Microsoft’s September 2026 Patch Tuesday has fixed a record 974 CVEs, including two actively exploited zero-day vulnerabilities and 20 wormable bugs, marking one of the largest single-month security update batches in the company’s history and putting IT teams worldwide on alert.
Quick Answer / Key Update
Microsoft’s September 2026 Patch Tuesday addressed 974 CVEs, including two zero-days already being exploited in the wild and 20 wormable vulnerabilities capable of spreading without user interaction. Separately, Cisco and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of a maximum-severity authentication bypass vulnerability, tracked as CVE-2026-20079, in Cisco’s Secure Firewall Management Center software.
What Happened?
September’s Patch Tuesday release addressed a record number of vulnerabilities, reflecting both the scale of Microsoft’s software ecosystem and the accelerating pace at which security flaws are being discovered and disclosed. Among the fixes was a critical Microsoft Exchange remote code execution vulnerability exploitable via Visio email attachments, a particularly concerning bug given how widely Exchange is used in enterprise email systems.
Separately, CISA added the actively exploited Cisco vulnerability, along with flaws in Microsoft Windows and N-able N-central, to its Known Exploited Vulnerabilities catalog, signaling that federal agencies and many enterprises are required to patch these issues on an accelerated timeline.
Latest Update
Shortly after Microsoft’s September 2026 Patch Tuesday updates rolled out, a security researcher released a new Microsoft Defender zero-day exploit, underscoring how quickly newly patched systems can face fresh threats. Google also patched 230 vulnerabilities in Chrome this week, including another actively exploited zero-day, the seventh such Chrome vulnerability patched since the start of the year, highlighting that browser security remains an equally active battleground alongside operating system patches.
Why Is This Trending?
Interest in this story is rising because the scale of September’s patch batch, combined with multiple actively exploited zero-days across Microsoft, Cisco, and Google products, directly affects IT administrators, businesses, and everyday users who rely on these widely used platforms. The volume of wormable bugs in particular raises concern about the potential for fast-spreading attacks if patches are not applied quickly.
Key Details
- Total CVEs fixed (September 2026 Patch Tuesday): 974, a record for a single month
- Actively exploited zero-days (Microsoft): 2
- Wormable vulnerabilities: 20
- Notable critical flaw: Exchange remote code execution via Visio email
- Cisco vulnerability: CVE-2026-20079, maximum-severity authentication bypass, actively exploited
- Chrome vulnerabilities patched this week: 230, including a seventh actively exploited zero-day this year
What We Know So Far
Confirmed: The 974-CVE count for September’s Patch Tuesday, the two Microsoft zero-days, and active exploitation of the Cisco Secure Firewall Management Center vulnerability are confirmed through Microsoft, Cisco, and CISA disclosures.
Developing: Information is not yet confirmed on the full scope of organizations affected by the newly released Microsoft Defender zero-day exploit, as this development occurred shortly after the initial patch release.
Why This Matters
The record scale of September’s patch cycle illustrates the growing complexity and attack surface of modern enterprise software. For businesses, unpatched systems remain one of the most common entry points for ransomware and data breach attacks, meaning delays in applying these updates can carry significant financial and operational risk. CISA’s decision to add multiple actively exploited flaws to its Known Exploited Vulnerabilities catalog reflects heightened urgency around timely patching, particularly for organizations in critical infrastructure sectors.
What Happens Next?
IT teams are expected to prioritize patching the actively exploited Cisco and Microsoft vulnerabilities immediately, given confirmed real-world exploitation. Security researchers will likely continue probing the newly patched Microsoft systems for additional weaknesses, as has historically happened following large patch releases, making close monitoring of vendor advisories important in the coming weeks.
Related Trends and Searches
Related searches include "Patch Tuesday September 2026," "Cisco firewall vulnerability CVE-2026-20079," "Chrome zero-day patch," and "Microsoft Exchange vulnerability," reflecting strong interest among IT professionals and security-conscious users in tracking this month’s critical updates.
Frequently Asked Questions
How many vulnerabilities did Microsoft fix in September 2026?
Microsoft’s September 2026 Patch Tuesday fixed a record 974 CVEs, including two actively exploited zero-days.
What is a wormable vulnerability?
A wormable vulnerability can potentially spread from system to system without requiring user interaction, making it especially dangerous if left unpatched.
What is the Cisco vulnerability being actively exploited?
CVE-2026-20079 is a maximum-severity authentication bypass flaw in Cisco’s Secure Firewall Management Center software, confirmed by both Cisco and CISA as actively exploited.
Should I update my systems immediately?
Given confirmed active exploitation of several vulnerabilities this month, security experts generally recommend applying critical patches as soon as possible, especially for internet-facing systems.
How many Chrome zero-days have been patched in 2026?
Google’s latest fix marks the seventh actively exploited Chrome zero-day patched since the start of 2026.
What is CISA’s Known Exploited Vulnerabilities catalog?
It is a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency of vulnerabilities confirmed to be actively exploited, which federal agencies are required to patch on an accelerated timeline.
What is the Microsoft Exchange vulnerability involving Visio?
It is a critical remote code execution flaw that can be exploited via Visio email attachments, affecting organizations that rely on Microsoft Exchange for enterprise email.


