All posts

September 2026 Patch Tuesday: Microsoft Fixes 974, Two Zero-Days

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 8, 2026

Microsoft ships a record Patch Tuesday with two exploited zero-days

This is the big one for the month. SecurityWeek reports Microsoft patched a record 974 vulnerabilities in the September 2026 release, including two zero-days that are already being exploited. BleepingComputer counts 966 flaws and the same two exploited zero-days, so the exact tally varies by how you count republished items, but the takeaway is the same: two are being used in attacks right now, and that moves them from patch-eventually to patch-now.

The cumulative updates are already out. Windows 11 gets KB5124008 and KB5122880, and Windows 10 receives the KB5122878 extended security update. If you run older builds, the ranked KBs this cycle include KB5046616 and KB5046698 for Windows Server 2022 (37 CVEs each) and KB5046615 and KB5046696 for Windows 10 1809 (31 and 36 CVEs), all rated Critical and all carrying KEV-listed content.

One caution before you push broadly: BleepingComputer notes the August updates triggered 0xc0000409 errors on Windows Server 2016. Test your Server 2016 ring before a wide rollout so you do not trade a patch gap for a crash loop.

Adobe patches a Magento zero-day already used to backdoor servers

Adobe fixed more than 170 vulnerabilities this cycle, and the one that matters most is CVE-2026-75650, a critical Commerce and Magento zero-day. BleepingComputer reports it was exploited to backdoor servers before the fix shipped. If you run Magento or Adobe Commerce, treat this as an active-exploitation event: patch, then hunt for web shells and unexpected admin accounts rather than assuming the update alone is enough.

Rod Trent's quick hits and SecurityWeek also flag a critical zero-day in N-able N-central, which is an RMM widely used by managed service providers. RMM compromise is a supply-chain problem, so apply that fix on priority if you or your provider run N-central.

KEV-listed movers still driving ransomware

No new CISA KEV additions came through since September 6, but the hot list is heavy with KEV-listed, ransomware-linked bugs you should confirm are closed. CVE-2026-15409, a SonicWall SMA1000 server-side request forgery flaw, sits at CVSS 10 with an EPSS of about 0.84, and it is both KEV-listed and ransomware-linked. CVE-2026-35273 in Oracle PeopleSoft PeopleTools (CVSS 9.8) and CVE-2026-41940 in WebPros cPanel and WHM (CVSS 9.8, EPSS 0.9853) are both KEV-listed and tied to ransomware.

Palo Alto PAN-OS authentication bypass CVE-2026-0257 (CVSS 9.1, EPSS 0.94) and the long-running ConnectWise ScreenConnect path traversal CVE-2024-1708 round out the ransomware-linked KEV entries. Sangoma Switchvox (CVE-2026-9586) and JFrog Artifactory (CVE-2026-82329) are KEV-listed as well. Every one of these is public-facing infrastructure or edge software, which is exactly where attackers look first.

Do this first

A short, ordered list grounded in today's facts:

  • Deploy the September Windows cumulative updates: KB5124008 and KB5122880 for Windows 11, KB5122878 for Windows 10, plus the ranked Server 2022 and Windows 10 1809 KBs. Test Server 2016 first given the 0xc0000409 reports.
  • Patch Adobe Commerce and Magento for CVE-2026-75650 now, then hunt for backdoors since it was exploited before the fix.
  • Confirm N-able N-central is updated to close the critical zero-day, especially if a managed service provider runs it in your environment.
  • Verify your edge and infrastructure appliances are patched against the KEV-listed, ransomware-linked CVEs: SonicWall CVE-2026-15409, Oracle PeopleSoft CVE-2026-35273, cPanel CVE-2026-41940, PAN-OS CVE-2026-0257, and ScreenConnect CVE-2024-1708.
  • Warn executives about the help-desk vishing campaign Help Net Security describes, where attackers trick leaders into handing over Microsoft 365 access. Reinforce that IT will never ask for credentials or MFA codes by phone.

Confirm your own state

With a record number of fixes shipping at once, the risk is losing track of which KEV-listed items are still open in your estate. The free Microsoft Patch Tracker from Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily so the SonicWall, Oracle, and PAN-OS entries above are easy to check against your inventory. Given the vishing angle on Microsoft 365, running a full audit of your Entra ID, Intune, and Defender configuration is a reasonable next step this week.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-08.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.