Cybersecurity Research

Microsoft's Biggest Patch Tuesday Ever: 972 Fixes Include Two Actively Exploited Flaws

CrowdStrike · 8 Sept 2026
Key Takeaway Prioritise patching internet-facing services and Office-related Critical vulnerabilities immediately, since several can be exploited without any user action.

Microsoft has released its largest Patch Tuesday update on record, fixing 972 vulnerabilities in September 2026, more than double August's total. Among these are two zero-day vulnerabilities that attackers are already exploiting, plus 113 flaws rated Critical. A separate proof-of-concept exploit against Microsoft Defender, called ShieldCrash, was also disclosed, though it is not part of this month's official patch set.

The most common issue types this month are elevation of privilege (437 patches), remote code execution (258 patches), and information disclosure (171 patches). Microsoft Office alone received 22 Critical patches, 12 of which can be triggered simply by previewing a malicious file in Preview or Reading Pane, meaning no click or macro approval is needed for an attacker to gain code execution. This type of flaw is popular with both mass phishing campaigns and targeted attackers because it removes the need to trick a user into taking action.

Separately, at least 17 vulnerabilities allow unauthenticated remote code execution across core network services such as DNS, DHCP, MSMQ, NFS, and SSTP VPN. These let attackers run code on exposed systems without needing a username, password, or any user interaction, making unpatched, internet-facing instances an easy target for automated scanning.

Summarised by CISO AI from CrowdStrike. We link back to every original so you can read it yourself.