Patch Tuesday Dashboard

Assurance Security Dashboard: September 2026 Patch Tuesday

September 2026 Assurance Security Dashboard infographic: 963 CVEs across Windows, Browser, Developer Tools, Office, Exchange and SQL Server with 106 Critical and 2 zero-day flags

Microsoft’s September 2026 Patch Tuesday addresses 963 CVEs across the September security release. The infographic above summarises severity and risk level by product family; the prose below unpacks the items that need attention this cycle. 2 CVEs carry a zero-day flag (publicly disclosed and/or being exploited in the wild).

Microsoft’s own release note for September 2026 lists 974. The difference is 12 Azure cloud-side CVEs, which Microsoft patches in its own services, and one third-party entry. None of them require a customer to deploy anything, so this dashboard counts the 963 that do.

September 2026 Patch Tuesday: updates by product family

  • Windows - 77 Critical, 649 Important, top CVSS 9.8. Action: Patch Now.
  • Browsers - no updates this month.
  • Development - 1 Critical, 23 Important, top CVSS 9.6. Action: Patch Now.
  • Office - 24 Critical, 113 Important, top CVSS 9.8. Action: Patch Now.
  • Exchange - 9 Important, top CVSS 9.3. Action: Schedule.
  • SQL Server - 4 Critical, 58 Important, top CVSS 8.8. Action: Patch Now.

Notable CVEs this cycle

  • CVE-2026-81963 (Windows) - Exploited, CVSS 7.8.
  • CVE-2026-85880 (Windows) - Exploited, CVSS 7.8.

Patch now: Windows, Development, Office, SQL Server. Critical-rated or actively exploited vulnerabilities drive these into the immediate-action queue.

Schedule: Exchange. Important-rated vulnerabilities to roll into the regular monthly update cycle.

Every patch, every platform change, every application update is a risk-based decision under uncertainty. Readiness Assurance turns that uncertainty into prescriptive guidance - where applications are scanned, tested, documented, and delivered with certainty into production.