Microsoft's September 2026 Patch Tuesday is one of the largest in recent history, addressing 421 vulnerabilities across the Microsoft product portfolio. Critically, one of these vulnerabilities is a zero-day that is actively being exploited in the wild.
The Zero-Day: Microsoft Edge Chromium RCE
The actively exploited zero-day affects Microsoft Edge (the Chromium-based version). The vulnerability allows a remote attacker to achieve remote code execution by enticing a user to visit a malicious website. No user interaction beyond visiting the site is required — the exploit triggers automatically upon page load.
This is particularly dangerous because Microsoft Edge is the default browser on Windows 10 and Windows 11, meaning a vast installed base is potentially vulnerable.
Breakdown of the 421 CVEs
The September 2026 Patch Tuesday covers vulnerabilities across:
- Microsoft Edge (Chromium): multiple vulnerabilities including the zero-day
- Windows Operating System: kernel, networking stack, and subsystem vulnerabilities
- Microsoft Office: memory corruption and privilege escalation flaws
- Azure services: multiple Azure component vulnerabilities
- Exchange Server: remote code execution and information disclosure flaws
- SharePoint Server: authentication bypass and information disclosure
- SQL Server: elevation of privilege vulnerabilities
- Visual Studio: multiple security issues
- Windows Defender: security feature bypass
Other Notable Vulnerabilities
Beyond the zero-day, several high-severity vulnerabilities were patched:
- Multiple Windows kernel elevation of privilege flaws
- Exchange Server remote code execution vulnerabilities
- Azure Active Directory authentication bypass
- .NET Framework information disclosure
Recommendations
- Apply the September 2026 security updates immediately
- Prioritize the Microsoft Edge update — the zero-day is under active exploitation
- Enable automatic updates where possible
- Review Microsoft's security update guide for a complete list of affected products
- Test updates in a staging environment before broad deployment (if enterprise environment)
Patch Tuesday Context
September 2026's 421 CVEs represent one of the highest counts in recent Patch Tuesday cycles. Security teams should budget additional time for testing and deployment given the volume. The presence of an actively exploited zero-day makes this an urgent patch cycle.