September 2026 Patch Tuesday Breaks Records: 973 Vulnerabilities, 113 Critical
What happened
Microsoft's September 2026 Patch Tuesday shipped fixes for 973 vulnerabilities, including 113 rated critical, according to the SANS Internet Storm Center. This is the largest Patch Tuesday release to date, surpassing the previous record of 664 vulnerabilities set in July 2026.
Per ISC, two vulnerabilities are listed as exploited in the wild, and none were publicly disclosed prior to release. Notable fixes cited include Windows privilege escalation issues and critical remote code execution (RCE) vulnerabilities in Skype for Business, MSMQ, and RRAS.
Why it matters
The sheer volume of this release raises the operational burden for patch management teams: triage, testing, and deployment windows will be stretched thin, and the two actively exploited flaws mean prioritization can't wait for a full staged rollout. MSMQ and RRAS RCEs are particularly notable because both services are often exposed on internal networks and, in some configurations, to the internet, making them attractive targets for lateral movement or initial access. Skype for Business RCEs matter for organizations that still run on-prem deployments rather than cloud-hosted Teams.
What defenders should do now
- Identify and prioritize patching for the two vulnerabilities confirmed as exploited in the wild — check Microsoft's Security Update Guide for the specific CVE IDs and affected versions.
- Inventory exposure to MSMQ and RRAS specifically; where these services aren't required, consider disabling them rather than relying solely on patching.
- Review privilege escalation fixes in the context of endpoint detection — look for anomalous local privilege escalation attempts (unexpected token manipulation, service creation, or process elevation) on Windows hosts as a general hunting angle while patches roll out.
- Given the scale of this release, consider a risk-based rollout: prioritize internet-facing and high-value assets first, and validate patch deployment status across the fleet before considering the cycle closed.
Developing story
Details on the specific CVE identifiers, affected product versions, and exploitation context for the two in-the-wild vulnerabilities were not included in the source summary. This is based on the SANS ISC diary published September 8, 2026, and should be treated as developing intel — check the original source for the full breakdown of individual CVEs: SANS ISC: September 2026 Microsoft Patch Tuesday.