# patch tuesday

Published articles for patch tuesday.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## September's Windows 11 patch needs an emergency patch of its own

DevFeed: [September's Windows 11 patch needs an emergency patch of its own](<https://devfeed.tech/articles/september-s-windows-11-patch-needs-an-emergency-patch-of-its-own-26958.md>)

Original publisher: [Read original article](<https://www.theregister.com/on-prem/2026/09/15/septembers-windows-11-patch-needs-an-emergency-patch-of-its-own/5296567>)

Author: Richard Speed

Published: 2026-09-15T13:33:55Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Windows 11](<https://devfeed.tech/topics/windows-11.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [USB](<https://devfeed.tech/topics/usb.md>)

Tags: [audio](<https://devfeed.tech/tags/audio.md>), [hyper-v](<https://devfeed.tech/tags/hyper-v.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [rdp](<https://devfeed.tech/tags/rdp.md>), [usb](<https://devfeed.tech/tags/usb.md>), [windows-11](<https://devfeed.tech/tags/windows-11.md>)

### AI overview

Microsoft fixes Windows 11 problems affecting RDP and Hyper-V, but some USB audio devices remain silent.

### Source excerpt

Microsoft fixes RDP and Hyper-V fallout, but some USB audio stays silent

## September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

DevFeed: [September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs](<https://devfeed.tech/articles/september-2026-patch-tuesday-two-exploited-zero-days-and-113-critical-vulnerabilities-among-972-cves-8309.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/>)

Author: Falcon Exposure Management Team

Published: 2026-09-12T11:17:51.295154Z

Content type: news

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [defender](<https://devfeed.tech/tags/defender.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday addresses 972 vulnerabilities, including two exploited zero-days and 113 critical issues. The article also notes a disclosed proof-of-concept zero-day exploit against Microsoft Defender.

### Source excerpt

Microsoft has released security updates for 972 vulnerabilities, including two exploited zero-days and 113 critical, in its September 2026 Patch Tuesday rollout.

## Microsoft fixes record 964 flaws, including 2 exploited zero-days

DevFeed: [Microsoft fixes record 964 flaws, including 2 exploited zero-days](<https://devfeed.tech/articles/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days-8439.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days>)

Author: Pieter Arntz

Published: 2026-09-09T10:01:08Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [cve-2026-81963](<https://devfeed.tech/tags/cve-2026-81963.md>), [cve-2026-85880](<https://devfeed.tech/tags/cve-2026-85880.md>), [dns](<https://devfeed.tech/tags/dns.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [news](<https://devfeed.tech/tags/news.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday fixes 964 customer-patched vulnerabilities, including two actively exploited Windows zero-days.

### Source excerpt

Microsoft's September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.

## Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

DevFeed: [Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)](<https://devfeed.tech/articles/microsoft-s-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880-8267.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880>)

Author: Research Special Operations

Published: 2026-09-08T18:07:55Z

Content type: news

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [cve-2026-85880](<https://devfeed.tech/topics/cve-2026-85880.md>), [.NET](<https://devfeed.tech/topics/net.md>), [ASP.NET](<https://devfeed.tech/topics/aspnet.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [asp-net-core](<https://devfeed.tech/tags/asp-net-core.md>), [cve-2026-81963](<https://devfeed.tech/tags/cve-2026-81963.md>), [cve-2026-85880](<https://devfeed.tech/tags/cve-2026-85880.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>), [visual-studio](<https://devfeed.tech/tags/visual-studio.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday release addresses 964 CVEs, including two zero-days exploited in the wild. The release rates 104 vulnerabilities as critical and 860 as important.

### Source excerpt

104Critical 860Important 0Moderate 0Low Microsoft addresses 964 CVEs, smashing July's release as the largest Patch Tuesday release. This month's updates include patches for two zero-days that were exploited in the wild. Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important. This month's update includes patches for: .NET .NET and Visual Studio ASP.NET Core Active Directory Certificate Services (AD CS) Active Directory Domain Services Active Directory Federation Services (AD FS) Audio Video Control Transport Protocol Azure Arc Azure CycleCloud Azure HDInsights BranchCache Connected Devices Platform Service (Cdpsvc) Data Sharing Service Client GitHub Copilot and Visual Studio Code Graphic Fonts HID class driver IP Helper Internet Storage Name Service Kernel Streaming WOW Thunk Service Driver Microsoft Account Microsoft Authenticator Microsoft Azure Attestation service and Device Health Attestation Service Microsoft Azure CLI Microsoft COM for Windows Microsoft Dynamics 365 Microsoft Exchange Server Microsoft Graphics Component Microsoft Install Service Microsoft JScript Microsoft Local Security Authority Server (lsasrv) Microsoft Office Microsoft Office Access Microsoft Office Excel Microsoft Office Outlook Microsoft Office PowerPoint Microsoft Office Publisher Microsoft Office SharePoint Microsoft Office Word Microsoft Standard XPS Microsoft Teams for Android Microsoft Trace Data Helper Microsoft UxTheme Library (uxtheme.dll) Microsoft WDAC OLE DB provider for SQL Microsoft WebP Image Extension Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows PDF Microsoft Windows SCSI Class System File Microsoft Windows Search Component Microsoft Windows Speech OpenSSH for Windows Power Automate Push Message Routing Service RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client Remote Desktop Gateway Service Role: DNS Server Role: Windows Fax Serv

## Forgotten UEFI shims undermining Secure Boot

DevFeed: [Forgotten UEFI shims undermining Secure Boot](<https://devfeed.tech/articles/forgotten-uefi-shims-undermining-secure-boot-8369.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/>)

Author: Martin Smolár

Published: 2026-07-14T08:53:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [applications](<https://devfeed.tech/tags/applications.md>), [boot](<https://devfeed.tech/tags/boot.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [os](<https://devfeed.tech/tags/os.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

ESET reported 11 outdated UEFI shim bootloaders that can bypass Secure Boot on systems trusting Microsoft's third-party UEFI certificate. Microsoft revoked the reported shim hashes in its June 2026 Patch Tuesday dbx update.

### Source excerpt

ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities

## Microsoft cumulative update fixes 206 vulnerabilities, including critical Windows flaws

DevFeed: [Microsoft cumulative update fixes 206 vulnerabilities, including critical Windows flaws](<https://devfeed.tech/articles/security-week-2625-microsoft-23077.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1047514/>)

Author: Kaspersky\_Lab ("Лаборатория Касперского")

Published: 2026-06-15T18:48:33Z

Content type: news

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Windows 11](<https://devfeed.tech/topics/windows-11.md>), [DHCP](<https://devfeed.tech/topics/dhcp.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [bitlocker](<https://devfeed.tech/tags/bitlocker.md>), [cve](<https://devfeed.tech/tags/cve.md>), [defender](<https://devfeed.tech/tags/defender.md>), [dhcp](<https://devfeed.tech/tags/dhcp.md>), [github](<https://devfeed.tech/tags/github.md>), [http](<https://devfeed.tech/tags/http.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [tag-9fe8963de219](<https://devfeed.tech/tags/tag-9fe8963de219.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-11](<https://devfeed.tech/tags/windows-11.md>)

### AI overview

Microsoft released a cumulative update that fixes 206 vulnerabilities, including 39 rated critical. The article covers high-severity Windows network-stack issues and patches for vulnerabilities previously disclosed by the person known as Nightmare Eclipse.

### Source excerpt

На прошлой неделе компания Microsoft выпустила очередной кумулятивный набор патчей для своих продуктов. В соответствии с общей тенденцией на увеличение количества обнаруживаемых уязвимостей за единицу времени, данный релиз исправляет рекордные 206 уязвимостей, из них 39 имеют статус критических. Если делить заплатки по категориям, то 63 патча закрывают уязвимости, ведущие к повышению привилегий, 56 багов обеспечивают выполнение произвольного кода, еще 30 могут приводить к утечке информации. Наиболее опасная уязвимость имеет идентификатор CVE-2026-45657, близкий к максимальному рейтинг опасности 9,8 балла по шкале CVSS. Это ошибка в ядре Windows при обработке сетевых пакетов данных, результатом эксплуатации которой может быть удаленное выполнение произвольного кода, затрагивает она Windows 11, а также Windows Server 2022 и 2025. Такого же высокого рейтинга удостоились еще две проблемы -- CVE-2026-47291 и CVE-2026-44815, они также относятся к сетевому стеку в Windows, соответственно затрагивая драйвер HTTP.sys и встроенный клиент DHCP. Кроме того, была закрыта уязвимость, позволяющая обойти BitLocker, ранее раскрытая анонимом, известным как Nightmare Eclipse. Об этом многомесячном противостоянии стоит поговорить подробнее. Читать далее

## 2025 CVE Data Review

DevFeed: [2025 CVE Data Review](<https://devfeed.tech/articles/2025-cve-data-review-27475.md>)

Original publisher: [Read original article](<https://jerrygamblin.com/2026/01/01/2025-cve-data-review/>)

Author: jgamblin

Published: 2026-01-01T18:38:43Z

Content type: article

Language: en

Sources: [Jerry Gamblin](<https://devfeed.tech/sources/jerry-gamblin.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>), [Security](<https://devfeed.tech/topics/security.md>), [Content Management System](<https://devfeed.tech/topics/cms.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [cms](<https://devfeed.tech/tags/cms.md>), [cve](<https://devfeed.tech/tags/cve.md>), [data](<https://devfeed.tech/tags/data.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [report](<https://devfeed.tech/tags/report.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trends](<https://devfeed.tech/tags/trends.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>), [volume](<https://devfeed.tech/tags/volume.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This review analyzes 2025 CVE publication data, reporting 48,185 published CVEs, a 20.6% increase from 2024. It highlights stable median CVSS scores, growth in web application and CMS-related flaws, publication clustering around vendor release cycles, and the Linux Kernel as the product with the most listed vulnerabilities. The article recommends prioritizing vulnerabilities by exploitability and automating remediation where possible.

### Source excerpt

2025 set a new baseline with 48,185 published CVEs. While the sheer volume is climbing, the median CVSS score remained surprisingly stable. We are seeing a distinct shift toward web application flaws (specifically in the CMS ecosystem) and a wider distribution of vendors, proving that vulnerabilities are spreading deeper into the supply chain. This massive growth ... Read more