Microsoft ships a record 974 CVEs with two exploited zero-days
Microsoft's September 2026 Patch Tuesday is the largest on record, fixing 974 vulnerabilities and including two zero-days that CISA says are already being exploited. Reporting from SecurityWeek, The Record, Dark Reading, Help Net Security, and Cisco Talos all line up on the numbers and the warning: two flaws are being used in the wild right now, so this is a patch-now cycle rather than a patch-when-convenient one.
Help Net Security flags CVE-2026-69414 among the notable entries and describes one issue as a SigRed successor, meaning a Windows DNS bug worth prioritizing on domain controllers and DNS servers. Separately, BleepingComputer reports a Microsoft Defender zero-day nicknamed ShieldCrash that grants SYSTEM access, so confirm your Defender platform and this month's cumulative updates are current across endpoints.
The relevant cumulative updates are already out. BleepingComputer notes Windows 11 updates KB5124008 and KB5122880 have shipped. If you run Windows Server 2016, note the earlier report that August updates triggered 0xc0000409 errors, so validate before broad deployment.
CISA adds four vulnerabilities to the KEV catalog
CISA added four Known Exploited Vulnerabilities on September 8. Two are Microsoft Windows flaws: CVE-2026-81963, a link following vulnerability, and CVE-2026-85880, a heap-based buffer overflow. Both are now KEV listed, which raises them above the general Patch Tuesday queue.
The other two hit widely deployed platforms. CVE-2026-75650 is a critical (CVSS 10) template engine injection in Adobe Commerce and Magento; SecurityWeek reports Adobe patched more than 170 vulnerabilities this cycle, including this Commerce zero-day. CVE-2026-86218 is a static code injection flaw in N-able N-central at CVSS 9.8, a managed platform that is high value to attackers if left exposed.
Hot movers still worth your attention
Several KEV-listed, ransomware-linked bugs continue to run hot on exploitation signals. Worth checking if any touch your perimeter or vendors:
- CVE-2026-15409, SonicWall SMA1000 SSRF, CVSS 10, KEV listed and ransomware linked
- CVE-2026-35273, Oracle PeopleSoft PeopleTools missing authentication, CVSS 9.8, KEV and ransomware linked, EPSS 0.95
- CVE-2026-41940, WebPros cPanel and WHM missing authentication, CVSS 9.8, KEV and ransomware linked, EPSS 0.99
- CVE-2026-0257, Palo Alto Networks PAN-OS authentication bypass, CVSS 9.1, KEV and ransomware linked
- CVE-2024-1708, ConnectWise ScreenConnect path traversal, KEV and ransomware linked
Google patches its seventh Chrome zero-day of 2026
Away from Microsoft, Google shipped Chrome 153 to fix its seventh actively exploited zero-day of the year, tracked as CVE-2026-87491 per Help Net Security, with BleepingComputer and SecurityWeek corroborating. Chrome updates in the background, but confirm your fleet has relaunched to apply the fix rather than waiting on users.
SecurityWeek also describes a new phishing technique that builds malicious pages inside the victim's own browser, and CISA's ICS Patch Tuesday roundup covers critical fixes from Schneider Electric and Siemens plus a CareCam Pro IP camera advisory. If you run OT or exposed cameras, add those to the same review.
Do this first
Prioritize by exploitation status, not raw CVSS. Focus on the KEV additions and the exploited zero-days before working through the rest of the record 974.
- Deploy this month's Windows cumulative updates and close CVE-2026-81963 and CVE-2026-85880, both now KEV listed
- Confirm Defender platform updates are current given the ShieldCrash SYSTEM-access report, and prioritize the DNS fix on domain controllers
- Patch Adobe Commerce and Magento for CVE-2026-75650 and N-able N-central for CVE-2026-86218
- Verify Chrome has relaunched to apply CVE-2026-87491
- Rank your open Microsoft patches by KEV, EPSS, and ransomware linkage with the free Microsoft Patch Tracker in Senserva, and track non-Microsoft KEV adds like the Adobe and N-able entries with its exploited-CVE tracker
Sources
- Help Net Security: September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor (2026-09-09)
- BleepingComputer: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access (2026-09-09)
- SecurityWeek: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (2026-09-08)
- SecurityWeek: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days (2026-09-08)
- The Record: Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited (2026-09-08)
- Help Net Security: Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) (2026-09-09)
- BleepingComputer: Google warns of new Chrome zero-day bug exploited in attacks (2026-09-09)
- SecurityWeek: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (2026-09-09)
- CISA Cybersecurity Advisories: CISA Adds Four Known Exploited Vulnerabilities to Catalog (2026-09-08)
- BleepingComputer: Windows 11 cumulative updates KB5124008 & KB5122880 released (2026-09-08)
- BleepingComputer: August updates trigger 0xc0000409 errors on Windows Server 2016 (2026-09-08)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-09.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.