TL;DR: Microsoft’s September 2026 Patch Tuesday lands a record 974 vulnerabilities plus two zero-days already being exploited, while Adobe also fixed an exploited Magento zero-day and several KEV-listed products remain active attack targets, according to Senserva. Patch velocity now matters less than exploitability, because exposed services, RMM tools, and identity-facing admin surfaces are where attackers move fastest.
NHIMG editorial — based on content published by Senserva: Microsoft ships a record Patch Tuesday with two exploited zero-days
By the numbers:
- Microsoft patched a record 974 vulnerabilities in the September 2026 release, including two zero-days that are already being exploited.
- Adobe fixed more than 170 vulnerabilities this cycle, including a critical Commerce and Magento zero-day exploited before the fix shipped.
- The ranked Windows Server 2022 updates each covered 37 CVEs, while the Windows 10 1809 updates covered 31 and 36 CVEs.
Questions worth separating out
Q: What breaks when exploited zero-days stay in the patch queue too long?
A: Exploited zero-days break the assumption that patching can wait for the next maintenance window.
Q: Why do Microsoft 365 support workflows create takeover risk?
A: Microsoft 365 support workflows create takeover risk because attackers can target the recovery path instead of the login screen.
Q: How should teams prioritise Microsoft patches when multiple CVEs are involved?
A: Teams should rank Microsoft patches by the combination of exploit status, business impact, and affected control plane, not by CVSS alone.
Practitioner guidance
- Prioritise exploited and KEV-listed flaws first Build the patch queue around known exploitation, internet exposure, and ransomware linkage before severity-only ordering.
- Test Server 2016 before broad rollout Validate the August-to-September update path on a Server 2016 ring before mass deployment because 0xc0000409 crash-loop reports can turn remediation into outage.
- Hunt for backdoors after Magento patching Patch Adobe Commerce and Magento, then look for web shells, unexpected admin accounts, and unusual outbound connections because exploitation occurred before the fix shipped.
What's in the full analysis
Senserva's full analysis covers the operational detail this post intentionally leaves for the source:
- Patch-by-patch prioritisation guidance for the September 2026 Microsoft cycle, including the highest-risk KBs and why they matter.
- A practical breakdown of the Magento and Adobe Commerce zero-day response path, including hunt indicators after remediation.
- The full list of KEV-linked products and why each one changes urgency for exposed infrastructure and managed-service environments.
- State-audit context for Microsoft 365, Entra ID, Intune, and Defender configurations that matter after help-desk vishing.
👉 Read Senserva's analysis of the September 2026 Patch Tuesday and exploited zero-days →
Record Patch Tuesday volume and exploited zero-days: what now?
Explore further
Patch volume is now an access-governance problem, not just a change-management problem. When a release cycle contains both record volume and active exploitation, the operational question becomes which systems can be exploited into privileged access before remediation completes. That is especially true for infrastructure that fronts administrative sessions, remote management, or identity workflows. Practitioners should treat patch triage as a privilege-risk exercise, not a simple vulnerability count.
A question worth separating out:
Q: What should teams do immediately after patching an exploited Magento zero-day?
A: After patching an exploited Magento zero-day, teams should assume compromise and hunt for persistence. Check for web shells, unexpected admin accounts, malicious cron jobs, and unfamiliar outbound traffic. If the exploit landed before the fix, the system may already be a foothold rather than just a vulnerable server.
👉 Read our full editorial: Patch Tuesday’s record volume raises the cost of delay