Microsoft Patch Tuesday 2026: Record 974 CVEs Released, Including Actively Exploited Flaws
Two vulnerabilities are under active exploitation, with 58 additional flaws rated as more likely to be targeted, Microsoft reports.

Key Takeaways
- Microsoft's September 2026 Patch Tuesday addressed a record 974 CVEs in a single update cycle.
- Two vulnerabilities are confirmed to be actively exploited in the wild.
- A further 58 vulnerabilities are assessed as more likely to be exploited.
- Affected products include Windows, Office, Exchange Server, and Azure.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


