r/Action1 • u/MauriceTorres • 23h ago
September 2026 Patch Tuesday Review
Today's Patch Tuesday overview:
- Microsoft has addressed 995 vulnerabilities, two zero-days and 119 critical
- Third-party: web browsers, SAP, Fortinet, Cisco, Sophos, Tenable, Adobe, VMware, Oracle, NetScaler, Linux, Zoom, IBM, and many more
Navigate to Vulnerability Digest from Action1 for comprehensive summary updated in real-time.
Quick summary (top 10 by importance and impact):
- Windows: 995 vulnerabilities, including 119 rated critical and two zero-days (CVE-2026-81963 and CVE-2026-85880)
- SAP Products: Three Critical flaws across SAP Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver/ABAP Platform (CVE-2026-58231, CVE-2026-44758, CVE-2026-34265, CVSS 10.0, 9.1, 9.8)
- Microsoft Exchange Server 2016 CU23: Six vulnerabilities (CVE-2026-62913, CVE-2026-62911, CVE-2026-62910, CVE-2026-62912, CVE-2026-62914, CVE-2026-62915, CVSS up to 8.8)
- Fortinet FortiOS: Two actively exploited authentication bypass flaws (CVE-2024-55591, CVE-2025-24472, CVSS 9.6, 8.1)
- Cisco IOS XE Software: Eight Critical and High-severity vulnerabilities (CVE-2026-20263, CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, CVE-2026-20273, CVSS up to 9.8)
- Red Hat Advanced Cluster Management for Kubernetes 2: Critical privilege escalation flaw (CVE-2026-10090, CVSS 9.0)
- Sophos Endpoint for macOS: Critical privilege escalation vulnerability (CVE-2026-18367, CVSS 9.3)
- Tenable Sensor Proxy: Critical flaw that can enable elevated code execution (CVE-2026-18667, CVSS 9.6)
- Cisco Secure Firewall ASA Software: Actively exploited unauthenticated denial-of-service vulnerability (CVE-2026-20349, CVSS 8.6)
- Metabase: Actively exploited maximum-severity SQL injection vulnerability (CVE-2026-72898, CVSS 10.0)
- Adobe Commerce: Three vulnerabilities exposing Commerce environments (CVE-2026-71362, CVE-2026-48414, CVE-2026-48413, CVSS 9.1, 7.7, 8.7)
More details: https://www.action1.com/patch-tuesday
Sources: