Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

Imported from official source

Cybersecurity Classified by Officially

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. 

This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August.

Microsoft Patch Tuesday for September 2026 

This month’s release addresses 974 vulnerabilities, including 113 critical and 860 important-severity vulnerabilities.

In this month’s updates, Microsoft has addressed two vulnerabilities that have been exploited in the wild.

Microsoft has not addressed any vulnerabilities in Microsoft Edge (Chromium-based) in this month’s update.

Microsoft Patch Tuesday, September edition, includes updates for vulnerabilities in Windows HTTP.sys, Windows Hyper-V, GitHub Copilot, and Visual Studio Code, Copilot Studio, Data Sharing Service Client, Entra ID, Microsoft Exchange Server, and more.

This month’s release includes fixes for several high-severity issues that could potentially enable remote code execution, privilege escalation, or denial-of-service attacks. As always, timely patch deployment is crucial to reduce exposure and ensure systems remain resilient against exploitation attempts.

Qualys InstaScan posted detections for ETM Agent Insta-enabled customers 13 mins after Microsoft published Patch Tuesday. Find out more.

Get to Know Agent Insta

The September 2026 Microsoft vulnerabilities are classified as follows:

Vulnerability CategoryQuantitySeveritiesSpoofing Vulnerability16Critical: 1Important: 15Denial of Service Vulnerability56Important: 56Elevation of Privilege Vulnerability438Critical: 27Important: 411 Information Disclosure Vulnerability173Critical: 2Important: 171 Remote Code Execution Vulnerability253Critical: 82

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.qualys.com/vulnerabilities-threat-research/2026/09/08/microsoft-patch-tuesday-september-2026-security-update-review

Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Qualys — imported from official source
Official source
https://blog.qualys.com/feed RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://blog.qualys.com/?p=42202

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.