𝗮𝗱 𝗼𝗳 𝗲𝗺𝗲𝗿𝗴𝗶𝗻𝗴 𝘁𝗵𝗿𝗲𝗮𝘁𝘀. #CyberThreatIntelligence #VulnerabilityManagement #CyberRisk
To view or add a comment, sign in
-
-
🚨 It never rains but it pours. Microsoft has delivered a record-breaking Patch Tuesday, addressing 974 unique vulnerabilities in its September 2026 security updates. It is not easy to understand what is relevant with so many revealed. To help with that, we have written a 'short' article. Inside you will: ⚠️ Find out which two Windows vulnerabilities are already being actively exploited. 🪱 Learn why around 20 of the vulnerabilities are considered potentially wormable, including flaws affecting critical Windows infrastructure. 🎯 See which Exchange and Remote Desktop vulnerabilities deserve particular attention. 💻 Get a PowerShell command to quickly check whether your Windows 11 system has received the September update. 🛡️ See how BaseFortify can help make sense of releases like this by matching new CVEs against the components you actually use. We have also linked the highlighted CVEs directly to our BaseFortify reports, where you can dig into the details or ask our AI assistant questions about the vulnerability. So, if you don't fancy working your way through 974 CVEs yourself, have a read 👇 https://lnkd.in/eeuUMgJr #CyberSecurity #PatchTuesday #Microsoft #CVE #BaseFortify
To view or add a comment, sign in
-
-
Microsoft released 995 security patches yesterday. Not a typo. Five short of a thousand, in a single month. The biggest Patch Tuesday there has ever been. Inside that pile are 119 critical vulnerabilities and two zero days. A zero day is a hole attackers were already using before the fix existed. Here is the bit that matters if you run a business rather than an IT department. Nobody is sitting down tonight and working through 995 patches one by one. The real job is knowing which handful need doing today and which can wait for the normal monthly cycle. That is what a patching process is for. Not a Windows Update pop up that someone has been clicking "remind me later" on for three weeks. We took over a client earlier this year whose laptops had not been patched since the previous autumn. Not because anyone was lazy. Because nobody owned it. Three questions worth asking whoever looks after your IT this week: How many of the 995 have already gone out to our machines? Which of our devices are still missing the two zero day fixes? Who is responsible for checking, and how would I know if it slipped? If the answer to the last one is a shrug, that is the thing to fix first. #CyberSecurity #PatchTuesday #ITSupport #Halcyon
To view or add a comment, sign in
-
-
Microsoft's biggest Patch Tuesday ever, and why it isn't really about the number 📊 September's security update from Microsoft was a record: 974 vulnerabilities fixed, 114 of them rated critical, and two flaws that attackers were already exploiting before the fix landed. That number sounds alarming, but it's actually good news. Those are problems being closed off. The catch is that a fix only protects you once it reaches every device you own. And that's where it quietly falls down for a lot of businesses: ✅ Updates install on the main laptops, but not the spare one in the corner ✅ Servers get patched, but the firmware on your router and firewall doesn't ✅ Windows updates run automatically, but third-party apps like browsers and Adobe don't ✅ Everyone assumes "IT handles it", but nobody can actually see the patch status None of that is dramatic. It's just invisible. And invisible gaps are the ones that stay open. That last one is the whole point of proactive monitoring: the fix is identified, applied and confirmed before it becomes a problem, rather than after. Not sure whether your devices are genuinely up to date? Our team can check your patch status, close the gaps and keep it that way. 🔎 Get your free IT audit: mercury-systems.co.uk #ITSupport #CyberSecurity #ProactiveIT #HampshireBusiness
To view or add a comment, sign in
-
-
CVE-2026-81963 is actively exploited and listed on CISA's Known Exploited Vulnerabilities catalog as of September 8, 2026. The flaw is a link-following vulnerability in the Windows Update Stack. An attacker who already holds low-privileged authenticated access can exploit improper link resolution before file access to elevate privileges locally — gaining full control over the affected system. Affected platforms: Windows 11 (23H2 through 26H1) and Windows Server 2025. CVSS 7.8 with confirmed in-the-wild exploitation means this is not a candidate for your next patch cycle. Shared environments, enterprise workstations, and any system where low-privileged accounts exist are directly in scope. Apply Microsoft's September 2026 security update immediately and validate coverage across your Windows 11 and Server 2025 fleet. CISA's KEV listing effectively mandates action for federal agencies — but the exploitation signal is relevant for every organisation running affected Windows versions. https://lnkd.in/eKz8aMcA #cybersecurity #vulnerabilities #ciso
To view or add a comment, sign in
-
-
Researchers are calling it the "spiritual successor to SigRed" — and that comparison should get your attention. CVE-2026-69730 is a use-after-free vulnerability in Windows DNS Server, carrying a CVSS score of 9.8. It's unauthenticated and zero-click: an attacker sends a single specially crafted packet, and code executes on the target — no credentials, no user interaction. Here's what makes it particularly dangerous: in most Active Directory environments, DNS runs directly on domain controllers. A successful exploit doesn't just compromise a name server — it can hand an attacker code execution at the heart of your identity infrastructure. Microsoft rates this "Exploitation More Likely" and it's part of a record-breaking September 2026 Patch Tuesday — 973 vulnerabilities in total. Affected: Windows Server 2012 through 2025, Windows 10 (versions 1607, 1809). Windows 11 is not affected. Prioritize your domain-integrated DNS servers. Full details: https://lnkd.in/dyuHe-cn #Microsoft #PatchTuesday #CVE #CyberSecurity #VulnTracker
To view or add a comment, sign in
-