Overview
- Microsoft released the cumulative September updates on Tuesday, September 8, 2026, delivering fixes that the company counts as 974 CVEs across Windows and other products.
- The package includes two publicly confirmed actively exploited zero‑day bugs that let attackers elevate privileges and a cluster of about 20 'wormable' flaws that allow unauthenticated remote code execution and could enable fast, automated spread.
- Among the critical fixes are high‑severity remote code execution bugs affecting DNS Server, Remote Desktop Services, Exchange and the Windows Shell, with some CVSS scores as high as 9.8.
- Microsoft has urged customers to deploy quality updates within three days and to set zero‑ or one‑day deadlines for critical fixes, while researchers say organizations should prioritize confirmed‑exploited and high‑impact flaws and adopt inventory, phased automation, and mitigations.
- Security teams face real operational strain because so many fixes must be tested and rolled out quickly, and the broader trend driving this patch surge is AI‑assisted vulnerability discovery that speeds both finding bugs and the potential for attackers to weaponize them.