Hacker News September 9, 2026

Microsoft September 2026 Patch Tuesday: 421 CVEs Fixed, One Zero-Day Under Exploitation

Microsoft's September 2026 Patch Tuesday is one of the largest in recent history, addressing 421 vulnerabilities across the Microsoft product portfolio. Critically, one of these vulnerabilities is a zero-day that is actively being exploited in the wild.

The Zero-Day: Microsoft Edge Chromium RCE

The actively exploited zero-day affects Microsoft Edge (the Chromium-based version). The vulnerability allows a remote attacker to achieve remote code execution by enticing a user to visit a malicious website. No user interaction beyond visiting the site is required — the exploit triggers automatically upon page load.

This is particularly dangerous because Microsoft Edge is the default browser on Windows 10 and Windows 11, meaning a vast installed base is potentially vulnerable.

Breakdown of the 421 CVEs

The September 2026 Patch Tuesday covers vulnerabilities across:

Other Notable Vulnerabilities

Beyond the zero-day, several high-severity vulnerabilities were patched:

Recommendations

Patch Tuesday Context

September 2026's 421 CVEs represent one of the highest counts in recent Patch Tuesday cycles. Security teams should budget additional time for testing and deployment given the volume. The presence of an actively exploited zero-day makes this an urgent patch cycle.