All posts

September 2026 Patch Tuesday: 974 CVEs and Two Zero-Days

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 10, 2026

Microsoft's record 974-CVE Patch Tuesday with two exploited zero-days

This month's Patch Tuesday is the biggest yet. Microsoft published a record 974 CVEs, including two zero-days that CISA warns are already being exploited (A9, A10, A12). Help Net Security also flags a SigRed successor in the Windows DNS space tied to CVE-2026-69414, so this is not a cycle to defer (A5).

The four cumulative updates for Windows 11 and Windows 10 carry enormous CVE counts: KB5122871 (678 CVEs), KB5122882 (640), KB5124008 (628), and KB5122880 (601), all rated Critical and all containing KEV-listed fixes. KB5124008 and KB5122880 rolled out for Windows 11 this week (A14). One caution before you push: BleepingComputer reports August updates triggering 0xc0000409 errors on Windows Server 2016, so validate on a pilot ring first (A13).

Separately, BleepingComputer describes a new Microsoft Defender zero-day dubbed ShieldCrash that grants SYSTEM access, another item to track as fixes land (A7).

Four new CISA KEV additions: Windows, N-able N-central, and Adobe Commerce

CISA added four Known Exploited Vulnerabilities to the catalog on September 8 (G3). Two are Microsoft Windows: CVE-2026-81963 (link following) and CVE-2026-85880 (heap-based buffer overflow). The other two are third-party and both serious.

CVE-2026-75650 is an Adobe Commerce and Magento template engine injection carrying a CVSS of 10. Adobe patched it as part of a release covering over 170 vulnerabilities, and it was disclosed as a Commerce zero-day (A8). CVE-2026-86218 is a static code injection flaw in N-able N-central at CVSS 9.8. If you run an MSP stack or a storefront, these are patch-now items, not patch-eventually.

Exploitation picture: ransomware-linked movers still in play

Several older KEV entries remain hot and carry ransomware links. SonicWall SMA1000 CVE-2026-15409 (CVSS 10, EPSS 0.84) sits at the top and is both KEV-listed and ransomware-associated. Others with ransomware ties include Oracle PeopleSoft PeopleTools CVE-2026-35273 (EPSS 0.95), WebPros cPanel and WHM CVE-2026-41940 (EPSS 0.99), Palo Alto Networks PAN-OS CVE-2026-0257 (EPSS 0.94), and ConnectWise ScreenConnect CVE-2024-1708. If any of these live in your perimeter, treat them as active fire.

On the browser side, Google shipped Chrome 153 patching its seventh zero-day of 2026, tracked as CVE-2026-87491 and confirmed exploited in attacks (A1, A4, A6). Push the Chrome update through your managed fleet alongside the Windows work.

What to do first

The volume this month is large, so sequence by exploitation, not by count.

  • Apply the September Windows cumulative updates after pilot validation, watching for the Server 2016 0xc0000409 error (A13, A14).
  • Patch the four new KEV entries now: CVE-2026-81963 and CVE-2026-85880 on Windows, CVE-2026-75650 on Adobe Commerce and Magento, and CVE-2026-86218 on N-able N-central (G3, A8).
  • Force Chrome to 153 to close the exploited CVE-2026-87491 zero-day (A4, A6).
  • Re-check exposure to the ransomware-linked movers: SonicWall, Oracle PeopleSoft, cPanel, PAN-OS, and ScreenConnect.
  • Use the free Microsoft Patch Tracker in Senserva to rank your open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker in Siemserva to follow the daily KEV adds.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-10.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.