Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Every outlet that covered this Patch Tuesday agrees on one thing: this is the biggest single Patch Tuesday release Microsoft has published. Where they differ is in the exact count, and that difference is worth understanding before anyone panics over a headline number.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft’s Biggest Patch Tuesday Yet: 974 CVEs in One Release
Every outlet that covered this Patch Tuesday agrees on one thing: this is the biggest single Patch Tuesday release Microsoft has published. Where they differ is in the exact count, and that difference is worth understanding before anyone panics over a headline number.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
The scale of this Patch Tuesday alone would make it notable. CrowdStrike called the release more than double the CVE count Microsoft shipped in August 2026, and outlets from The Hacker News to BleepingComputer independently flagged it as a record. What makes it a story worth digging into, though, is what’s inside the pile: a Defender privilege-escalation chain now in its third round of bypasses, an unauthenticated Exchange RCE that needs zero user interaction, and a growing gap between how fast vendors patch and how fast attackers move to the next bug.
Microsoft’s Biggest Patch Tuesday Yet: 974 CVEs in One Release
Every outlet that covered this Patch Tuesday agrees on one thing: this is the biggest single Patch Tuesday release Microsoft has published. Where they differ is in the exact count, and that difference is worth understanding before anyone panics over a headline number.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft’s September 2026 Patch Tuesday landed on September 8 with the largest single batch of security fixes the company has ever shipped: 974 CVEs, according to Microsoft’s own Security Update Guide. Two of those flaws were already being exploited before the patches went out, one of them a bypass of a Windows Defender fix Microsoft issued just months earlier. A third bug lets an attacker take over an Exchange mail server by emailing it a booby-trapped Visio file, no clicks required.
The scale of this Patch Tuesday alone would make it notable. CrowdStrike called the release more than double the CVE count Microsoft shipped in August 2026, and outlets from The Hacker News to BleepingComputer independently flagged it as a record. What makes it a story worth digging into, though, is what’s inside the pile: a Defender privilege-escalation chain now in its third round of bypasses, an unauthenticated Exchange RCE that needs zero user interaction, and a growing gap between how fast vendors patch and how fast attackers move to the next bug.
Microsoft’s Biggest Patch Tuesday Yet: 974 CVEs in One Release
Every outlet that covered this Patch Tuesday agrees on one thing: this is the biggest single Patch Tuesday release Microsoft has published. Where they differ is in the exact count, and that difference is worth understanding before anyone panics over a headline number.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft’s September 2026 Patch Tuesday landed on September 8 with the largest single batch of security fixes the company has ever shipped: 974 CVEs, according to Microsoft’s own Security Update Guide. Two of those flaws were already being exploited before the patches went out, one of them a bypass of a Windows Defender fix Microsoft issued just months earlier. A third bug lets an attacker take over an Exchange mail server by emailing it a booby-trapped Visio file, no clicks required.
The scale of this Patch Tuesday alone would make it notable. CrowdStrike called the release more than double the CVE count Microsoft shipped in August 2026, and outlets from The Hacker News to BleepingComputer independently flagged it as a record. What makes it a story worth digging into, though, is what’s inside the pile: a Defender privilege-escalation chain now in its third round of bypasses, an unauthenticated Exchange RCE that needs zero user interaction, and a growing gap between how fast vendors patch and how fast attackers move to the next bug.
Microsoft’s Biggest Patch Tuesday Yet: 974 CVEs in One Release
Every outlet that covered this Patch Tuesday agrees on one thing: this is the biggest single Patch Tuesday release Microsoft has published. Where they differ is in the exact count, and that difference is worth understanding before anyone panics over a headline number.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.
Microsoft’s September 2026 Patch Tuesday landed on September 8 with the largest single batch of security fixes the company has ever shipped: 974 CVEs, according to Microsoft’s own Security Update Guide. Two of those flaws were already being exploited before the patches went out, one of them a bypass of a Windows Defender fix Microsoft issued just months earlier. A third bug lets an attacker take over an Exchange mail server by emailing it a booby-trapped Visio file, no clicks required.
The scale of this Patch Tuesday alone would make it notable. CrowdStrike called the release more than double the CVE count Microsoft shipped in August 2026, and outlets from The Hacker News to BleepingComputer independently flagged it as a record. What makes it a story worth digging into, though, is what’s inside the pile: a Defender privilege-escalation chain now in its third round of bypasses, an unauthenticated Exchange RCE that needs zero user interaction, and a growing gap between how fast vendors patch and how fast attackers move to the next bug.
Microsoft’s Biggest Patch Tuesday Yet: 974 CVEs in One Release
Every outlet that covered this Patch Tuesday agrees on one thing: this is the biggest single Patch Tuesday release Microsoft has published. Where they differ is in the exact count, and that difference is worth understanding before anyone panics over a headline number.
Microsoft’s own Security Update Guide lists 974 Microsoft CVEs for September 2026, including 723 vulnerabilities across Windows components alone, according to a breakdown published by tbreak.com. Zero Day Initiative’s Dustin Childs put his count at 972 vulnerabilities in his Patch Tuesday analysis, rising to 997 once the Chromium code ported into Microsoft Edge is factored in. BleepingComputer’s own tally landed at 966 flaws. Tenable’s research team counted 964. CrowdStrike published 972. None of these are wrong, they’re just counting slightly different things, whether that’s including non-Microsoft CVEs bundled into the release, Edge’s Chromium base, or entries still pending final severity classification.
Whatever number you land on, the release is more than double what Microsoft shipped in August 2026, when the company patched roughly 751 CVEs, per Senserva’s Patch Tuesday tracker. That jump is the real headline for patch management teams: whatever monthly cadence you built your maintenance windows around this year, September broke it.
Breaking Down the September 2026 Patch Tuesday by Severity
Severity counts vary slightly depending on scope, same as the topline CVE number. Senserva’s tracker, which includes the full set of entries published this cycle (1,169 by its count, covering Microsoft plus bundled third-party CVEs), put the severity split at 118 Critical, 910 Important, 104 Moderate, and 14 Low. Narrowing to the 973 Microsoft CVEs with full severity data attached, Splashtop’s analysis found 113 Critical and 860 Important. CrowdStrike’s count landed at 113 Critical vulnerabilities among 972 CVEs, plus 857 of lower severity. Ars Technica’s Patch Tuesday coverage cited 112 Critical bugs.
BleepingComputer’s category breakdown of the release shows where those bugs actually sit in Microsoft’s stack:
| Vulnerability category | Approximate count | Share of release |
|---|---|---|
| Elevation of privilege | 438 | ~45% |
| Remote code execution | 258 | ~27% |
| Information disclosure | 173 | ~18% |
| Denial of service | 56 | ~6% |
| Security feature bypass | 19 | ~2% |
| Spoofing | 16 | ~2% |
Source: BleepingComputer’s September 2026 Patch Tuesday breakdown. Figures are approximate counts as reported and may not sum exactly to Microsoft’s headline total due to overlapping classifications.
Elevation-of-privilege bugs make up nearly half the release, which lines up with the two zero-days that headline this month, both of which are privilege escalation flaws rather than remote code execution bugs. That’s a pattern worth watching: attackers increasingly don’t need an initial-access RCE if they can chain a cheap local exploit onto phishing or a compromised low-privilege account.
The Two Zero-Days Attackers Already Had Before the Patch Shipped
Microsoft confirmed two vulnerabilities in this release were being actively exploited in the wild ahead of patching, a fact The Hacker News reported directly: “Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
Help Net Security’s write-up on this month’s zero-days names the two flaws directly: CVE-2026-81963, a privilege escalation bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that grants SYSTEM-level access. Both are local privilege escalation bugs rather than remote code execution flaws, meaning an attacker needs some existing foothold on a machine, phishing, a compromised account, malware already dropped, before either bug becomes useful. That’s cold comfort for defenders, since local privilege escalation is exactly the step that turns a low-severity phishing click into a full domain compromise.
Neither zero-day was publicly disclosed before the patch
Unlike some Patch Tuesday cycles where a researcher drops proof-of-concept code weeks ahead of a fix, ap7i.com’s roundup of this release noted both zero-days were exploited in the wild with none publicly disclosed ahead of the patch, meaning Microsoft found out through in-the-wild attack telemetry rather than responsible disclosure. That generally means defenders had zero warning window, the first anyone outside Microsoft and its telemetry partners knew about either bug was the day the fix shipped.
ShieldCrash: A Third Bypass of the Same Defender Bug in Three Months
The most unusual bug in this release isn’t one of the two official zero-days, it’s a Windows Defender privilege escalation issue that BleepingComputer reported under the name ShieldCrash. According to that reporting, ShieldCrash bypasses the patch for CVE-2026-69414, known as ShieldBreak, a privilege escalation bug in the Microsoft Malware Protection Engine that powers Windows Defender. ShieldBreak itself was a bypass of an earlier Defender flaw called RoguePlanet, disclosed in June 2026 and patched in July.
That’s three rounds of the same underlying issue resurfacing: RoguePlanet, patched in July, bypassed by ShieldBreak, patched with this cycle’s fixes, and now apparently still not fully closed by ShieldCrash. BleepingComputer quoted the researcher who found the bypass directly: “Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak.” Help Net Security’s coverage confirms the same chain, describing ShieldCrash as a bypass that “ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender.”
For enterprise security teams, the practical takeaway is that a single fix for a Defender privilege-escalation chain isn’t proof the underlying issue is gone. If your organization treated the July or August ShieldBreak patch as case-closed, this release is a reminder to re-check whether SYSTEM-level access through Defender’s own scanning engine is still reachable on your build.
CVE-2026-55007: An Exchange RCE That Doesn’t Need a Click
The bug most likely to keep Exchange administrators up at night this month is CVE-2026-55007, a remote code execution vulnerability that Security Affairs flagged as arguably the most dangerous issue in the release. Per the reporting summarized by news.shield53.com, citing Security Affairs directly, an unauthenticated attacker can email a specially crafted Visio attachment to a target Exchange server. The server processes the attachment during content indexing, with no user interaction required, meaning an attacker can achieve code execution on a mail server simply by sending mail, provided the organization hasn’t hardened content indexing or applied the patch.
That description puts CVE-2026-55007 in the same category of concern as past Exchange RCEs that fueled mass-exploitation waves once proof-of-concept code circulated. On-premises Exchange servers remain a favorite target precisely because they sit exposed to the internet and hold enough access to move laterally through a whole organization. There is no indication yet that CVE-2026-55007 has been exploited in the wild, but unauthenticated, zero-click, mail-server RCE is exactly the profile that turns into a mass-exploitation event once details spread.
How the Different Trackers Counted the Same Release
One side effect of a record-setting Patch Tuesday is that every security vendor publishes its own count, and none of them match exactly. That’s not a data quality problem so much as a reflection of how differently each tracker scopes “this month’s release.”
| Source | Reported CVE count | Scope notes |
|---|---|---|
| Microsoft Security Update Guide | 974 | Official Microsoft CVE count for the release |
| Zero Day Initiative (Dustin Childs) | 972 (997 incl. Chromium/Edge) | New CVEs only; separate count with Edge’s Chromium base included |
| CrowdStrike | 972 | Patch Tuesday analysis blog |
| BleepingComputer | 966 | Patch Tuesday-only Microsoft flaws |
| Tenable | 964 | Statement shared with The Hacker News |
| Senserva | 1,169 | Broadest scope; includes bundled third-party CVEs |
For patch management purposes, the number that matters most is whatever your own vulnerability scanner reports against your specific software inventory, not the headline figure any outlet leads with. But the spread between 964 and 1,169 is a useful reminder that “how many CVEs did Microsoft patch” doesn’t have one universally agreed-upon answer, even among outlets working from the same Microsoft data.
Patch Tuesday’s Twenty-Three-Year Climb to 974 CVEs
Microsoft has shipped security updates on the second Tuesday of the month since October 2003, a cadence built originally to give IT departments a predictable window to test and deploy fixes instead of scrambling every time a new bug surfaced. In its early years, a typical Patch Tuesday covered a handful of bulletins addressing a dozen or so vulnerabilities. Growth in Windows’ installed base, the expansion of the Microsoft product portfolio into cloud services, Office, Exchange, SQL Server, and Edge’s Chromium engine, and a much larger population of security researchers and automated fuzzing tools all fed into steadily rising monthly counts over the following two decades.
September 2026’s roughly 974 CVEs represent that long climb reaching a new peak, more than double August 2026’s count in a single month-over-month jump. Whether that reflects a genuine spike in newly introduced bugs, a backlog of findings being cleared at once, or simply more thorough automated discovery tooling on Microsoft’s side isn’t something any of the outlets covering this release definitively answered. What is clear is that the trend line for CVE counts across the industry, not just Microsoft, has been rising for years, and this release is the most visible recent data point.
Competitive Comparison: How Microsoft’s Patch Load Stacks Up
Microsoft isn’t alone in shipping large, disruptive security fixes this cycle. Adobe pushed its own out-of-band emergency patch, APSB26-146, on September 7, 2026, addressing CVE-2026-75650 in Adobe Commerce, a CVSS 10.0 template-engine injection flaw that Adobe itself reported was being exploited in the wild, according to Zero Day Initiative’s monthly security update review. A maximum-severity, actively exploited bug landing outside the normal patch cycle is itself a serious event, it just happened to be overshadowed by Microsoft’s record-setting release the following Tuesday.
A vendor-tracking table published by Senserva, covering cumulative actively exploited CVEs by vendor as of September 2026, put Microsoft’s running total at 388 exploited CVEs tracked, 115 of them ransomware-linked, against Adobe’s 81 exploited CVEs with 11 ransomware-linked. That gap partly reflects Microsoft’s much larger and more exposed software footprint (Windows, Exchange, Office, and Edge all sit on both consumer and enterprise machines) rather than a simple statement about which vendor writes more secure code. For context on the browser side, shattered.io separately covered Chrome’s sixth actively exploited zero-day of 2026, a reminder that no major vendor is shipping a zero-vulnerability year in 2026, Microsoft’s release is just the largest single data point.
Why This Keeps Happening: The Defender Bypass Chain Problem
The RoguePlanet-to-ShieldBreak-to-ShieldCrash chain is a useful case study in a problem that shows up across the industry: patching the specific proof-of-concept a researcher demonstrates doesn’t always close the underlying design flaw that made the bug possible in the first place. Each fix addressed the literal reproduction steps disclosed at the time. Each time, a researcher went back and found a slightly different path to the same SYSTEM-level outcome through the same component.
This isn’t unique to Microsoft, or even to this particular Defender component. It’s a recurring pattern anywhere a security product itself runs with elevated privileges to do its job, antivirus engines, EDR agents, and patch management tools all carry this same structural risk, because the thing meant to protect the system needs enough access to be a target in its own right. September’s KEV additions elsewhere in the industry echoed the same theme: shattered.io’s earlier coverage of CISA’s KEV catalog additions and the BOD 26-04 remediation deadline, the SonicWall SMA1000 zero-day chain, and the fourth CVSS 10.0 fix N-able shipped for N-central in five weeks all involved administrative or security infrastructure being turned against the organizations it was meant to protect. See shattered.io’s full security coverage for ongoing tracking of actively exploited vulnerabilities.
Market and Operational Impact for IT Teams
A near-1,000-CVE release doesn’t just mean more line items on a spreadsheet, it changes how patch cycles actually get executed. Testing and staging that a team might normally complete in a standard maintenance window has to stretch further when the release touches 723 Windows components in a single cycle, per tbreak.com’s breakdown, plus Exchange, Office, and SQL Server fixes layered on top.
For managed service providers and internal IT teams running WSUS, Intune, or third-party patch management tooling, the immediate operational risk isn’t the total count, it’s triage. With 113 to 118 Critical-rated bugs depending on whose count you use, and two of them already under active exploitation, teams that patch in batches by product line rather than by severity risk leaving the two zero-days and the Exchange RCE sitting unpatched while lower-priority fixes roll out first. CrowdStrike’s framing of the release as “over double the number of CVEs released in August” is also an operational warning: teams that budgeted patch-testing time based on typical monthly volume were likely under-resourced for this cycle specifically.
Checking Exposure: A Quick Audit for Windows Admins
Before diving into full remediation, IT teams can get a fast read on which machines received the September 2026 cumulative update with a standard PowerShell query against installed hotfixes:
Get-HotFix | Where-Object {$_.InstalledOn -ge (Get-Date "2026-09-08")} | `
Select-Object HotFixID, Description, InstalledOn | Sort-Object InstalledOn
For fleets managed through WSUS or Microsoft Endpoint Configuration Manager, cross-referencing that output against your organization’s list of internet-facing Exchange servers and any endpoint still running an unpatched Defender build should take priority over general Windows workstation rollout, given that CVE-2026-55007 and the ShieldCrash bypass both carry a higher real-world exploitation profile than most of the remaining 900-plus lower-severity fixes in this release.
What Security Vendors Are Telling Their Customers
Beyond the raw numbers, several vendors used their Patch Tuesday write-ups to frame what the release means going forward rather than just cataloging CVEs. CrowdStrike’s analysis emphasized the month-over-month jump as a new Patch Tuesday record in its own right, not just a large release. Tenable’s research team, in a statement shared with The Hacker News, characterized the release as another turning point in Patch Tuesday history, noting that nearly 1,000 CVEs patched in a single month is a new record set within 2026 specifically, implying this isn’t a one-off spike but part of a pattern building across the year. Zero Day Initiative’s monthly review, meanwhile, focused less on the topline count and more on urging administrators to prioritize the Exchange and Adobe Commerce out-of-band fixes over routine Windows updates, given both carry confirmed in-the-wild exploitation.
Priority Patch List: What to Fix First
| CVE ID | Product | Issue type | Exploitation status |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Privilege escalation | Actively exploited |
| CVE-2026-85880 | Windows ALPC | Privilege escalation to SYSTEM | Actively exploited |
| CVE-2026-69414 / ShieldCrash bypass | Windows Defender (Malware Protection Engine) | Privilege escalation bypass | Bypass publicly demonstrated |
| CVE-2026-55007 | Exchange Server | Unauthenticated RCE via Visio attachment | No confirmed in-the-wild exploitation yet |
| CVE-2026-75650 | Adobe Commerce (out-of-band) | Template-engine injection, CVSS 10.0 | Actively exploited, per Adobe |
Treat the top four rows as this month’s must-patch list regardless of how the rest of the September 2026 Patch Tuesday rollout is sequenced across your environment.
Five Predictions for the Rest of 2026’s Patch Cycles
- Monthly CVE counts stay elevated through Q4 2026. A jump this large rarely reverts to the prior baseline immediately; expect October and November releases to run well above the roughly 751 CVEs Microsoft shipped in August.
- The Defender bypass chain gets a fourth round. Given RoguePlanet, ShieldBreak, and ShieldCrash all trace back to the same Malware Protection Engine privilege path, a follow-up bypass report within the next one to two patch cycles would fit the pattern already established.
- CVE-2026-55007 becomes a mass-exploitation target if patching lags. Unauthenticated, zero-click Exchange RCEs have historically drawn rapid reverse-engineering once a patch ships, and organizations slow to update internet-facing Exchange servers should expect scanning activity targeting this bug within weeks.
- Vendor CVE-count discrepancies keep widening. As Microsoft’s release scope grows to include more bundled Chromium, third-party, and cloud-service CVEs, expect the gap between outlets like Tenable, ZDI, and Microsoft’s own guide to persist or grow, making single-outlet headline numbers less useful for planning than direct scanner data.
- Out-of-band emergency patches become more common, not less. Adobe’s September 7 out-of-band fix for a CVSS 10.0 Commerce bug, landing right before Microsoft’s own record release, suggests vendors are increasingly willing to break their normal cadence when exploitation is confirmed rather than waiting for the next scheduled cycle.
Frequently Asked Questions
How many CVEs did Microsoft actually patch in September 2026?
Microsoft’s own Security Update Guide lists 974 CVEs, though independent trackers reported figures ranging from 964 (Tenable) to 1,169 (Senserva’s broader scope including bundled third-party entries), depending on what’s counted.
What are the two actively exploited zero-days in this release?
Per Help Net Security’s reporting, they are CVE-2026-81963, a privilege escalation bug in the Windows Update Stack, and CVE-2026-85880, a privilege escalation flaw in the Windows Advanced Local Procedure Call component that can grant SYSTEM-level access.
What is ShieldCrash and is it a new zero-day?
ShieldCrash, as reported by BleepingComputer, is a bypass of the patch for CVE-2026-69414 (ShieldBreak), a Windows Defender privilege escalation bug. It’s the third bypass in a chain that started with a flaw called RoguePlanet disclosed in June 2026.
Is the Exchange Server vulnerability CVE-2026-55007 being exploited right now?
There is no confirmed in-the-wild exploitation reported as of this Patch Tuesday. Security Affairs flagged it as the most dangerous issue in the release because it’s an unauthenticated, zero-click RCE, which historically makes for fast mass exploitation once technical details circulate.
How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 saw roughly 751 CVEs patched, according to Senserva’s tracker. September’s release, at 964 to 1,169 CVEs depending on scope, is more than double that count, per CrowdStrike’s analysis.
Should home users be worried about this Patch Tuesday?
The Exchange and out-of-band Adobe Commerce bugs primarily affect organizations running those server products. Home users are most exposed through the two Windows privilege-escalation zero-days and should install the September 2026 cumulative update through Windows Update as soon as it’s available rather than deferring it.
Where can I check if my organization’s software is on CISA’s exploited vulnerabilities list?
CISA maintains a public Known Exploited Vulnerabilities catalog that federal agencies are required to remediate against under binding operational directives; shattered.io’s coverage of the most recent KEV additions and BOD 26-04 deadline and the recent PaperCut zero-day KEV addition cover the current remediation timelines in detail.
Why do different security outlets report different CVE counts for the same Patch Tuesday?
Outlets scope their counts differently. Some count only new Microsoft CVEs, others include Chromium fixes ported into Edge, and others include bundled third-party CVEs Microsoft publishes alongside its own. All of the figures cited by Tenable, Zero Day Initiative, BleepingComputer, and Microsoft itself are accurate within their stated scope, they’re simply measuring slightly different things.




