Microsoft's September security update addressed 974 unique CVEs, the largest Patch Tuesday release yet, including two zero-day flaws already being actively exploited. Windows accounted for the vast majority of fixes at 723, with Office, SQL, SharePoint and Azure making up the rest, while 13 issues were rated Critical.
darkreading.com
· 2026-09-08
Microsoft released its September security update addressing roughly 972 vulnerabilities, including 112 rated critical, surpassing the previous record of 570 set just two months ago. The company has now fixed 2,760 vulnerabilities in 2024 alone, more than double last year's total and on pace to exceed the combined totals of the past three years.
arstechnica.com
· 2026-09-08
Microsoft has issued the KB5122878 update for Windows 10 Enterprise LTSC and machines enrolled in the Extended Security Updates program, bumping systems to build 19045.7725 (or 19044.7725 for LTSC 2021). The update bundles this month's Patch Tuesday security fixes plus smaller changes covering Secure Boot certificate rollout, a time-zone correction for Morocco, and diagnostic and compatibility tweaks.
bleepingcomputer.com
· 2026-09-08
Microsoft's latest Patch Tuesday release addresses 966 vulnerabilities, its largest batch ever, including 105 rated Critical and two zero-days already being exploited in the wild. The count excludes 204 additional flaws Microsoft patched earlier in the month across products like Azure AI Language, Copilot Studio, and Entra ID.
bleepingcomputer.com
· 2026-09-08
Microsoft has shipped the September 2026 Patch Tuesday cumulative updates KB5124008 and KB5122880 for Windows 11 versions 25H2/24H2 and 23H2. The update patches roughly 1,000 vulnerabilities catalogued in recent months and is mandatory, installable via Windows Update or the Microsoft Update Catalog. Since 25H2 shares its codebase with 24H2, both versions receive identical fixes and features.
bleepingcomputer.com
· 2026-09-08
Microsoft is set to release its largest patch Tuesday yet, fixing more than 650 security vulnerabilities in Windows, according to sources. This follows a summer of escalating patch counts—around 200 in June, 570 in July, and nearly 400 in August—driven by AI models from Anthropic and OpenAI that are uncovering software flaws far faster than before.
theverge.com
· 2026-09-08
Shadowserver has identified nearly 22,000 internet-exposed Microsoft Exchange servers that remain unpatched against CVE-2026-62911, a high-severity authentication bypass flaw affecting Exchange Server 2016, 2019, and Subscription Edition. Most vulnerable systems are located in the United States and Germany, where officials say roughly 85% of on-premises Exchange servers remain exposed despite Microsoft releasing a fix in August 2026.
bleepingcomputer.com
· 2026-09-01
Microsoft has confirmed that the August 2026 .NET Framework cumulative update causes some WPF-based applications to throw a System.IO.FileFormatException when printing or exporting to PDF/XPS with fonts like Calibri. The bug affects current Windows 10 and 11 releases as well as Windows Server versions from 2012 through 2025, and Microsoft is still working on a permanent fix.
bleepingcomputer.com
· 2026-08-24