Skip to Content

September Patch Tuesday haul includes 973 CVEs

Windows takes 718 fixes… but what if it was actually a slow month?

Author placeholder

Microsoft on September 9 released 973 patches affecting 39 product families. Of those, 114 of the addressed issues are considered by Microsoft to be of Critical severity; 58 CVEs are expected to be exploited within the next 30 days. (Two Important-severity Windows vulnerabilities already are; more on those below.) 284 have a CVSS Base score of 8.0 or higher. None of this month’s collection were publicly disclosed prior to patch release. 

For the second month in a row, the relatively low advisory count poses an interesting contrast to the main event. The Chrome team released 24 Edge-related patches in the days before Patch Tuesday, while Adobe moved 21 patches affecting Acrobat with the main release. The usual Servicing Stack update (ADV990001) was issued. MITRE sent word of CVE-2025-70873, an information disclosure issue affecting SQLite v3.51.1. The only eyebrow-raising advisory item, in fact, comes from the OpenSSL Software Foundation, warning of CVE-2026-34182 – an improper validation of an integrity-check value (CWE-354) concerning CMS (Cryptographic Message Services) data in certain containers. It carries a 9.1 CVSS Base score.

Nine Microsoft CVEs announcements likewise could be considered advisory, since they were patched prior to September 9. All are Critical-severity and two carry a “perfect” 10.0 CVSS base score; these affect Azure, Copilot, Discovery Studio, Entra, Fabric, and Power Automate. We include these nine items in the usual charts and statistics below, but they’re fortunately not items the average administrator need address in any fashion. The average CVSS Base score of these nine CVEs is 9.0, compared with a 7.4 average for the other 964 CVEs.

Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below. 

And that is, as they say, the good news. Now let’s talk about patch volume.

Six months in the whirlwind

First, let us stipulate that a patched vulnerability is – with an exception we’ll cover in a second – always better than an unpatched vulnerability. In that light, it’s easy to appreciate not only the delivery of nearly a thousand patches in September, but the gift that is Patch Tuesday – it’s free, it’s expectable, and it improves products. (Remember always that the team that coordinates and delivers the protections is not the team that wrote whatever is broken. First of all, the protections team is much smaller.) The continued choice by Microsoft and others to patch flaws long after the customers’ checks have cleared is a positive thing; we can quibble about product lifespans, but the fact remains that we all want things to be made better when trouble arises. Patch Tuesday is a regularly scheduled commitment to making that so.

That said, the system was not built for the AI-finder age. Figure 1 shows patch volumes over the last 60 months (five years) of Patch Tuesday. 

 

pt2609-fig01.png

Figure 1: A year ago, a hundred patches seemed like a lot in one month. It was a more innocent time.

That spike over the last six months has a number of cascading effects -- from the sheer volume of data moving across the internet to the extraordinary effort on the part of the teams involved in testing bug reports, identifying affected versions, developing the patches, getting them out the door, and applying them to literally millions of systems. (Even analysis gets wild at these levels. For instance, the Summary document sent out by Microsoft to provide analysts with information on each patch would, were it formatted for print, be a 3,002-page PDF – and yes, some analysts read every page.)

And effects have costs. As mentioned, there is an exception to patched > unpatched. With a system like Patch Tuesday, which retains customer trust in part by virtue of its relative transparency, to issue a fix is to reveal that a vulnerability exists. The burden then shifts to the customer to test and apply the patch if it is pertinent to their systems. However, every so often, a patch is only available for part of the userbase. That can happen when a product is out of support -- for example, there’s a good chance that a nonzero number of this month’s vulnerabilities exist in, say, Vista, but there’ll be no mainstream patches for that system.

It can also happen if you are a user of a less common flavor of a product – Office for Mac, for instance. Over the years, the occasional Office patch has gone out on Patch Tuesday with a note telling the Mac crowd to watch the published CVE information for work on when their Apple-scented fix would be available.

This month, there were 68 Office patches for which the Summary included notice that the vulnerability applies to Office for Mac, but the fix wasn’t ready yet. Two of those are Critical-severity, 9.8 CVSS Base issues.  Thirteen more also indicate there’s no Mac patch version yet, and also that Preview Pane is a vector. One more has no Mac patch yet, and also simply viewing the message in Outlook is a vector.  That’s eighty-two CVEs for which, most likely, Microsoft simply ran out of runway.

For now, other AI-related trends we’ve observed in the last six months are holding. Just two CVEs were under active exploit in the wild as of September 9. The average CVSS Base score for each month’s patches has dropped from a rock-steady 7.8 in the pre-AI era to a more palatable 7.4. Finders, however they are coming up with their discoveries, are working within the disclosure system (with a few Noisy Exceptions). And the continuing decline in advisory counts hints that perhaps there will be a similar break in the fever for patches. (The Chrome team has announced that they’ll be moving to a every-two-week patch cycle, but Microsoft assures us that this will have no effect on the lists of Edge-related Chrome advisories they release each month.)

So there’s that. However, another glance at Figure 1 should make observers uneasy. Without getting into the mechanics of it, Patch Tuesday traditionally has a rhythm to its patch volume, with the first month of each quarter (January-April-July-October) a little heavier than the next two. September in particular has always been a bit of a respite. The phrase does this month look like a respite to you? comes to mind. The thing is… what if we get to October and find out it was!

By the numbers

  • Total CVEs: 973
  • Publicly disclosed: 0
  • Exploit detected: 2
  • Severity
    • Critical: 114
    • Important: 857
    • Moderate: 1
    • Low: 1
  • Impact:
    • Defense in Depth: 1
    • Denial of Service: 56
    • Elevation of Privilege: 437
    • Information Disclosure: 173
    • Remote Code Execution: 258
    • Security Feature Bypass: 18
    • Spoofing: 17
    • Tampering: 13
  • CVSS base score 9.0 or greater: 44
    • CVSS base score 9.0 or greater, but patched in advance of Patch Tuesday: 5
  • CVSS base score 8.0 or greater: 284

 

pt2609-fig02.png

Figure 2: Even Defense in Depth gets a turn in September 2026 – a single Low-severity CVE. Elevation of Privilege also accounted for a few patches this month.

Products

  • .NET: 6
  • 365: 106
  • Access: 4
  • ASP.NET: 2
  • Auth / Android: 1
  • Azure: 4
  • Azure AI: 1
  • Azure Cosmos DB: 1
  • Azure CycleCloud: 1
  • ClrMD: 1
  • Copilot Studio: 1
  • Discovery Studio: 1
  • Dynamics 365: 2
  • Entra: 2
  • Excel: 30
  • Exchange: 9
  • Fabric: 1
  • HEIF: 1
  • HEVC: 2
  • MSAL for node.js: 1
  • Office: 106
  • Outlook: 1
  • Power Automate: 1
  • Power Platform: 1
  • PowerPoint: 6
  • PowerShell: 1
  • Publisher: 2
  • RDP for Windows: 1
  • Remote Desktop: 3
  • SharePoint: 16
  • Skype: 10
  • Spring Cloud Azure: 1
  • SQL: 63
  • Teams: 2
  • VS: 21
  • WebP: 1
  • Windows: 718
  • Word: 32
  • Xbox: 1

As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect. 

 

pt2609-fig03.png

Figure 3: As has become customary, we’ve removed Windows (718 updates) from this chart, as well as the 18 families receiving just one update. Please see the list above for details.

 

pt2609-fig04.png

Figure 4: And with that, Elevation of Privilege passes 1,000 CVEs for the year. Nice job, EoP. Got your trophy right here.

Notable September updates

In addition to the issues discussed above, a few items merit general attention. 

Office for Mac – 82 CVEs

As discussed above, these updates were not available for Patch Tuesday release. We’ve listed all 82 on a special page of the Excel workbook for September.

CVE-2026-81963 -- Windows Update Stack Elevation of Privilege Vulnerability
CVE-2026-85880 -- Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

The only two CVEs for which active exploits have thus far been detected are both Important-severity Elevation of Privilege issues in Windows. Curiously, they are mirror images of each other in a sense; for every version of Windows (client or server) in support, one patch or the other applies, but never both. They differ under the hood, too – according to their respective CWEs, the Update Stack issue is a matter of link following (CWE-59) plus improper access control (CWE-284), while the ALPC issue involves heap-based buffer overflow (CWE-122, once again the most common CWE among the month’s vulnerabilities) plus use of an uninitialized resource (CWE-908).


Sophos protections

CVESophos Intercept X/Endpoint IPS

Sophos XGS Firewall

CVE-2026-68846Exp/2668846-AExp/2668846-A
CVE-2026-68876Exp/2668876-AExp/2668876-A
CVE-2026-68884Exp/2668884-AExp/2668884-A
CVE-2026-69277Exp/2669277-AExp/2669277-A
CVE-2026-69301Exp/2669301-AExp/2669301-A
CVE-2026-69305Exp/2669305-AExp/2669305-A
CVE-2026-69310Exp/2669310-AExp/2669310-A
CVE-2026-69337Exp/2669337-AExp/2669337-A
CVE-2026-69364Exp/2669364-AExp/2669364-A
CVE-2026-69366Exp/2669366-AExp/2669366-A
CVE-2026-69385Exp/2669385-AExp/2669385-A
CVE-2026-69406Exp/2669406-AExp/2669406-A
CVE-2026-69436Exp/2669436-AExp/2669436-A
CVE-2026-69451Exp/2669451-AExp/2669451-A
CVE-2026-69460Exp/2669460-AExp/2669460-A
CVE-2026-69466Exp/2669466-AExp/2669466-A
CVE-2026-69473Exp/2669473-AExp/2669473-A
CVE-2026-69498Exp/2669498-AExp/2669498-A
CVE-2026-69541Exp/2669541-AExp/2669541-A
CVE-2026-69585Exp/2669585-AExp/2669585-A
CVE-2026-69600Exp/2669600-AExp/2669600-A
CVE-2026-69605Exp/2669605-AExp/2669605-A
CVE-2026-69623sid:2313028, sid:2313031sid:2313028, sid:2313031
CVE-2026-69714Exp/2669714-AExp/2669714-A
CVE-2026-69723Exp/2669723-AExp/2669723-A
CVE-2026-69757Exp/2669757-AExp/2669757-A
CVE-2026-69779Exp/2669779-AExp/2669779-A
CVE-2026-69832Exp/2669832-AExp/2669832-A
CVE-2026-69911Exp/2669911-AExp/2669911-A
CVE-2026-69921Exp/2669921-AExp/2669921-A
CVE-2026-70289Exp/2670289-AExp/2670289-A
CVE-2026-70342Exp/2670342-AExp/2670342-A
CVE-2026-70583Exp/2670583-AExp/2670583-A
CVE-2026-71340Exp/2671340-AExp/2671340-A
CVE-2026-71343Exp/2671343-AExp/2671343-A
CVE-2026-77500Exp/2677500-AExp/2677500-A
CVE-2026-80093Exp/2680093-AExp/2680093-A
CVE-2026-81963Exp/2681963-AExp/2681963-A

 

As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.

Appendix: Patch Tuesday 2026-09

Once again we are dropping the mile-long appendices – which would be up to about five miles at this point -- and present to you all the data you crave in a far more civilized format, an Excel workbook. You’ll find all your favorite appendix data there, in a format that allows readers to pivot and sort to their hearts’ content. The workbook contains multiple sheets, including a special sheet this month for Mac folk:

PT_Summary – key monthly metrics in a single-screen format
PT_PriSevImp – best for sorting by impact, Microsoft-assigned severity / CVSS, impact, and prospects for exploitability
PT_ByProduct – a more granular breakdown focusing on product families; helpful when dealing with CVEs with multi-family applicability
PT_Windows – a chart showing which versions of Windows are affected by each patched CVE
PT_Protections – a list of all Sophos-issued protections applicable to this month’s patches; replicates the chart in this blog post for easy reference
PT_Advisories – a Servicing Stack notice along with information on Adobe and Edge patches
PT_CWE – a breakdown of which vulnerabilities were most often discovered in the products patched in September
PT_Mac_CVEs – a list of the 82 Office for Mac vulnerabilities still pending as of 9 September