Microsoft patched 974 flaws this month. Four are already under attack.
The Register called this month's September Patch Tuesday count a record.
On 9 September 2026, Microsoft issued 974 CVEs. In the whole of 2025 it issued 1,130.
Four flaws in the month's disclosures are under active exploitation, according to the report, and two of them are Microsoft's. CVE-2026-85880 and CVE-2026-81963 are Windows privilege escalations. CVE-2026-75650, called StyleSmuggler, allows remote code execution in Adobe Commerce and Magento. CVE-2026-85046 is a Chrome V8 flaw that was still unpatched in Edge when the article was published.
Microsoft wrote of CVE-2026-85880: "An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required."
CISA gave United States federal civilian agencies until 22 September for the two Windows flaws. The deadline for the Adobe one was 11 September. The Register puts the rising counts down to AI-driven bug hunting.
Your change board approves a fixed number of emergency windows a month. What happens to the rest?
Sources
Our file on Microsoft
- 20 Sept
Infor shipped three AI agents into a distributor's ERP in two weeks.
- 19 Sept
Microsoft's AI agents rewrote 430,000 lines of Copilot code. The tokens cost $120,000.
- 17 Sept
Microsoft confirmed an Excel security update can silently break paste. No fix date yet.
- 17 Sept
Broadcom raised VMware prices by 10x or more, European cloud providers say.
- 15 Sept
Microsoft knocked out Remote Desktop with two September security updates.
For your next steering committee
- 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
- 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
- 3Ask how long a restore took the last time it was tested.
Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01
Welcome back. · Issue 01
