Microsoft's latest update fixes hundreds of security issues, but several high-severity flaws affecting Exchange and other products are likely to draw the most attention from security teams.
Key Takeaways:
Microsoft has released the September 2026 Patch Tuesday Updates for all supported versions of Windows 11 and Windows 10. This month, the company rolled out 974 patches to address several vulnerabilities in Windows, Office, Azure, Active Directory, Exchange Server, Remote Desktop Client and Server, SQL Server, Windows Hello, Microsoft Defender, and other components.
Microsoft has already fixed 2,760 vulnerabilities this year, which is more than double the number from 2025. On the quality and experience update front, Microsoft has released several improvements for Windows 11 versions 26H1 as well as 25H2 and 24H2.
According to the Zero Day Initiative, Microsoft has fixed 114 security flaws rated as “Critical,” with the rest being rated Important in terms of severity. Here’s a list of the most notable vulnerabilities Microsoft addressed in September:
You can find the full list of CVEs addressed in the September 2026 Patch Tuesday Updates below:
| Product Family | Updates per Product/Version | Vulnerabilities Addressed | Distinct Updates | Type of Update |
| Azure | 1 | 29 | 15 | Individual |
| Defender | 1 | 2 | 1 | Cumulative |
| Developer Tools | 1 | 27 | 36 | Cumulative |
| Edge | 1 | 16 | 1 | Cumulative |
| Exchange Server | 1 | 8 | 4 | Cumulative |
| Office | 1 | 99 | 11 | Cumulative (except 2016) |
| Office 2016 | 1 | 99 | 18 | Individual |
| Other | 1 | 9 | 4 | Individual |
| SharePoint Server | 1 | 30 | 3 | Cumulative |
| Windows | 1 | 240 | 32 | Cumulative |
Microsoft released the KB5124008 update for PCs running Windows 11 versions 26H1 and 25H2/24H2. This release brings additionalhigh-confidencee device targeting data, which increases coverage of devices eligible to automatically receive new Secure Boot certificates. Microsoft will continue certificate deployment through Windows updates across supported PCs and non-managed business devices in the next few months.
The KB5124008 update enhances the diagnostics logging experience for the OMA-DM client. It provides additional information to help troubleshoot device management server connection issues. Microsoft has also fixed a bug that could cause Microsoft Outlook and Teams to unexpectedly close on Arm64-based PCs.
Microsoft advises organizations to perform thorough testing to confirm that updates do not compromise the stability of their production systems. However, it is crucial to deploy Patch Tuesday updates to proactively address potential threats.
Additionally, IT administrators must prioritize backing up their systems before applying updates, utilizing the built-in backup features of Windows and Windows Server. These features allow for the restoration of specific files and folders or entire systems as required.
Last but not least, organizations should consistently monitor their systems for anomalies or unexpected behaviors. Regular monitoring is essential for staying vigilant against emerging risks and adopting appropriate security measures.