September 2026 vulnerabilities
Microsoft reports 2 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 2,269 vulnerabilities across 4,267 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.
- Patch records
- Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
- Tracked here
- Records joined to a vulnerability record in this tracker.
- Defender priority
- Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
- More likely
- Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.
Narrow the complete month
Filters use every patch record in this month, including records on later static pages.
Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.
Loading the complete-month filter index…
The complete-month filter index could not be loaded, so filters are unavailable. The static records and page links below remain complete and usable.
An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.
Microsoft Security Response Center
Cross-vendor patches
Page 3 of 22 · records 401 to 600 of 4,267
Microsoft Security Response Center
and 1 more
KB5126106and 1 more
KB5124012and 1 more
KB5124012and 1 more
KB5124012and 1 more
KB5124012The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.