Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
September 8, 2026
Microsoft released fixes for 974 unique vulnerabilities in its scheduled security update for September, which until recently would have represented a full year’s worth of CVEs.
Of these, the highest-priority vulnerabilities include two that are already under active exploitation. Additionally, Microsoft rated 13 flaws as "Critical" and 58 it deemed as bugs that attackers are more likely to exploit for different reasons, including low attack complexity and high impact.
Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each. The remaining vulnerabilities were spread across other Microsoft technologies, including 62 in SQL, 22 in Developer Tools, 16 in SharePoint Server, and 12 in Azure. This month's release follows a recent trend of increasingly large and record-setting volumes of CVEs for the software giant's Patch Tuesday.











