SPOJENO AI KEV ✓ (3 z 6) EPSS 0.42 (nejvyšší)
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
CVE v události 6
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2023-21674 | 8.8 3.1 · microsoft | KEV ✓ | 0.42 |
| CVE-2026-66302 | 9.8 3.1 · microsoft | – | 0.01 |
| CVE-2026-69579 | 9.8 3.1 · microsoft | – | 0.01 |
| CVE-2026-69590 | 9.8 3.1 · microsoft | – | 0.01 |
| CVE-2026-81963 | 7.8 3.1 · microsoft | KEV ✓ | 0.01 |
| CVE-2026-85880 | 7.8 3.1 · microsoft | KEV ✓ | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.
Jak se o tom psalo 14
-
· Malwarebytes Labs US
Microsoft fixes record 964 flaws, including 2 exploited zero-days
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch. The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of…
-
· CSIRT Itálie (ACN) IT
Aggiornamenti Mensili Microsoft
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 973 nuove vulnerabilità, di cui 2 di tipo 0-day.
-
· NCSC-FI FI
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-69805, CVE-2026-58649, CVE-2026-69806, CVE-2026-69439, CVE-2026-69821, CVE-2026-69624, CVE-2026-62810, CVE-2026-69395, CVE-2026-62762, CVE-2026-62813, CVE-2026-69809, CVE-2026-69359, CVE-2026-69524, CVE-2026-69546, CVE-2026-72978, CVE-2026-57099, CVE-2026-69304, CVE-2026-69401, CVE-2026-70352, CVE-2026-62895 (+1151 other associated CVEs), Summary: Today is Microsoft's September 2026 Patch…
-
· CERT-FR – avis FR
Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...
-
· Cisco Talos US
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and…
-
· Rapid7 US
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will…
-
· SANS Internet Storm Ctr. US
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS. A few vulnerabilities worth mentioning: Windows Update Stack…
-
· Cyber Centre Kanada CA
Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1
Serial Number: AV26-896Date: September 8, 2026 As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP…
-
· BleepingComputer US nadpis události
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
-
· Tenable Research US
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain…
-
· Microsoft Security US
CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
-
· CISA KEV US
Microsoft Windows Link Following Vulnerability (CVE-2026-81963)
CISA added CVE-2026-81963 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft Windows. Remediation due date: 2026-09-22.