Microsoft just set a record — and not the kind anyone wants to celebrate.
The September 2026 Patch Tuesday release fixed nearly 1,000 vulnerabilities across Windows, Office, SQL Server, Exchange, and more. Two of them were already being actively exploited before the patches were even released. Adobe released its own round of critical patches on the same day, including one vulnerability that received a perfect 10.0 severity score.
Vulnerabilities are scored on a scale of 1 to 10 based on how easy they are to exploit and how much damage they can cause. A 10 means an attacker can use the flaw remotely, without a password, without any help from the victim, and gain complete control of the affected system. A 7 or 8 is still serious — it just means there is some additional step required, like being on the same network or having a basic account. Anything rated Critical by Microsoft (generally 9.0 and above) should be treated as urgent.
If your computers and software are not updated, you are exposed. This month is not a normal patch cycle.
What Microsoft Released
Microsoft addressed somewhere between 972 and 1,169 vulnerabilities depending on which tracking service you follow, making it the largest single Patch Tuesday release on record. Of those, 113 are rated Critical — the highest severity classification Microsoft issues. The rest range from Important to Moderate, but that does not mean they are safe to ignore.
The two vulnerabilities already under active exploitation are both elevation-of-privilege flaws: one in Windows Advanced Local Procedure Call (CVE-2026-85880) and one in the Windows Update Stack itself (CVE-2026-81963). Elevation-of-privilege means that an attacker who is already on your system — through phishing, a compromised password, or another method — can use these flaws to gain full administrative control. That is the last thing you want happening on a machine with access to client files, financial data, or email.
Beyond the zero-days, the list of critical remote code execution vulnerabilities is long and covers software that most businesses use every day. A few worth knowing about:
Windows Shell has a remote code execution vulnerability rated 9.8 out of 10; Windows DNS Server has one rated 9.8; Windows Deployment Services has one rated 9.8. Skype for Business has one rated 9.8. Microsoft Word has a remote code execution flaw rated 8.8. Windows SMB — the file-sharing protocol that connects computers on a network — has two remote code execution vulnerabilities rated 8.8.
Remote code execution means an attacker can run malicious software on your machine without being physically present and, in some cases, without you doing anything at all. The SMB vulnerabilities are particularly worth noting because SMB is turned on by default in most Windows environments.
There is also a separately disclosed proof-of-concept exploit called “ShieldCrash” targeting Microsoft Defender. Microsoft has not issued a patch for it yet, but researchers have demonstrated it works. That one bears watching.
What Adobe Released
Adobe pushed patches on the same day for Acrobat and Reader (APSB26-141), Adobe Commerce and Magento (APSB26-138), and Adobe Campaign (APSB26-142).
The most serious of the bunch is a vulnerability in Adobe Commerce and Magento Open Source that received a CVSS score of 10.0 — a perfect severity rating, which is as bad as it gets. The flaw (CVE-2026-75650) allows an attacker to execute arbitrary code on the affected server without any authentication. No password needed, no user interaction required. Adobe actually released an emergency patch for this one on September 7, a day before the regular update cycle, because it was that urgent. If your business runs an Adobe Commerce or Magento storefront, this needs to be addressed today.
Acrobat and Reader patches are relevant to nearly every business. These files move through email constantly, and a vulnerability in the PDF reader is a reliable attack vector because the files look harmless and people open them without thinking.
This Means for Your Business
The practical reality is that software vulnerabilities are discovered every day. The vendors patch them on a schedule. The attackers know that schedule too, and they start working on exploits the moment patches are released — because that is when they know what vulnerability is. The window between “patch released” and “attackers actively exploiting it” gets shorter every year.
Two of this month’s vulnerabilities were already being exploited before the patches came out. That is the worst-case scenario, and it happened twice in one month.
Unpatched machines are not just a theoretical risk. They are machines with an unlocked door that gets listed in a catalog that attackers share with each other.
What to Do
If your IT is managed by a provider, check in with them to confirm this month’s patches are being deployed. A good provider is already on it, but it does not hurt to ask.
If you manage your own computers and software, now is the time to act. On a Windows machine, go to Settings > Windows Update and check for updates, and make sure automatic updates are turned on. For Adobe products, open the application and look for an update option, or visit Adobe’s website directly.
Do not put it off. The two zero-days in this release are already being used. The attackers are not waiting.
Amicus IT manages patching for all of our managed clients as a standard part of our service. If you have questions about your patch status or want to know more about managed IT services, contact us.