Microsoft’s September 2026 Patch Tuesday fixes 9 vulnerabilities — all of them Critical. On paper, that sounds manageable after August’s 421-CVE pile-up. In practice, one of these nine was already being exploited in the wild before the patch shipped. The others include two CVSS 10.0 flaws — the worst possible score — one of which simply had no authentication at all on an Azure AI Language endpoint. The “quiet month” framing you’ll see elsewhere is wrong. Patch, audit your logs, and read on. The CVE That Was Already Being Exploited CVE-2026-62916 (CVSS 9.1) is an authentication bypass in Microsoft Entra […]
The post