Microsoft's record 974-CVE Patch Tuesday with two exploited zero-days
This month's Patch Tuesday is the biggest yet. Microsoft published a record 974 CVEs, including two zero-days that CISA warns are already being exploited (A9, A10, A12). Help Net Security also flags a SigRed successor in the Windows DNS space tied to CVE-2026-69414, so this is not a cycle to defer (A5).
The four cumulative updates for Windows 11 and Windows 10 carry enormous CVE counts: KB5122871 (678 CVEs), KB5122882 (640), KB5124008 (628), and KB5122880 (601), all rated Critical and all containing KEV-listed fixes. KB5124008 and KB5122880 rolled out for Windows 11 this week (A14). One caution before you push: BleepingComputer reports August updates triggering 0xc0000409 errors on Windows Server 2016, so validate on a pilot ring first (A13).
Separately, BleepingComputer describes a new Microsoft Defender zero-day dubbed ShieldCrash that grants SYSTEM access, another item to track as fixes land (A7).
Four new CISA KEV additions: Windows, N-able N-central, and Adobe Commerce
CISA added four Known Exploited Vulnerabilities to the catalog on September 8 (G3). Two are Microsoft Windows: CVE-2026-81963 (link following) and CVE-2026-85880 (heap-based buffer overflow). The other two are third-party and both serious.
CVE-2026-75650 is an Adobe Commerce and Magento template engine injection carrying a CVSS of 10. Adobe patched it as part of a release covering over 170 vulnerabilities, and it was disclosed as a Commerce zero-day (A8). CVE-2026-86218 is a static code injection flaw in N-able N-central at CVSS 9.8. If you run an MSP stack or a storefront, these are patch-now items, not patch-eventually.
Exploitation picture: ransomware-linked movers still in play
Several older KEV entries remain hot and carry ransomware links. SonicWall SMA1000 CVE-2026-15409 (CVSS 10, EPSS 0.84) sits at the top and is both KEV-listed and ransomware-associated. Others with ransomware ties include Oracle PeopleSoft PeopleTools CVE-2026-35273 (EPSS 0.95), WebPros cPanel and WHM CVE-2026-41940 (EPSS 0.99), Palo Alto Networks PAN-OS CVE-2026-0257 (EPSS 0.94), and ConnectWise ScreenConnect CVE-2024-1708. If any of these live in your perimeter, treat them as active fire.
On the browser side, Google shipped Chrome 153 patching its seventh zero-day of 2026, tracked as CVE-2026-87491 and confirmed exploited in attacks (A1, A4, A6). Push the Chrome update through your managed fleet alongside the Windows work.
What to do first
The volume this month is large, so sequence by exploitation, not by count.
- Apply the September Windows cumulative updates after pilot validation, watching for the Server 2016 0xc0000409 error (A13, A14).
- Patch the four new KEV entries now: CVE-2026-81963 and CVE-2026-85880 on Windows, CVE-2026-75650 on Adobe Commerce and Magento, and CVE-2026-86218 on N-able N-central (G3, A8).
- Force Chrome to 153 to close the exploited CVE-2026-87491 zero-day (A4, A6).
- Re-check exposure to the ransomware-linked movers: SonicWall, Oracle PeopleSoft, cPanel, PAN-OS, and ScreenConnect.
- Use the free Microsoft Patch Tracker in Senserva to rank your open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker in Siemserva to follow the daily KEV adds.
Sources
- Help Net Security: September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor (2026-09-09)
- BleepingComputer: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access (2026-09-09)
- SecurityWeek: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (2026-09-08)
- SecurityWeek: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days (2026-09-08)
- The Record: Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited (2026-09-08)
- Dark Reading: Patch Tuesday Sets Another Record With 974 CVEs (2026-09-08)
- BleepingComputer: August updates trigger 0xc0000409 errors on Windows Server 2016 (2026-09-08)
- BleepingComputer: Windows 11 cumulative updates KB5124008 & KB5122880 released (2026-09-08)
- SecurityWeek: Chrome 153 Patches Seventh Zero-Day of 2026 (2026-09-09)
- Help Net Security: Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) (2026-09-09)
- BleepingComputer: Google warns of new Chrome zero-day bug exploited in attacks (2026-09-09)
- CISA Cybersecurity Advisories: CISA Adds Four Known Exploited Vulnerabilities to Catalog (2026-09-08)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-10.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.