The Microsoft Patch Day in September is a major one: More than 950 vulnerabilities have been fixed — Microsoft's largest patch release to date. Particularly critical: Two zero-day vulnerabilities are already being actively exploited. The September 2026 update addresses more than 950 security vulnerabilities. Two of them are zero-days and are already being actively exploited.
And Microsoft is not alone. SAP, Adobe, and Cisco also disclosed critical security vulnerabilities in September. For IT teams, this means: Patch, prioritize, and check affected systems now.
Microsoft’s Patch Tuesday is unusually extensive this month, with more than 950 vulnerabilities addressed. Two of them deserve particular attention. Both allow Elevation of Privilege, enabling attackers to escalate existing user permissions potentially up to full system control:
The sheer number of vulnerabilities stands out. One possible reason is Microsoft’s increased use of AI-powered systems to identify security flaws, allowing vulnerabilities to be detected faster and at greater scale. For businesses, this does not mean every CVE requires immediate action. What matters is prioritizing vulnerabilities based on actual risk. For the two Windows vulnerabilities mentioned above, the situation is clear: they are already being actively exploited.
Not every one of the 950+ Microsoft vulnerabilities is equally relevant to every organization. It depends on the environment. IT teams should therefore focus on these key questions:
Are the affected Windows versions in use?
Are clients and servers fully patched?
Are there systems where updates are being delayed?
Are there signs of unusual activity or a potential compromise?
Do particularly critical systems require additional protection?
Especially with actively exploited zero-days, do not wait for the regular patch cycle to catch up.
September is an unusually busy month for security updates beyond Microsoft. Other critical enterprise systems are affected as well.
CVE-2026-44756 (OVERPASS) | CVSS 10.0 – Critical. Memory corruption in SAP Extended Passport (EPP) processing. A missing bounds check during the deserialization of EPP data allows an unauthenticated attacker to trigger memory corruption over the network. Potential impacts include:
Arbitrary code execution with administrative privileges
Credential theft
Manipulation of SAP data
Modification of SAP binaries
There is currently no public confirmation of active exploitation. However, due to its CVSS score of 10.0, unauthenticated attack vector, and potential administrative impact, this vulnerability should be treated as the highest SAP priority in this patch cycle.
CVE-2026-58240 (S4GET) | CVSS 9.8 – Critical. Missing authentication in the SAP NetWeaver Message Server. The Message Server does not adequately verify the authenticity of application components during registration. An unauthenticated attacker with network access could register a malicious component and perform unauthorised actions within the SAP environment. There are currently no indications of active exploitation for this vulnerability either.
The situation at Adobe is particularly urgent. Adobe has released an emergency fix outside its regular update cycle for a critical zero-day vulnerability affecting its e-commerce platforms.
CVE-2026-75650 (StyleSmuggler) | Critical. Arbitrary code execution in Adobe Commerce and Magento Open Source. Adobe confirms that the vulnerability is already being actively exploited. Observed attacks include the installation of backdoors on affected servers. In one case, a backdoor was disguised as legitimate NTP traffic. Another attacker deployed a PHP web shell. Affected products include:
Adobe Commerce 2.4.4 through 2.4.9
Adobe Commerce B2B 1.3.3 through 1.5.3
Magento Open Source 2.4.6 through 2.4.9
Network infrastructure is not spared either: CVE-2026-20212 | CVSS 9.8 – Critical. Remote code execution in Cisco Nexus 9000 Series switches.
The vulnerability affects certain Nexus 9000 switches equipped with Silicon One ASICs. Two TCP ports – 43210 and 43211 – are accessible within the default Layer 3 VRF. An unauthenticated attacker could send crafted input and potentially execute code with root privileges. A successful attack could also crash the affected process and cause the switch to restart.
Cisco has not identified any active exploitation or public proof of concept so far. Due to the severity and potential impact, Cisco is providing both a permanent fix and a temporary Live Protect mitigation.
Not every vulnerability needs to be addressed at the same speed. The key question is: Which vulnerabilities are relevant to your environment, and which are already being actively exploited? For September, we recommend the following order:
Microsoft’s September 2026 Patch Tuesday is a good opportunity to take a critical look at your own patch management process. More than 950 Microsoft vulnerabilities is a lot. For businesses, the goal is therefore not to blindly install every patch as quickly as possible. It is about prioritizing risks correctly, knowing which systems are affected, and closing critical vulnerabilities quickly.
And in September, that applies not only to Microsoft, but to the entire IT landscape. Security updates are routine. Getting the prioritization right determines how secure that routine really is.