Patch Tuesday · September 2026
Microsoft September 2026 Patch Tuesday: Prioritizing 974 Vulnerabilities
The Microsoft September 2026 Patch Tuesday release just delivered the largest security update on record. Reported totals vary slightly by outlet — you’ll see this release cited as fixing 964 CVEs, 971 CVE, 972 CVEs, or 974 CVEs depending on the source and how borderline advisories are counted — but every count lands in the same range: a record-breaking release with 113 Critical vulnerabilities, making triage, not just patching, the real challenge for IT teams this month.
For organizations running Windows 11, Windows 10, or Windows Server, the sheer scale of this release means a “patch everything, in order” approach isn’t realistic. Here’s how to make sense of what matters most.
Source: SC Media — What Microsoft’s largest security update means to security teams
What Happened in the September 2026 Release
This release brings the 2026 year-to-date CVE total past 2,600 — already more than double any previous year on record. Of the roughly 974 CVEs patched, 113 are classified Critical, and a handful are already being used in real-world attacks.
Source: Netmanageit / Cisco Talos — September 2026 Microsoft Patch Tuesday Priorities
The Vulnerabilities to Prioritize First
Not every CVE in this release deserves the same urgency. CISA has already added the actively exploited flaws to its Known Exploited Vulnerabilities catalog with a hard remediation deadline, which is the clearest signal of where to start.
The technical root causes worth knowing when you’re briefing leadership:
Heap-based buffer overflow — affecting core Windows components, capable of granting SYSTEM-level access to an authenticated attacker
Use-after-free — found in the Windows Kernel, another path to privilege escalation
Stack-based buffer overflow — impacting graphics-rendering components, with Remote Code Execution potential
Information disclosure — lower severity individually, but valuable to attackers chaining multiple flaws together
When you’re scoring these internally, don’t rely on CVSS alone. A moderate CVSS score attached to an internet-facing, identity-adjacent service (think Microsoft Entra ID or Windows Kerberos) deserves more urgency than a higher score on an isolated internal workload.
Source: Qualys — Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
Which Products and Components Are Affected
This month’s fixes span far beyond the desktop OS. On the endpoint side, patches cover Windows 11, including Windows 11, version 25H2, Windows 11, version 24H2, and Windows 11, version 23H2, along with Windows 10, and every actively supported Windows Server release — Windows Server 2025, Windows Server 2022, Windows Server 2019, and Windows Server 2016, plus Azure Edition builds.
Beyond the OS layer, this release also touches:
Microsoft SQL Server
Microsoft Entra ID
Microsoft Dynamics 365 On-Premises
Skype for Business
Microsoft Copilot
And a long list of core Windows services and protocols that rarely make headlines but are frequently the actual attack surface: Windows DNS Server, Windows DHCP Server, Windows Netlogon, Windows Hyper-V, Windows Kerberos, Windows Message Queuing, Windows Secure Socket Tunneling Protocol, Windows Advanced Local Procedure Call, Windows Routing and Remote Access Service, the Windows Update Stack itself, Windows Imaging Component, Windows HTTP Print Provider, Windows Shell, Internet Connection Sharing, Microsoft Failover Cluster, Microsoft Graphics Component, HEVC Video Extensions, and Microsoft Discovery Studio.
If your environment includes even a handful of these — and most enterprise networks do — this isn’t a release you can selectively skip.
Source: Qualys — Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
974 CVEs, 113 Critical, 2 already being exploited — and a “patch in KB order” plan won’t hold up.
We can help you build a risk-based sequence for this release, and a repeatable process for the next one.
What Security Researchers Are Saying
Independent threat intelligence teams moved quickly on this release. Cisco Talos flagged the actively exploited vulnerabilities and published detection guidance the same day. Other major vendors in the endpoint and vulnerability management space — including CrowdStrike, Rapid7, and Trend AI — have echoed the same message: volume alone isn’t the right way to prioritize. Exposure, exploitability, and business criticality should drive the sequence, not the raw CVE count.
For the authoritative technical detail on any individual CVE, Microsoft Learn and Microsoft Support remain the primary source — third-party summaries are useful for triage, but the official advisories are what you cite in a compliance record.
Source: Netmanageit / Cisco Talos — September 2026 Microsoft Patch Tuesday Priorities
Hotpatch vs. Standard Update: Do You Need to Restart?
Microsoft’s hotpatch capability — available for eligible Windows 11 and Windows Server builds — lets many of this month’s fixes apply without a restart, reducing the operational disruption of an unusually large release. Devices not enrolled in hotpatch will need the full standard update applied through Windows Update or WSUS, which does require a reboot to complete.
This release also continues Microsoft’s rollout of updated Secure Boot certificates and reinforces existing security baseline recommendations — worth reviewing alongside the CVE fixes rather than treating as a separate project.
Source: Neowin — Microsoft releases emergency out-of-band Windows update to fix Patch Tuesday bugs
Where to Get the Updates
The core cumulative updates for this cycle are:
Windows 11, version 25H2 / 24H2 — KB5124008
Windows 11, version 23H2 — KB5122880
Corresponding builds for Windows Server 2025, Windows Server 2022, Windows Server 2019, and Windows Server 2016 are available through the same September cycle — confirm the exact KB for your specific server SKU against the Microsoft Update Catalog before deploying, since server and Azure Edition builds are versioned separately from client builds.
Source: BleepingComputer — Windows 11 cumulative updates KB5124008 & KB5122880 released
How to Prioritize Without Burning Out Your Team
With close to 974 fixes in a single release, a flat “patch in KB order” approach will exhaust your team without necessarily protecting what matters most. A more sustainable sequence:
Patch the actively exploited zero-days first — these are already being used in the wild, full stop.
Prioritize internet-facing and identity-adjacent systems — Entra ID, DNS, DHCP, Kerberos, and RRAS services carry outsized risk regardless of their individual CVSS score.
Use hotpatch where eligible to close the gap on the largest batch of fixes without a full restart cycle.
Confirm exact KB numbers per SKU before pushing to servers — client and server builds diverge, and a mismatched KB wastes a deployment window.
Document what you didn’t patch yet, and why — with a release this size, a risk-based rollout plan is defensible; silence isn’t.
How WME Can Help
Patch Tuesday releases of this scale are exactly where a structured, risk-based patch management process pays for itself. If your team is still working through this month’s release — or wants a second set of eyes on your prioritization approach before the next one lands — WME’s security team can help you build a repeatable process instead of a monthly scramble.
A record-breaking release shouldn’t mean a monthly scramble.
WME’s security team can help you build a repeatable, risk-based patch management process instead of a KB-by-KB fire drill.


