september 2026 exploits

What's happened since August Patch Tuesday

It's been an active month between cycles. Since Microsoft's August 11 release, five Microsoft CVEs have been confirmed exploited in the wild, and Google shipped an emergency Chrome fix for a sixth 2026 zero-day. None of this is theoretical — all six are on CISA's Known Exploited Vulnerabilities catalogue today, and two carry active nation-state attribution. Before we get into today's release, here's what defenders should already have handled — or should escalate immediately if not:

Microsoft — confirmed exploited since (and including) the August release:

  • CVE-2026-68820 — Windows Ancillary Function Driver for WinSock (afd.sys), Elevation of Privilege. Important, CVSS 7.0. A use-after-free flaw lets a locally authenticated attacker win a race condition and elevate to SYSTEM. Confirmed exploited in the wild as of the August release; Check Point Research ties active exploitation to the Lazarus group's Operation Dream Job campaign, deploying a new build of the FudModule kernel rootkit. Patch available: August 11, 2026 (added to CISA KEV the same day it was disclosed). Confirm deployment if you haven't already.
  • CVE-2026-33824 — Windows Internet Key Exchange (IKE) Service Extensions, Remote Code Execution. Critical, CVSS 9.8. A double-free vulnerability that's wormable and unauthenticated. Patch available: April 14, 2026 — this one sat patched for over four months before CISA confirmed active exploitation and added it to KEV on August 18, 2026. If this is still outstanding anywhere in your environment, it's been exploitable in the wild for weeks with a fix that's been sitting in the update console since spring.
  • CVE-2026-55040 — Microsoft SharePoint Server, Security Feature Bypass (weak authentication). Critical, CVSS 9.1. Patch available: July 14, 2026 (July Patch Tuesday). Exploitation began within hours of Rapid7's August 11 public technical write-up; added to CISA KEV August 18. This flaw is also being chained with CVE-2026-63520 (patch available August 11, 2026 — August Patch Tuesday) for authentication bypass followed by remote code execution — both patches are required to close the full chain.
  • CVE-2019-1068 — Microsoft SQL Server, Remote Code Execution. Patch available: July 9, 2019. Re-added to CISA's KEV catalogue August 26, 2026 based on renewed evidence of active exploitation, despite being a six-year-old CVE. A reminder that "old" doesn't mean "safe to deprioritize" — this patch has been available for years.
  • CVE-2026-62832 — Windows User Profile Service, Elevation of Privilege. Important, CVSS 7.8. Publicly disclosed prior to patch availability during the August cycle and assessed by Microsoft as "Exploitation More Likely." Not confirmed exploited and not on CISA's KEV catalogue as of this writing, so no KEV patch-availability date applies — included here given the elevated risk assessment.

Google Chrome — confirmed exploited since August Patch Tuesday:

  • CVE-2026-85046 — Chrome V8 JavaScript/WebAssembly engine, Type Confusion. High severity, CVSS 8.8. Crafted web content can trigger arbitrary read/write inside Chrome's sandbox, potentially leading to code execution. Google confirmed an exploit existed in the wild at the time of patching. Patch available: September 3, 2026 (Chrome 152.0.7977.82/.83) — this is Chrome's sixth confirmed exploited zero-day of 2026, and the third targeting V8 specifically. Added to CISA KEV: September 4, 2026, with an FCEB remediation deadline of September 18. Microsoft Edge, Brave, Opera, and Vivaldi all inherit the underlying Chromium flaw and require their own vendor updates.

If any of the above are still outstanding in your environment, treat them as higher priority than anything in today's release — confirmed exploitation beats CVSS score every time.

Today's Microsoft release

Microsoft's September 2026 Patch Tuesday resolves 973 CVEs — one of the largest single releases of the year — including 119 rated Critical and two zero-days, both confirmed exploited in the wild (CVE-2026-85880, CVE-2026-81963).

Known exploited / zero-day vulnerabilities (today's release)

  • CVE-2026-85880 — Heap-based buffer overflow in Windows ALPC (Advanced Local Procedure Call), Elevation of Privilege. High severity, CVSS 7.8 / 6.8. Allows an authorised local attacker with low privileges to elevate to SYSTEM with no user interaction required. Affected products: Windows 10, Windows 11, Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022 — effectively the entire supported Windows Server and desktop fleet. Microsoft's advisory lists this as exploited in the wild. Patch available today, September 8, 2026.
  • CVE-2026-81963 — Elevation of Privilege. CVSS 7.8 / 7.2. Affected products: Windows 11, Windows Server 2025. Successful exploitation could allow an attacker to gain SYSTEM privileges. Microsoft's advisory lists this as exploited in the wild. Notably narrower blast radius than CVE-2026-85880 — only the newest OS releases are affected, so environments still on Windows 10 or older Server builds are not exposed to this particular flaw, though they remain exposed to CVE-2026-85880 above. Patch available today, September 8, 2026.

Third-party vulnerabilities

Adobe: Adobe released 10 security bulletins between September 7–8, 2026, resolving roughly 161 CVEs in total. Updates affect: Experience Manager (APSB26-98), ColdFusion (APSB26-119), Photoshop (APSB26-130), Illustrator (APSB26-131), Animate (APSB26-132), Photoshop Mobile (APSB26-136), Commerce (APSB26-138 — a second, routine Commerce bulletin separate from yesterday's zero-day fix), Acrobat and Reader (APSB26-141), and Campaign Classic (APSB26-142). The zero-day, CVE-2026-75650 in Adobe Commerce (APSB26-146, published September 7 — unauthenticated arbitrary code execution, already exploited to backdoor online stores), remains the standout item and should keep its own lead callout separate from today's routine batch.

Mozilla: Firefox 155, released September 1, resolved 29 vulnerabilities, 13 rated critical. No evidence of in-the-wild exploitation on any of them. Firefox for iOS released on September 8 resolving one CVE that is rated low severity.

Chrome/Edge: Chrome 152.0.7977.82/.83 addressed 12 vulnerabilities total in the September 3, 2026 release, including the actively exploited CVE-2026-85046. Edge, Brave, Opera, and Vivaldi updates should follow on their own vendor timelines.

Ivanti September 2026 Security Update

Ivanti disclosed 10 CVEs across three products today, September 8, 2026: Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry. Ivanti states it has no evidence of active exploitation for any of these vulnerabilities prior to disclosure.

  • Ivanti Neurons for ITSM resolved eight CVEs. Cloud/SaaS customers were already protected — Ivanti applied the fix to all cloud landscapes on August 9, 2026. On-premises admins should apply the September 2026 Security Patch for their version now via the Ivanti Licence Server (ILS); on-premises 2026.2 will ship with the fix built in when it releases September 21, 2026.
  • Ivanti Endpoint Manager Mobile (EPMM) resolved one CVE. Affects versions 12.9.0.1 and earlier, 12.8.0.3 and earlier, and all builds prior to 12.10.0.0. Fixed in 12.10.0.0, 12.9.0.2, and 12.8.0.4.
  • Ivanti Sentry resolved one CVE. Affects R10.8.1, R10.7.2, R10.6.3, and earlier. Fixed in R10.8.2, R10.7.3, and R10.6.4. Also relevant to Sentry deployments managed through EPMM and Neurons for MDM.

September update to-do list

  1. Patch Adobe Commerce (CVE-2026-75650) immediately as it is under active exploitation right now, independent of today's Patch Tuesday.
  2. Confirm the five Microsoft CVEs and one Chrome CVE listed in the "since August" section above are closed in your environment — these predate today's release but remain the highest-confidence exploited risks outstanding.
  3. Patch immediately due to active exploitation: CVE-2026-85880 affects the entire Windows fleet (10, 11, Server 2012–2022) — prioritise across the board. CVE-2026-81963 is narrower (Windows 11 and Server 2025 only) but no less urgent for environments running those builds. Both are confirmed exploited zero-days in today's release and take priority over the rest of the Microsoft batch.
  4. Push Windows OS + Office updates to resolve the bulk of the remaining 973 CVEs; with 119 Critical this month, prioritise internet-facing and user systems first.
  5. Prioritise browser updates (Chrome, Firefox, Edge) on a weekly cadence regardless of severity.