September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
Blog post from Crowdstrike
CrowdStrike’s overview of Microsoft’s September 2026 Patch Tuesday reports a record 972 vulnerabilities, including 113 rated Critical and two actively exploited elevation-of-privilege zero-days in the Windows Update Stack and Windows ALPC, both of which can enable attackers with local access to obtain SYSTEM privileges. The release is dominated by elevation-of-privilege, remote-code-execution, and information-disclosure flaws, with Windows, Extended Security Updates, and Microsoft Office receiving the largest number of patches. Particularly serious issues include unauthenticated network-accessible remote-code-execution vulnerabilities affecting Netlogon, DNS Server, DHCP Server, MSMQ, Services for NFS, SSTP VPN, and other infrastructure components, several with CVSS scores of 9.8, as well as flaws in Kerberos, Hyper-V, Remote Desktop, SQL Server, and Windows graphics and media components. Twenty-two Critical Office-related vulnerabilities include numerous Outlook Reading Pane and Explorer Preview Pane attack paths that may allow code execution simply by previewing malicious content, increasing phishing-related risk. The report also notes a newly disclosed, unpatched proof-of-concept Microsoft Defender zero-day called ShieldCrash, whose claims remain under review, and recommends organizations prioritize exposed and high-impact systems while maintaining broader mitigation and vulnerability-management strategies when patches are unavailable.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 2 | 931 | 231 | 103 | -84% |
| Secrets Management | 1 | 451 | 99 | 43 | -80% |
| Zero Trust | 1 | 20 | 10 | 5 | -90% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.