Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should be posted within a couple of hours after the release.
Adobe Patches for September 2026
For the first part of the August release, Adobe released 10 bulletins addressing 172 unique CVEs in Adobe ColdFusion, Acrobat Reader, Commerce (two bulletins), Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate, and Adobe Photoshop Mobile. A total of 22 of these were submitted through the ZDI program.
Here’s this month’s overview table:
Adobe Patches for September 2026
APSB26-146 (Adobe Commerce) is an out-of-band advisory posted September 7, 2026 addressing CVE-2026-75650, a CVSS 10.0 template-engine injection that Adobe reports is being exploited in the wild. All other bulletins were released on Patch Tuesday, September 8, 2026. No public proof-of-concept is noted for any bulletin.
Clearly, the priority here is the Commerce bug currently under active attack. Campaign Classic and ColdFusion also clock in with a deployment priority of 1. The Acrobat Reader should also be a priority. It contains 32 CVEs, including many code execution bugs, and PDFs are a favorite of attackers. The Experience Manager has plenty of CVEs being patched and also rates a deployment priority of 2.
Besides the one bug in Commerce, none of the other Adobe bugs receiving patches this month are listed as publicly known or under active attack at the time of release.
Microsoft Patches for September 2026
It’s a new record release from Microsoft, but, again, that seems to be the new normal. As always, counting this beast is tricky, but I see 972 new CVEs rolling out from Redmond this month. As with last month, only a single CVE is listed as being under active attack, so that’s something, I suppose. As for the products affected by this release, we have Windows and Windows components, Office and Office Components, Azure and Azure Components, .NET and Visual Studio, Active Directory, Copilot Studio, Dynamics, Edge (Chromium-based), DHCP Server and Client, DNS Server, Exchange Server, Teams for Android, OpenSSH, Remote Desktop Client and Server, Skype for Business, Biometric Service, SQL Server, Windows Hello, Xbox, and Defender. Along with the external and Chromium bugs being documented this month, this drives the total CVE count to a staggering 997. Of these new CVEs, 114 are rated Critical, with the rest being rated Important.
To provide a little historical context on how many CVEs have been patched by Microsoft this year, let’s take a look at some year-over-year totals:
On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate. On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits – yet.
As always, we’ll start with the bugs under active attack and move on from there.
- CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability This is the first bug being exploited in the wild, but we know little how broadly that exploitation is. The bug itself is a privilege escalation in the Update Stack, which is worrisome, but I doubt the automatic update process itself is compromised. More likely is that this bug is being combined with a code execution bug to spread malware or ransomware. Patch this one quickly.
- CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability This is the other bug currently being exploited, and it is also a privilege escalation bug. These types of bugs must be triggered by the user, but they can hide within documents, PDFs, and other attachments. As with the Update Stack EoP, we don’t know how widespread these exploits may be, so assume they are coming for you and patch quickly.
- CVE-2026-55007 - Microsoft Exchange Server Remote Code Execution Vulnerability There are several Exchange patches this month, but despite the CVSS rating, I find this one most important. A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. The code execution occurs when the server processes the mail – no need even for the Preview Pane. Microsoft states the exploit would be unreliable, but the attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.
- CVE-2026-80097 - Microsoft Authenticator Elevation of Privilege Vulnerability This is the worst type of privilege escalation as it uses a bug in the authentication system itself. An attacker would need to install a malicious app on an Android device, then convince a user to complete the authentication sequence. Once done, the attacker gets the auth tokens and can access resources as the affected user. If you have a large Android user base, best not to ignore this one.
- CVE-2026-69465 - Microsoft Office SharePoint Remote Code Execution Vulnerability I count 17 different SharePoint bugs in this release, with four leading to code execution. On its own, this bug doesn’t look like the worst, but SharePoint has been a popular target recently , and these are the types of bugs being used. An authenticated user can submit a page that bypasses a control-safety check, causing the affected server to load code from a filesystem under the attacker’s control. If you have SharePoint servers accessible from the internet, test and deploy these updates quickly.
- CVE-2026-65669 - Microsoft SQL Server Elevation of Privilege Vulnerability Speaking of AI-assisted code audits, there are over 60 patches for SQL Server in the September release. This bug even has an AI component, as the attacker would need to convince a user to submit specially crafted instructions to SQL Copilot in SQL Server Management Studio. So there’s the user interaction component, but if they succeed, the attacker could gain access to the database at the user’s permission level. Patching SQL Server will not be trivial this month, so take your time with your testing and really guard those SQL Servers that may be connected to the Internet.
- CVE-2026-69525 - Remote Desktop Services Remote Code Execution Vulnerability This CVSS 9.8 bug allows remote, unauthenticated attackers to run arbitrary code on affected systems via a Use-After-Free bug. Microsoft notes it needs to be an “in-network attacker”, but the CVSS still says Network. Since many enterprises rely on RDP, I would treat this one seriously and test and deploy the patch soonest.
So where are the wormable bugs, you may ask? Well, quite frankly, there are too many to single out. I count 20 different patches that could all be classified as wormable. In each of these cases, a remote, unauthenticated attacker could get arbitrary code execution on affected systems with no user interaction. While some might be more exploitable than others, having 20 of them in a single release is something else. These are the ones I found (presented in no particular order):
CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-69510 – Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-69524 – Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-69530 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability
CVE-2026-69579 – Windows Message Queuing Remote Code Execution Vulnerability
CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-69590 – Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2026-69595 – Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability ( SigRed ’s spiritual successor)
CVE-2026-69730 – Windows DNS Server Remote Code Execution Vulnerability ( SigRed ’s spiritual successor)
CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-69858 – Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-72936 – Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-72979 – Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability
CVE-2026-72981 – IP Helper Remote Code Execution Vulnerability
CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability
CVE-2026-72982 – Windows Netlogon Remote Code Execution Vulnerability
CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
CVE-2026-72983 – Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability
CVE-2026-72987 – Windows DNS Remote Code Execution Vulnerability
CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73009 – Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability
CVE-2026-73010 – Microsoft Failover Cluster Remote Code Execution Vulnerability
CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability
CVE-2026-78444 – Microsoft Failover Cluster Remote Code Execution Vulnerability
CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78449 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78450 – Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability
CVE-2026-83997 – Windows Message Queuing Remote Code Execution Vulnerability
Here’s the full list of CVEs released by Microsoft for September 2026:
* Indicates this CVE had been released by a third party and is now being included in Microsoft releases.
** Indicates this CVEs has already been resolved by Microsoft, and no further action is needed by the end user.
† Indicates further administrative actions are required to fully address the vulnerability.
As with last month, I’ll do my best to summarize everything else in this release but assume there are details I miss that are relevant to your environment.
There are roughly 90+ Critical rated bug remaining, and I’ll do my best to call out which ones you should care . First, ignore those CVSS 10 bugs. They’ve already been patched by Microsoft, so there’s no action for you. But don’t ignore the EoP in Spring Cloud Azure. It’s a complex scenario, but Microsoft still lists it as exploitation more likely. There’s a plethora of server-side bugs rated at a CVSS of 9.8, including Skype for Business (remember that one?).
From here on out, I’ll try to break things down by component rather than severity rating or impact. It may make it easier. We’ll see. ¯\_(ツ)_/¯
Windows DHCP Server: Windows DHCP Server chimes in with 36 bugs: 12 RCE, 18 DoS, five info leaks, and one EoP. Nothing exploited or disclosed, but 22 of the 36 require no authentication. It's the third-largest single-component pile of the month, and it's all one story: someone pointed a (likely AI-assisted) fuzzer at DHCP packet parsing. In addition to the two wormable bugs already mentioned, there are three more that didn’t carry the exact wormable verbiage but look like close cousins: CVE-2026-69845 (9.8, heap overflow), CVE-2026-69266 (8.8, integer overflow), and CVE-2026-69620 (8.1, stack overflow). If you're being generous, that's five wormable-shaped bugs in DHCP Server alone. The remaining seven RCEs need an authorized attacker. CWE spread is pure memory corruption: heap, stack, UAF, integer overflow. There are 18 DoS bugs, and 13 are unauthenticated at a CVSS score of 7.5. Malformed packet in, service crash out. Individually boring, but collectively, an unauthenticated attacker on the network has 13 different ways to take out DHCP, and when DHCP dies, clients stop getting leases and the helpdesk phone starts ringing. Finally, there are a couple of oddballs here: CVE-2026-69297 is an info leak that could expose passwords stored in a recoverable format, which is a configuration-secrets problem rather than a memory bug. The lone EoP is missing authentication on a critical function.
Windows Biometric Service: 64 bugs here, and 63 of them look almost identical. It's one bug class, stamped 56 times. CWE-122 heap-based buffer overflow accounts for 56 of them, with 5 integer overflows, 2 use-after-frees, and a NULL dereference rounding out the memory-corruption set. There are two worth noting: CVE-2026-69727. It has an outlier exploit vector: it reads “elevate privileges over a network” rather than locally, which is not what you want to see in a biometric service. The other is CVE-2026-73008. The lone info disclosure and it's CWE-359: exposure of private personal information. A biometric service leaking PII with high confidentiality impact is a worse look than the score implies. It also makes it a natural companion to the Hello cleartext tampering bug.
Windows Hello : Nine bugs here, with eight being Critical EoPs that result in an attacker gaining Virtual Trust Level 1 privileges. Code execution across the VTL0-to-VTL1 boundary into the secure world where VBS keeps credentials and biometric templates. That's the same trust line as Key Guard, and it's why they're rated Critical despite local vectors.
Exchange Server: Only nine bugs here, but there are some whoppers. Three different bugs rate CVSS 9.1 or higher. CVE-2026-69380 is an interesting exploit. A low-privileged user with a mailbox abuses request/token validation to impersonate any user and take over every mailbox: read, send, download attachments. Post-phish, this turns one compromised account into the whole org's mail. An unauthenticated mail-processing RCE plus a mailbox-takeover EoP in the same release is a chainable pair on paper. Initial access and lateral movement in one Cumulative Update. The other unauthenticated bug to mention is CVE-2026-69356, an specially crafted calendar invite; victim clicks the Join link, and script runs in their context. XSS wearing a spoofing label. Neat.
Microsoft Office Components: There are 110 Office-family bugs this month (excluding SharePoint's 17): 64 RCE, 45 info disclosure, and 1 spoofing. Most are of the open-and-own variety, but a few stick out, namely a CVSS 98 bug in Outlook’s CVSS 9.8 duo. CVE-2026-78509 is a Critical RCE. It has a network vector, no user interaction per the metrics, and explicitly lists the Preview Pane as an attack vector. That's the worst combination Office offers: code execution from a message you merely preview. There are a few other Preview Pane bugs in Office and Word.
SharePoint Server: This month’s release includes 16 SharePoint bugs: six RCE, two EoP, four spoofing, and four info disclosure. All Important, none exploited or publicly disclosed, nothing rated above “Exploitation Less Likely”, but given SharePoint's recent history of “Less Likely” becoming “in the KEV catalog,” the RCE set deserves respect. The RCE bugs do all require authentication, but the level is pretty basic, although the bug classes (deserialization, SQLi, SSRF, XSS, auth bypass) read like a web-app pentest report rather than memory corruption. The EoPs continue the theme of web-app sins in a server product: CVE-2026-69716 is a SQL injection letting a low-privileged user run database commands with elevated privileges; CVE-2026-83950 is an SSRF-based EoP; 69464 is an unnecessary-privileges flaw at CVSS 8.8.
Microsoft SQL Server: As previously mentioned, there are over 62 SQL Server bugs in this release: 61 in SQL Server proper plus the Azure Arc SQL Server Extension. Here’s the breakdown: 23 RCE, 14 EoP, 21 info disclosure, three DoS, and one SFB. Five are Critical. The overwhelming pattern is authenticated memory corruption. 55 of 62 require an authorized attacker, and the CWE spread is dominated by heap overflows (15 of the RCEs are CWE-122 alone) and out-of-bounds reads (13 of the info leaks). The template is CVE-2026-67378’s: log in, submit a crafted query, corrupt memory, run code on the server. That's why the 8.8s here are less scary than they score; an attacker already needs database credentials, but it's also textbook post-compromise lateral movement.
Windows DNS Server: There are 18 bugs here: 10 RCE, three DoS, two EoP, two info leaks, and one spoofing. Overwhelmingly use-after-frees in the server’s record handling: another single-component sweep, but this one lands on domain controllers. We’ve already mentioned a couple of wormable bugs, but the remaining RCE are not far off, but require either beating a race condition or non-default components. Unlike the DHCP pile, this one carries one of only two “More Likely” unauthenticated 9.8. Patch your domain controllers, then patch them again just to be sure.
Windows NTFS: We have 30 bugs in this component: 16 EoP, 10 RCE, three info leaks, and one link-following oddball. All Important except the two 9.8 Critical RCEs. Like Biometric and DHCP, it's one bug class on repeat: 28 of 30 are memory-safety flaws (heap overflows lead at 12, then out-of-bounds reads). The headliner is CVE-2026-69463; simple heap-overflow RCE at 9.8, unauthenticated, network vector. The FAQ only offers the vague “in-network attacker calling arbitrary endpoints” phrasing, which likely means the remote path is something like SMB-reachable file operations rather than a raw packet, but a 9.8 in the file system driver everyone runs is still a top-tier patch either way. CVE-2026-69461 (8.8, stack overflow, unauth network) rides along just below them. Everything else can be somewhat dismissed as local-only noise, but remember the mount-a-drive trio that where “requires physical access” describes every USB port in the building.
The USB Stack: There are 23 bugs impacting the USB stack, but I really only want to talk one. CVE-2026-68839 (USB Mass Storage Class Driver) with a CVSS of 9.8 and a network vector. The FAQ offers only the generic “in-network attacker calling arbitrary endpoints” boilerplate, which doesn't explain how a USB class driver is network-reachable. Either the metric is scored to worst case or there's a remote path (RDP device redirection would be the plausible one). I'd treat the score skeptically in print but patch like it's real.
Kerberos and the KDC: Six different bugs affect these components, but it’s the two Critical rated ones that raised my eyebrows. Six bugs across Kerberos and the KDC — two Critical RCEs, two EoPs, and two DoS. Nothing exploited or disclosed, but one carries the rating that matters. CVE-2026-69676 is an RCE in Kerberos with a CVSS of 8.8 and classified as Exploitation More Likely. An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction. “The server” here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That's a domain-compromise primitive, and Microsoft expects to see it exploited. CVE-2026-69712 is in KDC and reads almost identical to the : authenticated, low-level access, crafted request, code on the server, no interaction, but this one's a use-after-free in the KDC itself, the component that mints every ticket in the domain. Its practical impact is identical to 69676; only the exploitability rating separates them.
Exploitation More Likely: If you prioritize by Microsoft’s Exploit Index (XI), which I don’t recommend, there are a couple of bugs not mentioned yet: CVE-2026-72940 (Schannel RCE, CVSS 8.8, TLS stack), CVE-2026-72957 (Windows Deployment Services RCE, CVSS 7.8, PXE infrastructure), CVE-2026-71343 (Remote Access Connection Manager RCE, CVSS 7.8), and CVE-2026-70585 (a third NFS ONCRPC XDR RCE, CVSS 7.0). Again, I take all of these rating with a gigantic grain of salt, but you do you.
The Remnants: Another ~100 bugs land in six familiar components: Win32k (25), Standard XPS (18), WER (13), Device Association (13), (11), Print Spooler (11). Almost all are local EoPs to SYSTEM, but don't skim past them: 19 are rated More Likely, and XPS smuggles in an unauthenticated 9.8 RCE (CVE-2026-69824).
No new advisories are being released this month.
The Patch Tuesday will be on October 13. Assuming I survive the fun that is Pwn2Own Ireland, I’ll be back then to give you my full thoughts on the release – no matter how large it may be. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!
Stand at the front line of proactive security
TrendAI™ ZDI connects the experts who discover, remediate, and defend. Add your voice to the work that pushes attackers back.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
