September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

Imported from official source

Cybersecurity Classified by Officially

Microsoft has addressed 972 vulnerabilities in its September 2026 security update release, over double the number of CVEs released in August, and a new Patch Tuesday record. This month's patches include fixes for two exploited zero-day vulnerabilities and 113 Critical vulnerabilities, along with 857 additional vulnerabilities of varying severity levels. Additionally, there was a new proof-of-concept zero-day exploit disclosed against Microsoft Defender, dubbed ShieldCrash. This is discussed at the end of this blog, separately from Microsoft’s patches.

New AI-Powered Capabilities in Falcon Exposure Management 

With CrowdStrike Falcon® Exposure Management, you can automatically classify and prioritize assets, show attack paths targeting client-side exploitation of devices, and integrate with CrowdStrike Falcon® Next-Gen SIEM. Learn more in this blog post: 

This month's leading risk types by exploitation technique are elevation of privilege with 437 patches (45%), remote code execution (RCE) with 258 patches (26%), and information disclosure with 171 (18%).

Microsoft Office received 22 Critical patches this month, of which 12 are exploitable via Preview Pane or Reading Pane. When Preview Pane or Reading Pane is enabled, merely previewing a crafted file triggers code execution without any click, attachment open, or macro prompt. This attack pattern has historically been favored by both commodity phishing campaigns and targeted intrusion operators because it eliminates much of the social-engineering friction of convincing users to take an action.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/

Officially imported this from CrowdStrike’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
CrowdStrike — imported from official source
Official source
https://www.crowdstrike.com/blog/feed/ RSS
Imported
September 18, 2026 11:35
Versions
1 recorded
Identity
https://www.crowdstrike.com/?p=971387

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.