Technology intelligence for a changing world

About · Editorial standards

CyberProfi

ENGLISH EDITION

Microsoft September 2026 Patch Tuesday

Microsoft’s September 2026 Patch Tuesday fixes 1,169 vulnerabilities, including two zero-days under active attack. Learn what it means for enterprise security.

Select the most newsworthy verified cybersecurity, AI, or technology development from the past 24 hours - CyberProfi

On September 10, 2026, Microsoft released its latest security updates as part of the September 2026 Patch Tuesday cycle, addressing a staggering 1,169 unique vulnerabilities (CVEs) across its product portfolio. Most notably, two of these vulnerabilities are actively being exploited in the wild, heightening urgency for organizations to apply the patches immediately. As attackers continue to focus on critical bugs in widely deployed enterprise software, timely response to Microsoft’s Patch Tuesday remains a frontline defense for global businesses and public sector institutions alike.

In this report, CyberProfi unpacks the significance of this month’s Patch Tuesday release, the impact of actively exploited zero-days, and the evolving cyber risk landscape for organizations relying on Windows, Office, and Microsoft 365 ecosystems.

The scale and scope of September 2026 Patch Tuesday

This month’s Patch Tuesday represents one of the most extensive security update rollouts Microsoft has undertaken in years. According to security tracking site Senserva, the September 2026 release includes 60 update packages—most identified by unique Knowledge Base (KB) numbers—together fixing 1,169 distinct CVEs. The vulnerabilities range from privilege escalation flaws in the Windows kernel to remote code execution bugs in Office and Exchange, as well as browser exploits and Active Directory exposures.

This volume highlights not only the complexity of the Microsoft ecosystem but also sustained adversarial focus on exploiting it. Enterprises dependent on Microsoft software should prioritize asset inventory, vulnerability scanning, and patch deployment cycles during and after high-volume releases such as this one.

Two zero-days under active exploitation

Every Patch Tuesday includes fixes for vulnerabilities at various risk levels, but the presence of zero-day flaws—those already being exploited before a patch is made public—adds critical urgency. The September 2026 cycle details that two zero-days have been actively targeted, according to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog and Microsoft advisories.

Senserva and BleepingComputer confirm that attackers are using these exploits to compromise enterprise environments prior to patch deployment. Organizations running an unpatched environment face a heightened threat of ransomware, espionage, or data destruction attacks enabled by these vulnerabilities. Exact CVE numbers of the two exploited flaws can be referenced in Senserva’s comprehensive breakdown, updated daily with feed data from CISA KEV and Microsoft’s Security Response Center.

Prioritization for patching

With over a thousand vulnerabilities patched, organizations face the challenge of rapid triage. Security professionals are strongly advised to prioritize fixes for:

  • Actively exploited (zero-day) vulnerabilities listed by CISA KEV
  • Flaws with highest Exploit Prediction Scoring System (EPSS) and Common Vulnerability Scoring System (CVSS) ratings
  • Vulnerabilities affecting internet-facing systems and domain infrastructure (e.g., Active Directory, Exchange, VPNs)

Senserva and CISA’s advisories recommend sequencing patch rollouts to address the most urgent risks first, then moving to medium- and lower-risk vulnerabilities in the following days.

Confirmed impact: Excel update bug and VMware exploitation surge

While the Patch Tuesday cycle primarily aims to address vulnerabilities, it occasionally introduces collateral issues. This month, Microsoft has confirmed that the KB5002914 security update for Excel may silently break copy-paste functionality for some users. Enterprises deploying these patches should test spreadsheet workflows and monitor support channels for potential workarounds or subsequent hotfixes.

Separately, CISA warned on September 15 that ransomware gangs are now exploiting a critical VMware vCenter vulnerability patched in July, with some tying exploit chains to recently published Microsoft vulnerabilities. Although this VMware bug is not new to the September Patch Tuesday, its exploitation spike and integration with fresh Microsoft exploits make defense-in-depth vital for large environments with hybrid workloads.

Patch Tuesday in context: Why it remains critical for cybersecurity

Microsoft’s Patch Tuesday remains a pivotal moment every month for defenders and attackers alike. The sheer scale of the September 2026 release—paired with prompt weaponization of zero-days—demonstrates why enterprise IT and security teams cannot treat patch management as a routine chore. Attackers increasingly automate exploitation, targeting internet-facing systems within days or even hours of disclosed flaws. Delayed patching is one of the single greatest risk multipliers for ransomware, supply chain attacks, and business email compromise events.

SecurityWeek also highlights the pattern of exploits against kernel-level vulnerabilities and authentication bypass bugs, which can empower attackers to move laterally across an organization once a foothold is established.

Practical recommendations for enterprise defenders

  • Monitor authoritative feeds (Microsoft MSRC, CISA KEV, Senserva) for actively exploited CVEs associated with each Patch Tuesday release
  • Apply patches for zero-days as soon as possible (ideally within 24-48 hours of release)
  • Sequence updates for business-critical and internet-facing systems first
  • Test critical business applications (such as Excel) for post-patch usability issues and verify regular backups
  • Leverage modern vulnerability management tools to automate detection and prioritization

For process improvement guidance, see previous CyberProfi coverage on cybersecurity patch management and our zero-day response checklist.

Key takeaways from September 2026 Patch Tuesday

Frequently Asked Questions

What is Patch Tuesday and why is it important?
Patch Tuesday refers to Microsoft’s scheduled monthly security update release, typically on the second Tuesday of each month. It is a critical opportunity for organizations to close newly discovered security gaps in popular Microsoft products.
How many zero-days were included in the September 2026 Patch Tuesday?
According to Senserva and CISA KEV, two vulnerabilities patched in September 2026 were being actively exploited at the time of release.
Which Patch Tuesday updates should organizations prioritize?
Actively exploited (zero-day) patches listed by CISA, followed by high-severity CVEs (EPSS, CVSS) and updates for internet-exposed systems.
Are there known problems with any September 2026 patches?
Microsoft has confirmed that KB5002914 for Excel can silently break copy-paste; organizations should test for unexpected breakage post-patch.
How can enterprises stay current on immediately exploited vulnerabilities?
Refer to CISA’s Known Exploited Vulnerabilities catalog and automation-friendly feeds from Senserva, Microsoft MSRC, and local CERTs.

Sources