Brief
Microsoft's September 2026 Patch Tuesday Fixes Record 973 Vulnerabilities
Microsoft released patches for a record-breaking 973 vulnerabilities in its September 2026 Patch Tuesday, including 113 rated critical and two exploited in the wild.
Microsoft released patches for a record-breaking 973 vulnerabilities in its September 2026 Patch Tuesday, including 113 rated critical. It is the largest Patch Tuesday to date, ahead of the previous high of 664 set in July 2026.
Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical remote code execution flaws in Skype for Business, MSMQ and RRAS.
Our reading
Our view is that small teams running Windows, Skype for Business, MSMQ or RRAS should prioritize these updates, given the exploited-in-the-wild flaws and critical remote code execution vulnerabilities.
What to do or watch
Check whether your environment runs the products named in the notable fixes — Windows, Skype for Business, MSMQ and RRAS — and apply this month's updates, given the two exploited-in-the-wild flaws. The unresolved question is which two vulnerabilities are being exploited and whether they sit in those specific products, since the source does not say.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by SANS Internet Storm Center
- Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical.
- It is the largest Patch Tuesday to date, ahead of the previous high of 664 set in July 2026.
- Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday.
- Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
Sources
- SANS Internet Storm CenterText stored 14 September 2026
How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.
What that means
- 4 of 4 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief