Zero Day Room
Live
Vulnerabilities

Microsoft and Adobe Patch Critical Vulnerabilities

September 2026's Patch Tuesday follows a record-breaking August with 398 CVEs patched. Experts highlight actively exploited SharePoint and Exchange flaws, while Microsoft works on a fix for the 'ShieldBreak' Defender vulnerability.

Vulnerabilities: September 2026's Patch Tuesday follows a record-breaking August with 398 CVEs patched

The volume of software patches continues to hit record highs, with August 2026's Patch Tuesday resolving 398 Common Vulnerabilities and Exposures (CVEs). According to a forecast on HelpNetSecurity, this was the second-largest Patch Tuesday in history. Despite the high number, only one vulnerability was confirmed as actively exploited at the time of release.

A primary challenge for security teams is the sheer lack of time to test and deploy this flood of updates. Igor Sahknov, Microsoft's Corporate Vice President for Azure Networking, has discussed the "collapse of the patch window." He argues that network controls can act as a important defense layer during the period before patching is complete. The objective, he states, is "to create a meaningful layer of defense during the period when patching has not yet been completed." This approach aims to buy time while a risk-driven remediation system reduces exposure.

Critical Vulnerabilities Require Attention

Several specific vulnerabilities from recent months demand immediate action, especially for organizations behind on their patch cycles. Two SharePoint flaws, CVE-2026-55040 and CVE-2026-63520, are being chained together by threat actors. This combination allows for authentication bypass followed by remote code execution on SharePoint servers. Patches were released in July and August 2026, respectively.

Another significant threat is CVE-2026-62911, an Exchange Server elevation of privilege vulnerability. Released in August and carrying a CVSS score of 8.0, it is rated Critical. Microsoft warns that an attacker exploiting this flaw could take over all user mailboxes, enabling them to send emails, read messages, and download attachments.

Microsoft also addressed several critical vulnerabilities in its cloud services. The following cloud-based CVEs were all rated with a maximum CVSS score of 10.0.

ProductCVE IdentifierCVSS Score
Azure ArcCVE-2026-6581610.0
Azure ArcCVE-2026-6955510.0
Exchange Server OnlineCVE-2026-6580110.0

These vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog in the past two months.

Upcoming End-of-Support Deadlines

Several major Microsoft products are approaching end-of-support milestones next month, which will impact patch availability. October 2026's Patch Tuesday will deliver the final updates for Windows 11 Version 24H2 Home and Professional editions. It also marks the end of Extended Security Update (ESU) support for Server 2012, Server 2012 R2, and Exchange Server 2016 and 2019. Organizations are advised to follow Microsoft's upgrade guidance or implement recommended mitigations for these systems.

The 'ShieldBreak' Defender Flaw and Other Forecasts

Microsoft is developing a fix for a publicly disclosed vulnerability in its antivirus engine, known as "ShieldBreak." Tracked as CVE-2026-69414, this elevation of privilege flaw in Microsoft Defender could grant system-level privileges. Proof-of-concept exploit code is already available, making a patch urgent.

The forecast anticipates the high volume of CVEs to continue into September. Adobe released seven updates on August 25, which may lessen the burden for the upcoming Patch Tuesday. Apple may also release a set of operating system updates, having settled into a roughly monthly update rhythm. Google addressed 12 CVEs in a Chrome browser update this week, noting that CVE-2026-85046 is being exploited in the wild. Mozilla, however, released major security updates for all its products on September 1st, suggesting a break may be coming next week.

With the third consecutive month of exceptionally high patch volumes, the security industry watches to see if this "Patch Apocalypse" will become the new normal.

Related coverage

More from Vulnerabilities