Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will…
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS. A few vulnerabilities worth mentioning: Windows Update Stack…
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August…
Microsoft heeft 666 kwetsbaarheden verholpen in Windows. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. Microsoft heeft voor Windows 666 kwetsbaarheden verholpen. De 32 ernstigste kwetsbaarheden bevinden zich in meerdere Windows componenten en hebben een CVSS score van 9.0 en hoger toegewezen gekregen. Kwaadwillenden met toegang tot deze componenten kunnen zonder voorafgaande…
Microsoft heeft 114 kwetsbaarheden verholpen in diverse Office producten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. Voor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide bestand te openen of link te volgen. Microsoft heeft voor Office 114 kwetsbaarheden verholpen. De 4 ernstigste kwetsbaarheden bevinden zich in meerdere Office componenten en hebben…
Microsoft heeft 15 kwetsbaarheden verholpen in diverse Developer Tools. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade zoals benoemd in onderstaande tabel. De ernstigste kwetsbaarheid met kenmerk CVE-2026-81376 heeft een CVSS-score van 9,6. Een kwaadwillende misbruiken door een gebruiker ertoe te verleiden een speciaal geprepareerde Visual Studio Code-workspace te openen. Hiermee kunnen de Workspace Trust-beperkingen…
Microsoft heeft 62 kwetsbaarheden verholpen in diverse componenten van SQL Server. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade zoals benoemd in onderstaande tabel. ``` SQL Server: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-47297 | 8,10 | Uitvoeren van willekeurige code | | CVE-2026-66814 | 8,80 |…
Microsoft heeft 9 kwetsbaarheden verholpen in Exchange Server. Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service uit te voeren, zich voor te doen als andere gebruiker, zich verhoogde rechten toe te kennen, willekeurige code uit te voeren en/of toegang te krijgen tot gevoelige gegevens. De ernstigste kwetsbaarheid met kenmerk CVE-2026-69380 heeft een CVSS-score van 9,9 en betreft een autorisatiekwetsbaarheid. Een geauthenticeerde kwaadwillende met beperkte rechten en…
Microsoft heeft 2 kwetsbaarheden verholpen in Dynamics, zowel online als on-premise. De kwetsbaarheden stellen een kwaadwillende in staat om zich verhoogde rechten toe te kennen, willekeurige code uit te voeren en/of toegang te krijgen tot gevoelige gegevens. ``` Microsoft Dynamics 365: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65772 | 8,80 | Uitvoeren van willekeurige…
Microsoft heeft 4 kwetsbaarheden verholpen in diverse Azure componenten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. De kwetsbaarheid met kenmerk CVE-2026-69854 heeft een CVSS-score van 9,0. Een kwaadwillende die al over een geldige sessie beschikt, kan de kwetsbaarheid onder specifieke voorwaarden, zoals bepaalde protocolinstellingen of configuraties, misbruiken om zijn rechten…
Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should…
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
Serial Number: AV26-895Date: September 8, 2026 As of September 8, 2026, Commvault is affected by vulnerabilities in the following product: Commvault Cloud 11.36.0 Prior to 11.36.123 11.40.0 Prior to 11.40.72 11.44.0 Prior to 11.44.20 11.46.0 Prior to 11.46.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CV_2026_07_1: Command Center API Authentication Bypass Commvault Cloud Security Advisories
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain…
Serial Number: AV26-894Date: September 8, 2026 As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products: SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20 SAP Cloud Application Programming Model (CAP) prior or equal to 1.183 prior…
Serial Number: AV26-893Date: September 8, 2026 As of September 8, 2026, Hitachi is affected by vulnerabilities in the following product: Cosminexus Component Container Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerability in Cosminexus Hitachi Vulnerability Information
Serial Number: AV26-892Date: September 8, 2026 As of September 4, 2026, Inductive Automation is affected by a vulnerability in the following product: Ignition Prior to or equal to 8.1.53 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CSAF/csaf_files/OT/white/2026/icsa-26-246-06.json at develop · cisagov/CSAF · GitHub Inductive Automation Ignition | CISA
Serial Number: AV26-891Date: September 8, 2026 As of September 7, 2026, JetBrains is affected by vulnerabilities in the following products: GoLand Prior to 2026.2.2.1 Hub Prior to 2026.2.52442 IntelliJ IDEA Prior to 2026.2.2 YouTrack Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Fixed security issues
Serial Number: AV26-890Date: September 8, 2026 As of September 8, 2026, Siemens is affected by vulnerabilities in the following products: Reyrolle 7SR5 Versions prior to V2.70 Teamcenter Multiple versions and models Siveillance Control Multiple versions and models SIMATIC AX Runtime Multiple versions and models Desigo CC Product Family Multiple versions and models Industrial Edge Management Multiple versions and models SIMOVE Fleetmanager and SIPLANT Multiple versions and models The Cyber…
Serial Number: AV26-889Date: September 8, 2026 As of September 7, 2026, OpenVPN is affected by vulnerabilities in the following product: OpenVPN Prior to or equal to 2.6.22 Prior to or equal to 2.7.6 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-84732 - Reliability layer unbounded TLS timeout and acks for non-outstanding packets Security Advisories & Updates | OpenVPN
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
Nell’ambito del Security Patch Day di settembre, SAP rilascia aggiornamenti di sicurezza per risolvere molteplici nuove vulnerabilità, di cui 4 con gravità “critica” e 4 con gravità “alta”.
Serial Number: AV26-888Date: September 8, 2026 As of September 7, 2026, Adobe is affected by a vulnerability in the following products: Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Magento Open Source All except Hotfix for…
Serial Number: AV26-886Date: September 8, 2026 As of September 7, 2026, Dell is affected by vulnerabilities in the following products: Dell OpenManage Network Integration Prior to 3.10 or later Dell iDRAC9 Versions prior to 7.30.10.50 and 7.00.00.184 Dell iDRAC10 Prior to 1.30.30.50 or later Dell PowerEdge Server for Intel 2026 Multiple versions and models Dell Open Manage Python SDK (omsdk) Prior to 1.2.519 or later Dell Avamar Multiple versions Dell Networker Virtual Edition (NVE) Multiple…
Serial Number: AV26-884Date: September 4, 2026 As of September 4, 2026, SonicWall is affected by vulnerabilities in the following product: Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM) 4.3.0 and earlier versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SonicWall NSM On-Prem Affected By Multiple Vulnerabilities Security Advisory
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.