974 CVEs in one Patch Tuesday: patch capacity is the constraint, not patch knowledge
The scale of the September 2026 release
Microsoft's September 2026 security release covered 974 vulnerabilities according to FreeBuf's count, with Windows accounting for 723 of them and Office for a further 222. A separate tally records 973 entries carrying severity ratings, of which 113 were rated critical and 860 important.
Those two numbers differ by one, which is a useful reminder that even batch totals depend on how a publisher counts. What is consistent across the coverage is the shape of the month: privilege escalation and remote code execution together account for more than seventy percent of the fixes, and 258 remote code execution and 438 privilege escalation entries were listed in one breakdown.
Tenable's comparison puts the trend in context, reporting roughly 964 CVEs for September against 569 in July. ZDI's threat awareness lead described the batch as a field of stars, and attributed the volume partly to AI-assisted discovery.
Why volume alone does not set the order
Two flaws in the batch were already exploited: the ALPC sandbox escape CVE-2026-85880 and the Windows Update stack link flaw CVE-2026-81963. Twenty entries were rated wormable remote code execution, with Windows DNS Server, DHCP, Remote Desktop Services, SMB and Netlogon among the affected components. The DNS Server flaw CVE-2026-69730 draws specific attention in that group because DNS servers are usually reachable and often run on domain controllers.
Adobe's release in the same month is part of the same problem. It covered 172 CVEs including an exploited zero-day in Magento and Adobe Commerce tracked as CVE-2026-75650, which allowed unauthenticated code injection through a template and affected versions 2.4.4 through 2.4.9, with exploitation observed from 2026-09-04.
Where patch capacity actually runs out
Every organisation has a finite number of maintenance windows, reboot tolerances and change approvals. When the monthly batch grows faster than that capacity, the queue becomes the risk, and the practical question shifts from whether a flaw is severe to which flaws can be deferred without accepting a specific consequence.
Three filters are worth applying deliberately. First, exploited in the wild, which is a fact rather than a forecast. Second, reachable and unauthenticated, which covers network-facing services on hosts that hold identity data. Third, an elevation-of-privilege flaw on a system that already has a lower-privilege foothold somewhere in the estate, because the combination is what the exploitation reports actually describe.
Everything else can be scheduled. A severity score alone cannot make that call, because a 7.8 elevation flaw on a domain controller is a larger problem than a 9.8 in a component nobody runs.
Where the limits are
A batch size is not a measure of exposure, and none of the coverage suggests that every entry was weaponised. The two confirmed exploited flaws are named specifically. Treating the remainder as equally urgent is as unhelpful as deprioritising the whole batch, and the difference between those two positions is an inventory that says what you actually run.
References
- FreeBuf: Microsoft's largest Patch Tuesday covers 974 CVEs, two exploited zero-days and 20 wormable flaws
- Electronic Enthusiast: 973 rated entries, 113 critical, 860 important
- InfoQ: Microsoft patches more than a thousand vulnerabilities in a single month
- Analysis of the September 2026 Microsoft patch release and the DNS Server risk
- Anheng bulletin covering the Microsoft release, Adobe's 172 CVEs and the Magento zero-day CVE-2026-75650
Top comments (0)