Cybersecurity Research

September Patch Tuesday: Microsoft Fixes 973 Vulnerabilities in Massive Update

Sophos · 16 Sept 2026
Key Takeaway Small businesses should prioritise applying this month's Microsoft, Chrome, and Adobe patches promptly, focusing first on Critical-severity fixes to reduce exposure to likely exploitation.

Microsoft's September 9 Patch Tuesday release addressed 973 vulnerabilities across 39 product families, one of the largest monthly totals in recent memory. Of these, 114 are rated Critical severity, 58 are expected to be exploited within 30 days, and 284 carry a CVSS Base score of 8.0 or higher. None of the issues were publicly disclosed before the patches were released, which is a positive sign, though the sheer volume presents a significant workload for IT teams.

The update arrived alongside other major releases: Google's Chrome team issued 24 Edge-related patches just before Patch Tuesday, and Adobe released 21 patches for Acrobat. A notable advisory came from the OpenSSL Software Foundation regarding CVE-2026-34182, a high-severity flaw (CVSS 9.1) involving improper validation of integrity-check values in CMS data containers. Separately, nine Microsoft CVEs affecting cloud services such as Azure, Entra, Copilot, and Power Automate were already patched before the official release date, meaning administrators do not need to take action on those specific items, though they are counted in the month's overall statistics.

These nine pre-patched cloud vulnerabilities carried an average CVSS score of 9.0, notably higher than the 7.4 average across the remaining 964 CVEs, underscoring the severity of cloud-focused threats this cycle. Businesses relying on Microsoft products, browsers, or Adobe software should prioritise reviewing this month's patches given the scale and criticality involved.

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.