September 8, 2026 was Microsoft’s largest Patch Tuesday. Qualys counted 974 fixes, 113 of them rated critical, against 570 in July and 400 in August; Tenable’s tally of the same release came in at 964.12 Two were already being exploited: one in the Windows Update Stack, one in Windows Advanced Local Procedure Call. Both climb to SYSTEM, and CISA lists both on the Known Exploited Vulnerabilities catalog with a September 22 deadline.1
Where I sit in the process
Most of the fleet where I work gets patched by automated deployment. I do not apply the fixes myself. My part of a record month is the research: read the release and the analysis around it, work out which of the 974 apply to us, sort them, and relay the order to the people who do the applying. The systems team takes the server-side items, the desktop team takes the endpoint ones, the Defender stack sits with me, and the CIO gets the short version with the dates attached.
Nobody on those teams needs the raw list of 974. Each needs a short document filtered to its scope, ordered the same way, with the deadlines attached.
The count hides the work
AI-assisted vulnerability discovery keeps adding candidates to every release, and September’s breakdown shows what that produces: 438 privilege escalation bugs, 253 remote code execution, and 173 information disclosure.1 Satnam Narang from Tenable put the triage problem plainly in an interview with Help Net Security: the count keeps rising, and the set of bugs that can affect any one organization stays about the same.3 Tyler Reguly from Fortra, in the same piece, reads the volume as Microsoft removing attack surface before attackers reach it, and warns that a team still sorting by CVSS is hurting itself.3
Applicability is the filter I put each critical through. Does the affected service exist here? Is it exposed? Can an attacker reach it from a position they could already hold? Those three questions reject most of the list before the CVSS score gets a vote.
The order I relay
First, anything on the KEV catalog with an exploitation note. The two zero-days go out ahead of everything else, and the attacker set the clock, so I work the rollout backward from September 22.
Second, the wormable cluster. ZDI counted 20 patches this month that a remote, unauthenticated attacker can use for code execution with no user interaction, including a DNS Server bug, CVE-2026-69730, that Childs calls the spiritual successor to SigRed.4 A DNS server that answers for a whole domain gets same-day treatment from me even with no exploitation report against it, and the systems team hears about that one the morning the release lands.
Third, the domain compromise primitives. CVE-2026-69676 is a Kerberos authentication bypass that ends in remote code execution on a domain controller, and Microsoft marks it Exploitation More Likely. Childs describes the path as one phished workstation account plus one crafted request to put code on a DC.4 That goes out with the same-day items.
Fourth, the criticals I can confirm we run, with reachable remote code execution ahead of the rest.
Everything left goes to the normal cycle.
What the cumulative covers
The cumulative update is what keeps a month this size manageable from where I sit. It bundles nearly all of the Windows-side fixes, the zero-days included, so the volume turns into a coverage question: did the fleet take the update, what is still pending, and what needs a reboot to finish. That part belongs to the teams running deployment, and a record month is a good reason to read their pending and failed counts instead of assuming it went out.
My hours go to whatever skips the rollup, and Defender is mine to cover. This month that is Exchange and SharePoint, plus a Defender privilege escalation, CVE-2026-69414, where a researcher using the handle Nightmare Eclipse published a proof of concept called ShieldCrash hours after the fixes shipped, claiming to bypass the patch.3 A bypass takes an item out of the normal cycle, because the patch may not close it on its own. That one stays with me: I track the engine version on the systems that matter and revisit it when Defender updates.
What the record release broke
Three of the September fixes caused problems of their own. Some devices lost Remote Desktop Services, where sessions stop responding and sign-in fails. Host folder shares went missing in Hyper-V Linux virtual machines, and some USB Audio Class 1.0 devices failed in multichannel modes. Microsoft shipped an out-of-band update on September 14, six days after the release, that fixes all three and rolls up the September fixes.5
The classification decides who gets it. On Windows 11 versions 26H1, 25H2, and 24H2 the out-of-band release is a security update, so Windows Update, Windows Update for Business, and WSUS carry it under their normal policy.56 On Windows 11 23H2 and Windows 10 22H2 it is optional and non-security, which means it waits for someone to install it.5 It carries a security fix of its own, CVE-2026-62721.5
The handoff
The note to the CIO is short: the two exploited bugs, what they get an attacker, the September 22 deadline, and which items are already moving. The systems team gets the same list filtered to servers, with the DNS and Kerberos entries marked same-day. The desktop team gets the endpoint set, which this month is the two zero-days. Defender is mine, so the ShieldCrash follow-up stays with me instead of going to them. All three get the out-of-band update, because a broken sign-in path outranks a CVE nobody can reach.
The measure of a good month
Reguly’s warning is the one I keep in mind: a team sorting by CVSS alone spends its capacity on bugs no attacker can reach.3 The benchmark I care about is smaller. The two exploited bugs and the wormable set reached the right teams with the right dates the day the release landed, the out-of-band fix reached them before anyone had to ask for it, and the rest went to the backlog on purpose.
-
Qualys. (2026, September 8). Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review. Qualys Blog. https://blog.qualys.com/vulnerabilities-threat-research/2026/09/08/microsoft-patch-tuesday-september-2026-security-update-review ↩︎ ↩︎ ↩︎
-
Tenable Research Special Operations. (2026, September 8). Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880). Tenable. https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880 ↩︎
-
Zorz, Z. (2026, September 9). September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor. Help Net Security. https://www.helpnetsecurity.com/2026/09/09/september-2026-patch-tuesday-zero-days-sigred-successor/ ↩︎ ↩︎ ↩︎ ↩︎
-
Childs, D. (2026, September 8). The September 2026 Security Update Review. Zero Day Initiative. https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review ↩︎ ↩︎
-
Microsoft. (2026, September 14). Take action: out-of-band update released to address issues from the September 2026 Windows security update. Windows message center, Microsoft Learn. https://learn.microsoft.com/en-us/windows/release-health/windows-message-center ↩︎ ↩︎ ↩︎ ↩︎
-
Microsoft. (2026, September 14). September 14, 2026, KB5129195 (OS builds 26200.9457 and 26100.9457) out-of-band. Microsoft Support. https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update ↩︎