September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows Microsoft's September 2026 Patch Tuesday release fixes 964 vulnerabilities, including two zero-days and a Windows DNS remote code execution flaw (CVE-2026-69730) that could be wormable, marking another record month since Microsoft began using AI to find holes. Dustin Childs of the Zero Day Initiative said AI-assisted bug discovery has 'exploded patch counts into a whole new galaxy,' and about 20 of the vulnerabilities could be wormable. Separately, SAP's Extended Passport Processing component has a critical vulnerability with a CVSS score of 10.0. Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep . The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party/open-source CVEs and 23 Chromium/Edge CVEs, as well as nine Microsoft mitigated vulnerabilities in applications like Azure, Entra, and Copilot Studio where no customer action is required. Separately, developers and SAP admins whose staff use SAP’s ABAP Advanced Business Application Programming should take action to close a critical vulnerability, with a CVSS score of 10.0, in the Extended Passport Processing EPP component. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application, say researchers at Onapsys. EPP is used in enterprise suites like SAP S/4Hana and NetWeaver to log document creation or trace end-to-end transactions. The two zero-days revealed today are: The sheer number of this month’s Microsoft patches stunned some experts. Dustin Childs https://www.linkedin.com/in/dustincchilds/ , head of threat awareness at the Zero Day Initiative, said, in a reference to the film 2001: A Space Odyssey , “looking at nearly 1,000 vulnerabilities in a single month, all I can think is: ‘My God, it’s full of stars.'” “AI-assisted bug discovery has exploded patch counts into a whole new galaxy,” he said, “and defenders simply have to embrace the suck.” About 20 of the vulnerabilities could be wormable bugs, he warned. “We haven’t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed https://nvd.nist.gov/vuln/detail/cve-2020-1350 , that reality could change fast.” That new vulnerability is CVE-2026-69730 https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-69730 , a Windows DNS remote code execution hole. As of Tuesday, it hadn’t yet been exploited, Microsoft said, but the company expects it will be. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system, with no authentication or user interaction required. Asked about vulnerabilities that could be wormed, Jack Bicer https://www.linkedin.com/in/bicer/ , Action1’s director of vulnerability research, drew attention to CVE-2026-62893 https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62893 , a Windows Deployment Services TFTP Server Remote Code Execution issue first patched in August, and CVE-2026-69590 https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-69590 , a Windows Routing and Remote Access Service Remote Code Execution. Neither requires authentication or user interaction. Because of this, he said, these types of vulnerability could spread quickly across a network if affected systems are not patched. Tyler Reguly https://www.fortra.com/profile/tyler-reguly , Fortra’s associate director of security R&D, pointed out that as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. “This is not a Microsoft-specific problem,” he noted. “We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing, as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed, and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key, and gift cards for extra coffee for your admins would likely be appreciated.” Bicer added that the scale of this month’s Microsoft releases requires security leaders to move beyond CVSS-driven patching and prioritize systems according to exploitability, network exposure, privilege requirements, business criticality, and the consequences of compromise. The most consequential risks, he said, are concentrated in remotely reachable infrastructure, identity and authentication services, database platforms, virtualization environments, and Windows components where successful exploitation could provide code execution or elevated privileges. “One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Bicer stressed. “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.” Researchers at Nightwing also noted that this week Adobe patched an actively exploited zero-day in Adobe Commerce and Magento CVE-2026-75650 https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146 , CVSS 10.0 , dubbed StyleSmuggler, which drops Linux backdoors and web shells. Adobe said “Urgent Action” is required. Fortinet confirmed ongoing active exploitation of older two authentication bypass vulnerabilities in FortiOS CVE-2024-55591 https://www.tenable.com/cve/CVE-2024-55591 and CVE-2025-24472 https://nvd.nist.gov/vuln/detail/cve-2025-24472 , allowing unauthenticated remote attackers to seize administrative control of edge firewalls. Cisco Systems addressed eight serious vulnerabilities https://www.csoonline.com/article/4219968/cisco-bundles-fixes-for-multiple-vulnerabilities-some-critical-into-one-patch-2.html across IOS XR systems while warning of active exploitation targeting an unauthenticated denial-of-service flaw in Secure Firewall ASA devices CVE-2026-20349 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF first described last month. Red Hat fixed a critical privilege escalation vulnerability in Advanced Cluster Management for Kubernetes 2 CVE-2026-10090 https://nvd.nist.gov/vuln/detail/cve-2026-10090 , CVSS 9.0, described last month that enables attackers to breach multi-tenant container boundaries; and Tenable resolved a critical flaw in Sensor Proxy protecting the core pipeline organizations rely on for security auditing CVE-2026-18667 https://nvd.nist.gov/vuln/detail/cve-2026-18667 , CVSS 9.6 that had permitted code execution with elevated privileges. Jonathan Stross, Pathlock’s senior product manager for cybersecurity R&I, noted that three of the Security Notes this month reach full compromise territory without a single valid credential. “That is an unusually concentrated cluster of unauthenticated, network-reachable, maximum-impact issues for a single Patch Day,” he said in a commentary https://pathlock.com/blog/sap-security-patch-day-september-2026/ . The critical hole plugged by SAP Security Note 3747649 https://me.sap.com/notes/3747649 is a memory corruption vulnerability in the Extended Passport Processing EPP component in ABAP-based systems. Researchers at Onapsis Research Labs, who discovered the vulnerability https://onapsis.com/blog/sap-security-patch-day-september-2026/ , have dubbed it OVERPASS. Boundary validation is missing during the deserialization of EPP data, resulting in a memory safety violation when processing externally supplied length fields. This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination. The SAP Security Note provides a patch for ABAP and Java kernels, and for SAP Web Dispatcher, version 9.16. Other Web Dispatcher versions and Web Dispatcher included in SAP S/4HANA Extended Application Services are not affected. Onapsys urged immediate patching, since the vulnerability exists by default in a wide range of SAP components, is exploitable remotely and without authentication, allows remote attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges that results in full compromise of the underlying SAP business data and processes, and is reachable through several SAP components and several communication protocols. None of these require credentials, Onapsys pointed out, so no single network control can fully mitigate risk. Onapsys also drew attention to SAP Security Note 3759472 https://me.sap.com/notes/3759472 , with a CVSS score of 9.8, in NetWeaver Message Server. This bug is the result of insufficient validation of the authenticity of internal application server components during registration. Consequently, unauthenticated attackers with network access can register unauthorized components and potentially perform unauthorized actions within the application environment. A successful exploitation could result in a high impact on the confidentiality, integrity, and availability of the affected system, SAP said. The vulnerability, which the Onapsis Research Labs is dubbing S4GET, is present across SAP’s entire modern kernel family 9.16, 9.18, 9.19, 9.20 , meaning every S/4HANA 2025 system, and any earlier release already moved to one of those kernels, is affected.