All posts

September Patch Tuesday breaks 974-CVE record, two zero-days

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 9, 2026

Microsoft ships a record 974 CVEs with two exploited zero-days

Microsoft's September 2026 Patch Tuesday is the largest on record, fixing 974 vulnerabilities and including two zero-days that CISA says are already being exploited. Reporting from SecurityWeek, The Record, Dark Reading, Help Net Security, and Cisco Talos all line up on the numbers and the warning: two flaws are being used in the wild right now, so this is a patch-now cycle rather than a patch-when-convenient one.

Help Net Security flags CVE-2026-69414 among the notable entries and describes one issue as a SigRed successor, meaning a Windows DNS bug worth prioritizing on domain controllers and DNS servers. Separately, BleepingComputer reports a Microsoft Defender zero-day nicknamed ShieldCrash that grants SYSTEM access, so confirm your Defender platform and this month's cumulative updates are current across endpoints.

The relevant cumulative updates are already out. BleepingComputer notes Windows 11 updates KB5124008 and KB5122880 have shipped. If you run Windows Server 2016, note the earlier report that August updates triggered 0xc0000409 errors, so validate before broad deployment.

CISA adds four vulnerabilities to the KEV catalog

CISA added four Known Exploited Vulnerabilities on September 8. Two are Microsoft Windows flaws: CVE-2026-81963, a link following vulnerability, and CVE-2026-85880, a heap-based buffer overflow. Both are now KEV listed, which raises them above the general Patch Tuesday queue.

The other two hit widely deployed platforms. CVE-2026-75650 is a critical (CVSS 10) template engine injection in Adobe Commerce and Magento; SecurityWeek reports Adobe patched more than 170 vulnerabilities this cycle, including this Commerce zero-day. CVE-2026-86218 is a static code injection flaw in N-able N-central at CVSS 9.8, a managed platform that is high value to attackers if left exposed.

Hot movers still worth your attention

Several KEV-listed, ransomware-linked bugs continue to run hot on exploitation signals. Worth checking if any touch your perimeter or vendors:

  • CVE-2026-15409, SonicWall SMA1000 SSRF, CVSS 10, KEV listed and ransomware linked
  • CVE-2026-35273, Oracle PeopleSoft PeopleTools missing authentication, CVSS 9.8, KEV and ransomware linked, EPSS 0.95
  • CVE-2026-41940, WebPros cPanel and WHM missing authentication, CVSS 9.8, KEV and ransomware linked, EPSS 0.99
  • CVE-2026-0257, Palo Alto Networks PAN-OS authentication bypass, CVSS 9.1, KEV and ransomware linked
  • CVE-2024-1708, ConnectWise ScreenConnect path traversal, KEV and ransomware linked

Google patches its seventh Chrome zero-day of 2026

Away from Microsoft, Google shipped Chrome 153 to fix its seventh actively exploited zero-day of the year, tracked as CVE-2026-87491 per Help Net Security, with BleepingComputer and SecurityWeek corroborating. Chrome updates in the background, but confirm your fleet has relaunched to apply the fix rather than waiting on users.

SecurityWeek also describes a new phishing technique that builds malicious pages inside the victim's own browser, and CISA's ICS Patch Tuesday roundup covers critical fixes from Schneider Electric and Siemens plus a CareCam Pro IP camera advisory. If you run OT or exposed cameras, add those to the same review.

Do this first

Prioritize by exploitation status, not raw CVSS. Focus on the KEV additions and the exploited zero-days before working through the rest of the record 974.

  • Deploy this month's Windows cumulative updates and close CVE-2026-81963 and CVE-2026-85880, both now KEV listed
  • Confirm Defender platform updates are current given the ShieldCrash SYSTEM-access report, and prioritize the DNS fix on domain controllers
  • Patch Adobe Commerce and Magento for CVE-2026-75650 and N-able N-central for CVE-2026-86218
  • Verify Chrome has relaunched to apply CVE-2026-87491
  • Rank your open Microsoft patches by KEV, EPSS, and ransomware linkage with the free Microsoft Patch Tracker in Senserva, and track non-Microsoft KEV adds like the Adobe and N-able entries with its exploited-CVE tracker

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-09.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.