Microsoft’s September 2026 Patch Tuesday addressed 966 vulnerabilities, including two zero-day vulnerabilities that are already being actively exploited.
The release includes 105 Critical vulnerabilities, 81 of which allow remote code execution across Windows, Windows Server, Microsoft Office and Excel.
Organisations should prioritise the known exploited vulnerabilities, followed by Critical vulnerabilities affecting internet-facing or network-accessible systems and widely deployed enterprise software.