The Microsoft Patch Day in September is a major one: More than 950 vulnerabilities have been fixed — Microsoft's largest patch release to date. Particularly critical: Two zero-day vulnerabilities are already being actively exploited. The September 2026 update addresses more than 950 security vulnerabilities. Two of them are zero-days and are already being actively exploited.
And Microsoft is not alone. SAP, Adobe, and Cisco also disclosed critical security vulnerabilities in September. For IT teams, this means: Patch, prioritize, and check affected systems now.
Microsoft: More than 950 Vulnerabilities – two Zero-Days actively exploited.
Microsoft’s Patch Tuesday is unusually extensive this month, with more than 950 vulnerabilities addressed. Two of them deserve particular attention. Both allow Elevation of Privilege, enabling attackers to escalate existing user permissions potentially up to full system control:
- CVE-2026-81963 | CVSS 7.8 – High – Elevation of Privilege in the Windows Update Stack: A flaw in how links are resolved before file access («link following») allows an authenticated attacker to elevate local privileges to SYSTEM level. This is particularly dangerous if an attacker has already gained access to a Windows device, as the vulnerability can then be used to escalate privileges and perform further actions on the system.
- CVE-2026-85880 | CVSS 7.8 – High – Elevation of Privilege in Windows Advanced Local Procedure Call (ALPC): ALPC is part of the internal communication between Windows processes. A vulnerability in this subsystem allows an authenticated attacker to reliably escalate local privileges and gain significantly greater control over the affected system.
Why this Patch Tuesday matters.
The sheer number of vulnerabilities stands out. One possible reason is Microsoft’s increased use of AI-powered systems to identify security flaws, allowing vulnerabilities to be detected faster and at greater scale. For businesses, this does not mean every CVE requires immediate action. What matters is prioritizing vulnerabilities based on actual risk. For the two Windows vulnerabilities mentioned above, the situation is clear: they are already being actively exploited.
What does this mean for Businesses?
Not every one of the 950+ Microsoft vulnerabilities is equally relevant to every organization. It depends on the environment. IT teams should therefore focus on these key questions:
-
Are the affected Windows versions in use?
-
Are clients and servers fully patched?
-
Are there systems where updates are being delayed?
-
Are there signs of unusual activity or a potential compromise?
-
Do particularly critical systems require additional protection?
Especially with actively exploited zero-days, do not wait for the regular patch cycle to catch up.
SAP, Adobe and Cisco are also affected by Security Vulnerabilities.
September is an unusually busy month for security updates beyond Microsoft. Other critical enterprise systems are affected as well.
- SAP has published 19 new Security Notes, including two critical vulnerabilities with CVSS scores of 10.0 and 9.8.
- Adobe Commerce and Magento are affected by a critical zero-day vulnerability that Adobe says is already being actively exploited.
- Cisco has disclosed a critical vulnerability affecting certain Nexus 9000 switches. It also allows remote code execution without prior authentication.
SAP: Two critical Vulnerabilities with CVSS 10.0 and 9.8.
CVE-2026-44756 (OVERPASS) | CVSS 10.0 – Critical. Memory corruption in SAP Extended Passport (EPP) processing. A missing bounds check during the deserialization of EPP data allows an unauthenticated attacker to trigger memory corruption over the network. Potential impacts include:
-
Arbitrary code execution with administrative privileges
-
Credential theft
-
Manipulation of SAP data
-
Modification of SAP binaries
There is currently no public confirmation of active exploitation. However, due to its CVSS score of 10.0, unauthenticated attack vector, and potential administrative impact, this vulnerability should be treated as the highest SAP priority in this patch cycle.
CVE-2026-58240 (S4GET) | CVSS 9.8 – Critical. Missing authentication in the SAP NetWeaver Message Server. The Message Server does not adequately verify the authenticity of application components during registration. An unauthenticated attacker with network access could register a malicious component and perform unauthorised actions within the SAP environment. There are currently no indications of active exploitation for this vulnerability either.
Adobe: Critical Zero-Day already actively exploited.
The situation at Adobe is particularly urgent. Adobe has released an emergency fix outside its regular update cycle for a critical zero-day vulnerability affecting its e-commerce platforms.
CVE-2026-75650 (StyleSmuggler) | Critical. Arbitrary code execution in Adobe Commerce and Magento Open Source. Adobe confirms that the vulnerability is already being actively exploited. Observed attacks include the installation of backdoors on affected servers. In one case, a backdoor was disguised as legitimate NTP traffic. Another attacker deployed a PHP web shell. Affected products include:
-
Adobe Commerce 2.4.4 through 2.4.9
-
Adobe Commerce B2B 1.3.3 through 1.5.3
-
Magento Open Source 2.4.6 through 2.4.9
Cisco: CVSS 9.8 in Nexus 9000 Switches.
Network infrastructure is not spared either: CVE-2026-20212 | CVSS 9.8 – Critical. Remote code execution in Cisco Nexus 9000 Series switches.
The vulnerability affects certain Nexus 9000 switches equipped with Silicon One ASICs. Two TCP ports – 43210 and 43211 – are accessible within the default Layer 3 VRF. An unauthenticated attacker could send crafted input and potentially execute code with root privileges. A successful attack could also crash the affected process and cause the switch to restart.
Cisco has not identified any active exploitation or public proof of concept so far. Due to the severity and potential impact, Cisco is providing both a permanent fix and a temporary Live Protect mitigation.
What Companies should do now: Patch Management.
Not every vulnerability needs to be addressed at the same speed. The key question is: Which vulnerabilities are relevant to your environment, and which are already being actively exploited? For September, we recommend the following order:
- Prioritise actively exploited vulnerabilities: The two Microsoft zero-days and the Adobe Commerce vulnerability should be assessed and patched as quickly as possible.
- Identify affected systems and versions: Check whether the Windows, SAP, Adobe or Cisco products mentioned above are used in your environment.
- Apply patches and mitigations: Where a full patch is not yet possible, implement available security measures and mitigations.
- Check for potential compromise: With actively exploited vulnerabilities, patching after the fact may not be enough. Affected systems should be checked for suspicious activity, backdoors or other signs of compromise.
- Treat patch management as an ongoing process: Organisations cannot manually assess every CVE individually. They need a process that prioritises vulnerabilities based on severity, exploit status, affected systems and actual business risk.
Our Suggestion: Not every CVE is equally urgent.
Microsoft’s September 2026 Patch Tuesday is a good opportunity to take a critical look at your own patch management process. More than 950 Microsoft vulnerabilities is a lot. For businesses, the goal is therefore not to blindly install every patch as quickly as possible. It is about prioritizing risks correctly, knowing which systems are affected, and closing critical vulnerabilities quickly.
And in September, that applies not only to Microsoft, but to the entire IT landscape. Security updates are routine. Getting the prioritization right determines how secure that routine really is.
%20-%20Teams%20Logo.png?width=576&height=182&name=Logo%20in%20standard%20arrangement%202%20(RGB)%20-%20Teams%20Logo.png)