{"slug": "september-2026-patch-tuesday-9-critical-cves-patch-now", "title": "September 2026 Patch Tuesday: 9 Critical CVEs — Patch Now", "summary": "Microsoft's September 2026 Patch Tuesday addresses 9 Critical vulnerabilities, including two CVSS 10.0 flaws, one of which is an unauthenticated Azure AI Language endpoint issue, and CVE-2026-62916 (CVSS 9.1), an authentication bypass in Microsoft Entra that was already exploited in the wild before the patch shipped.", "body_md": "Microsoft’s September 2026 Patch Tuesday fixes 9 vulnerabilities — all of them Critical. On paper, that sounds manageable after August’s 421-CVE pile-up. In practice, one of these nine was already being exploited in the wild before the patch shipped. The others include two CVSS 10.0 flaws — the worst possible score — one of which simply had no authentication at all on an Azure AI Language endpoint. The “quiet month” framing you’ll see elsewhere is wrong. Patch, audit your logs, and read on. The CVE That Was Already Being Exploited CVE-2026-62916 (CVSS 9.1) is an authentication bypass in Microsoft Entra […]\n\nThe post", "url": "https://wpnews.pro/news/september-2026-patch-tuesday-9-critical-cves-patch-now", "canonical_source": "https://byteiota.com/september-2026-patch-tuesday-9-critical-cves/", "published_at": "2026-09-08 15:13:51+00:00", "updated_at": "2026-09-08 15:25:57.281467+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety"], "entities": ["Microsoft", "Azure AI Language", "Microsoft Entra", "CVE-2026-62916"], "alternates": {"html": "https://wpnews.pro/news/september-2026-patch-tuesday-9-critical-cves-patch-now", "markdown": "https://wpnews.pro/news/september-2026-patch-tuesday-9-critical-cves-patch-now.md", "text": "https://wpnews.pro/news/september-2026-patch-tuesday-9-critical-cves-patch-now.txt", "jsonld": "https://wpnews.pro/news/september-2026-patch-tuesday-9-critical-cves-patch-now.jsonld"}}