Security news
Latest security news
Wed, 9 Sept 2026
- Microsoft breaks Patch Tuesday record with 974-CVE deluge
Adobe also brought goodies to the patch party and they deserve immediate attention
The RegisterMicrosoft, Adobe
Tue, 8 Sept 2026
- Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure.
CyberScoopMicrosoft - Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Cisco TalosMicrosoft - Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Krebs on SecurityMicrosoft, Windows - Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today. Windows ALPC: zero-day EoP The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the battle is centered on the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel capability that facilitates inter-process communication. Microsoft is aware of exploitation in the wild already. Successful abuse of the flaw underlying CVE-2026-85880 grants an attacker SYSTEM via a buffer overflow that enables an out-of-bounds write, and as we all know by now, this is exactly what would happen duri
CriticalUsed in attacksRapid7 BlogMicrosoft, Windows - Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Dark ReadingMicrosoft - OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
The Register - Feds accuse China of ‘systematic’ distillation of U.S. AI models
A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms.
CyberScoop - The EU CRA's Real Question: What Shipped, and When Did You Know?
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements.
BleepingComputer - Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
BleepingComputerF5, Linux
About this news
- 1,265
- Stories
- 23
- Added in the last 24 hours
- 13
- Critical in the last 7 days
- 4
- Reported by several outlets