{"id":26226,"date":"2026-09-21T15:44:16","date_gmt":"2026-09-21T23:44:16","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/september-2026-patch-tuesday-two-exploited-zero-days-and-113-critical-vulnerabilities-among-972-cves\/"},"modified":"2026-09-21T15:57:13","modified_gmt":"2026-09-21T23:57:13","slug":"september-2026-patch-tuesday-two-exploited-zero-days-and-113-critical-vulnerabilities-among-972-cves","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/september-2026-patch-tuesday-two-exploited-zero-days-and-113-critical-vulnerabilities-among-972-cves\/","title":{"rendered":"September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs"},"content":{"rendered":"<div class=\"container-wp container-wp--main-content-blog aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-container-wp\" data-cmp-is=\"responsive-grid-container\" data-padding-left=\"16\" data-padding-right=\"16\" id=\"container-c9ab7dd884\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12\">\n<div class=\"headline aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-wp-headline\" id=\"headline-en-us\">\n<h1>September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs<\/h1>\n<div class=\"publish_info\">\n<p>September 08, 2026<\/p>\n<p><span>\u2022<\/span><br \/>\n<a href=\"\/en-us\/blog\/author.falcon-exposure-management-team\/\" rel=\"author\" title=\"Posts by Falcon Exposure Management Team\"><br \/>\n                Falcon Exposure Management Team<\/a><br \/>\n<span>\u2022<\/span><br \/>\n<a href=\"\/en-us\/blog\/category.exposure-management\/\" title=\"Exposure Management\">Exposure Management<\/a>\n<\/p>\n<\/div>\n<div class=\"post_image\">\n<img alt=\"\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" decoding=\"async\" fetchpriority=\"high\" height=\"698\" src=\"https:\/\/www.crowdstrike.com\/content\/dam\/crowdstrike\/marketing\/en-us\/images\/blog\/main-images\/exposure-management\/Blog-PT-2025.png\" width=\"1060\"\/>\n<\/div>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"container-wp aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-container-wp\" data-cmp-is=\"simple-container\" id=\"container-5cb263ff0f\">\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-17245a915a\">\n<span><\/p>\n<p>Microsoft has addressed 972 vulnerabilities in its September 2026 security update release, over double the number of CVEs released in August, and a new Patch Tuesday record. This month\u2019s patches include fixes for two exploited zero-day vulnerabilities and 113 Critical vulnerabilities, along with 857 additional vulnerabilities of varying severity levels. Additionally, there was a new proof-of-concept zero-day exploit disclosed against Microsoft Defender, dubbed ShieldCrash. This is discussed at the end of this blog, separately from Microsoft\u2019s patches.<\/p>\n<h2>New AI-Powered Capabilities in Falcon Exposure Management\u00a0<\/h2>\n<p>With CrowdStrike Falcon\u00ae Exposure Management, you can automatically classify and prioritize assets, show attack paths targeting client-side exploitation of devices, and integrate with CrowdStrike Falcon\u00ae Next-Gen SIEM. Learn more in this blog post:\u00a0<\/p>\n<p><a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/falcon-exposure-management-ai-driven-risk-prioritization-shows-what-to-fix-first\/\" rel=\"noopener noreferrer\" style=\"\tfont-weight: bold;\n\" target=\"_blank\">Falcon Exposure Management\u2019s AI-Powered Risk Prioritization Shows Organizations What to Fix First<\/a><\/p>\n<h2>September 2026 Risk Analysis<\/h2>\n<p>This month\u2019s leading risk types by exploitation technique are <a href=\"https:\/\/www.crowdstrike.com\/cybersecurity-101\/privilege-escalation\/\" rel=\"noopener noreferrer\" target=\"_blank\">elevation of privilege<\/a> with 437 patches (45%), <a href=\"https:\/\/www.crowdstrike.com\/cybersecurity-101\/remote-code-execution-rce\/\" rel=\"noopener noreferrer\" target=\"_blank\">remote code execution<\/a> (RCE) with 258 patches (26%), and information disclosure with 171 (18%).<\/p>\n<\/p>\n<p><\/span>\n<\/div>\n<\/div>\n<div class=\"image\">\n<div class=\"cmp-image\" data-asset-id=\"9c38ede3-d292-4d80-9024-63c1296919f4\" data-cmp-hook-image=\"imageV3\" data-cmp-is=\"image\" data-target-location=\"false\" data-title=\"Figure 1. Breakdown of September 2026 Patch Tuesday exploitation techniques\" id=\"image-en-us-figure-1--breakdown-of-se\" itemscope=\"\" itemtype=\"http:\/\/schema.org\/ImageObject\">\n<img alt=\"Figure 1. Breakdown of September 2026 Patch Tuesday exploitation techniques\" class=\"cmp-image__image\" decoding=\"async\" itemprop=\"contentUrl\" loading=\"lazy\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-2609PT-1?wid=720&amp;hei=405&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/><br \/>\n<svg class=\"cmp-image__play-icon__image-alt\">\n<use href=\"#play-alt\" xlink:href=\"#play-alt\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<span class=\"cmp-image__title\" itemprop=\"caption\">Figure 1. Breakdown of September 2026 Patch Tuesday exploitation techniques<\/span>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-b1315ae7f9\">\n<span>Microsoft Windows received the most patches this month with 726, followed by Extended Security Updates (ESU) with 650, and Microsoft Office with 135.<\/span>\n<\/div>\n<\/div>\n<div class=\"image\">\n<div class=\"cmp-image\" data-asset-id=\"16a453fe-9864-4071-9b51-9d400bc58611\" data-cmp-hook-image=\"imageV3\" data-cmp-is=\"image\" data-target-location=\"false\" data-title=\"Figure 2. Breakdown of product families affected by September 2026 Patch Tuesday\" id=\"image-en-us-figure-2--breakdown-of-pr\" itemscope=\"\" itemtype=\"http:\/\/schema.org\/ImageObject\">\n<img alt=\"Figure 2. Breakdown of product families affected by September 2026 Patch Tuesday\" class=\"cmp-image__image\" decoding=\"async\" itemprop=\"contentUrl\" loading=\"lazy\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-2609PT-2?wid=720&amp;hei=405&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/><br \/>\n<svg class=\"cmp-image__play-icon__image-alt\">\n<use href=\"#play-alt\" xlink:href=\"#play-alt\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<span class=\"cmp-image__title\" itemprop=\"caption\">Figure 2. Breakdown of product families affected by September 2026 Patch Tuesday<\/span>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"text text--blog-content\">\n<div class=\"cmp-text\" data-cmp-is=\"text\" data-cmp-name=\"cmp-text-\" data-target-location=\"false\" id=\"text-943c1355ac\">\n<span><\/p>\n<h2>September 2026 Attack Surface Overview<\/h2>\n<p>Microsoft Office received 22 <b>Critical<\/b> patches this month, of which 12 are exploitable via Preview Pane or Reading Pane. When Preview Pane or Reading Pane is enabled, merely previewing a crafted file triggers code execution without any click, attachment open, or macro prompt. This attack pattern has historically been favored by both commodity phishing campaigns and targeted intrusion operators because it eliminates much of the social-engineering friction of convincing users to take an action.<\/p>\n<p>Unauthenticated network-reachable RCE vulnerabilities span at least 17 CVEs across core infrastructure services including Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), Microsoft Message Queuing (MSMQ), Network File System (NFS), and Secure Socket Tunneling Protocol (SSTP) VPN. These flaws allow remote attackers to execute code without credentials or user interaction, making any exposed instance an immediate target for opportunistic scanning and exploitation.<\/p>\n<p>Identity-platform components face elevated risk this month with critical RCE vulnerabilities in both Netlogon and Kerberos. These protocols underpin domain authentication: Netlogon handles secure channel establishment between domain members and controllers, while Kerberos issues authentication tickets for every domain resource. Successful exploitation of either provides a foothold inside the authentication layer that every other domain service trusts.<\/p>\n<p>Windows Hyper-V vulnerabilities this month include flaws that enable guest-to-host escape, expanding the exposure profile from a single compromised virtual machine to the entire virtualization host and all co-resident guests. Hypervisor escapes have historically been high-value targets for advanced adversaries because they bypass the isolation boundary that multi-tenant and segmented environments depend on.<\/p>\n<h2>Exploited Zero-Day Vulnerability in Windows Update Stack<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-81963\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-81963<\/a> is an <b>Important<\/b> elevation of privilege vulnerability in Windows Update Stack and has a <b>CVSS<\/b> score of <b>7.8<\/b>. Microsoft has confirmed the flaw is being exploited in the wild. A local attacker with low privileges can exploit improper link resolution (a link-following flaw) to reach SYSTEM privileges. No user interaction is required.<\/p>\n<p>The attack surface here is effectively the entire Windows fleet. The Update Stack runs on every supported Windows client and server, and its components execute with elevated privileges during patch operations. Link-following bugs in high-privilege services are a well-understood primitive for post-compromise escalation: An attacker who has achieved initial code execution on a workstation, whether through phishing, a browser exploit, or stolen credentials, can chain this flaw to complete the local-admin-to-SYSTEM step without needing a second vulnerability. This class of flaw has historically been incorporated into commodity post-exploitation toolkits because it reliably converts \u201cfoothold\u201d into \u201cfull control\u201d across a broad range of enterprise configurations.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 1. Exploited zero-day in Windows Update Stack<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Important<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81963<\/td>\n<td>Windows Update Stack Elevation of Privilege Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Exploited Zero-Day Vulnerability in Windows Advanced Local Procedure Call<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-85880\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-85880<\/a> is an <b>Important<\/b> elevation of privilege vulnerability in Windows Advanced Local Procedure Call (ALPC) and has a <b>CVSS<\/b> score of <b>7.8<\/b>. Microsoft has confirmed the flaw is being exploited in the wild. A local attacker who already has code execution, even within a low-privilege AppContainer sandbox, can trigger a heap-based buffer overflow to escape the container and reach SYSTEM privileges. No user interaction is required.<\/p>\n<p>ALPC is the foundational inter-process communication mechanism in Windows. It underpins RPC, COM, and a broad set of system services, and is present and active on every supported Windows version from workstation to server core. Because ALPC operates at such a low level in the kernel\u2019s IPC path, vulnerabilities here tend to be reliable privilege-escalation primitives once an attacker has any local code execution. This class of flaw has historically appeared in post-compromise tooling used by both commodity malware and targeted intrusion operators as a reliable final step from user-mode to kernel-mode control.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 2. Exploited zero-day vulnerability in Windows ALPC<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Important<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-85880<\/td>\n<td>Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerability in Windows Netlogon<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72982\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72982<\/a> is a <b>Critical<\/b> RCE vulnerability in the Windows Netlogon service and has a <b>CVSS<\/b> score of <b>9.8<\/b>. An unauthenticated attacker can send a specially crafted packet to Netlogon and execute arbitrary code on the target system. No user interaction is required.<\/p>\n<p>Netlogon is the service that handles domain logon requests, secure channel establishment between domain members and domain controllers (DC), and machine-account password updates. It runs on every domain controller and listens on the network by design. Successful exploitation gives an attacker code execution on a DC, which in practice means immediate access to the NTDS.dit database, Kerberos keys, and the ability to issue or forge authentication artifacts for any account in the domain.<\/p>\n<p>The attack surface is significant: Netlogon must be reachable from domain-joined machines, and in many environments, it is also reachable from broader network segments or even across site-to-site links with minimal filtering. Similar flaws in Netlogon have historically been high-priority targets for ransomware operators and sophisticated intrusion groups because a single vulnerable DC can unlock the entire forest.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 3. Critical RCE vulnerability in Windows Netlogon<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-72982<\/td>\n<td>Windows Netlogon Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerability in Windows DNS Server<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69730\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69730<\/a> is a <b>Critical<\/b> RCE vulnerability in Windows DNS Server and has a <b>CVSS<\/b> score of <b>9.8<\/b>. An unauthenticated attacker can send a specially crafted packet to the DNS service and execute code on the target system. No user interaction is required.<\/p>\n<p>In most Active Directory (AD) environments, DNS runs on domain controllers themselves rather than on dedicated infrastructure. A successful exploit against an AD-integrated DNS server can deliver code execution on a domain controller. Similar DNS service flaws have historically drawn rapid attention from both ransomware operators and nation-state actors because of this co-location pattern.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 4. Critical RCE vulnerability in Windows DNS Server<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-69730<\/td>\n<td>Windows DNS Server Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerabilities in Windows DHCP Server<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69845\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69845<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72979\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72979<\/a> are <b>Critical<\/b> RCE vulnerabilities in Windows DHCP Server, both carrying <b>CVSS<\/b> scores of <b>9.8<\/b>. An unauthenticated attacker with network access to a DHCP server can send specially crafted packets to trigger either a heap-based buffer overflow or a use-after-free condition and execute arbitrary code. No user interaction is required for either flaw.<\/p>\n<p>DHCP servers occupy a position in enterprise networks that amplifies the impact of any compromise. Most environments deploy at least one per subnet or site, and the service typically runs with elevated privileges on infrastructure that is trusted to configure every endpoint\u2019s network stack at boot time. Compromising a DHCP server gives an attacker a pivot point with broad Layer 2 visibility, the ability to inject malicious options into client configurations, and a foothold on a system that security monitoring often treats as stable infrastructure rather than a high-churn endpoint. Legacy network services of this class have historically attracted attention from adversaries seeking lateral movement paths that bypass endpoint detection.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 5. Critical RCE vulnerabilities in Windows DHCP Server<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-69845<\/td>\n<td>Windows DHCP Server Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-72979<\/td>\n<td>Windows DHCP Server Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerability in Windows Message Queuing<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69579\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69579<\/a> is a <b>Critical<\/b> RCE vulnerability in Windows Message Queuing (MSMQ) and has a <b>CVSS<\/b> score of <b>9.8<\/b>. An unauthenticated attacker can send a specially crafted packet to a system running the MSMQ service and execute code without any user interaction. The flaw stems from a use-after-free condition in the network-facing packet handling path.<\/p>\n<p>MSMQ is not installed by default on modern Windows versions, but many enterprises still deploy it to support legacy line-of-business applications, middleware, and monitoring agents. When enabled, the service listens on TCP port 1801 and often runs with SYSTEM privileges. Legacy network services of this class have historically been targeted in wormable exploitation scenarios because they combine unauthenticated remote reach with high-privilege code execution, a pattern that allows rapid lateral movement without credential harvesting.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 6. Critical RCE vulnerability in Windows Message Queuing<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-69579<\/td>\n<td>Windows Message Queuing Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerabilities in Windows Services for NFS<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69595\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69595<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-78445\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-78445<\/a> are <b>Critical<\/b> RCE vulnerabilities in the Windows Services for NFS Open Network Computing Remote Procedure Call (ONCRPC) External Data Representation (XDR) driver, both carrying <b>CVSS<\/b> scores of <b>9.8<\/b>. An unauthenticated attacker can send a specially crafted packet to an NFS service and execute code on the target system.<\/p>\n<p>Windows Services for NFS exists to enable Unix and Linux interoperability in mixed-OS environments, bridging file-sharing workflows between Windows servers and POSIX clients. The feature is not installed by default, but organizations with legacy engineering workloads, scientific computing clusters, or hybrid storage tiers frequently enable it on servers that sit deeper in the network than typical file shares. The ONCRPC XDR driver handles serialization at the protocol layer, so any host running the NFS Server role and reachable on TCP\/UDP 2049 is exposed.<\/p>\n<p>The exposure profile depends on where NFS services have been deployed. In environments where NFS shares back critical application data or serve as landing zones for Linux-based pipelines, a compromised host can provide an attacker with access to sensitive datasets and a pivot point into segments that may otherwise be unreachable from standard Windows infrastructure.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 7. Critical RCE vulnerabilities in Windows Services for NFS<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-69595<\/td>\n<td>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-78445<\/td>\n<td>Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerabilities and Information Disclosure Vulnerability Across Office Products<\/h2>\n<p>This month\u2019s release includes 21 <b>Critical<\/b> RCE vulnerabilities and one <b>Critical<\/b> information disclosure flaw spanning Outlook, Word, Excel, PowerPoint, Office Graphics Component, and Windows Graphics Component. Twelve of the 22 are triggerable through Outlook Reading Pane or Explorer Preview Pane, meaning that receipt of a crafted email or arrival of a crafted file at a shared location is sufficient for code execution without any user click. The other 10 require the recipient to open the malicious file for exploitation to succeed.<\/p>\n<p><b>CVSS<\/b> scores range from <b>6.5<\/b> to <b>9.8<\/b>. The three 9.8-scored items in the Preview Pane or Reading Pane subset are <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-77493\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-77493<\/a> (Windows Graphics Component, Preview Pane), <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-78510\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-78510<\/a> (Word, Preview Pane), and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-78509\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-78509<\/a> (Outlook, Reading Pane).<\/p>\n<p>Attack-surface size is the dominant concern for the Preview Pane subset. Microsoft Office is installed on virtually every enterprise endpoint, and the Preview Pane trigger removes the user-decision checkpoint that would otherwise stand in the way of document-borne payload execution. Malicious RTF files, PowerPoint presentations, and Outlook messages all appear as delivery vectors within this group. This class of flaw has historically been attractive to phishing operators and initial-access brokers because delivery is trivial and interaction requirements are minimal.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 8. Critical RCE vulnerabilities and information disclosure vulnerability across Office products<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-77493<\/td>\n<td>Windows Graphics Component Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-78509<\/td>\n<td>Microsoft Office Outlook Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-78510<\/td>\n<td>Microsoft Word Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69285<\/td>\n<td>Microsoft Office Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69632<\/td>\n<td>Microsoft Office Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69678<\/td>\n<td>Microsoft Office PowerPoint Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69767<\/td>\n<td>Microsoft Office PowerPoint Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69797<\/td>\n<td>Microsoft Office PowerPoint Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-78439<\/td>\n<td>Microsoft Office Graphics Component Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-78505<\/td>\n<td>Microsoft Office Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-78519<\/td>\n<td>Microsoft Office Outlook Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-78525<\/td>\n<td>Microsoft Office Outlook Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-81952<\/td>\n<td>Microsoft Word Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-81955<\/td>\n<td>Windows Graphics Component Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81948<\/td>\n<td>Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81949<\/td>\n<td>Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81950<\/td>\n<td>Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81951<\/td>\n<td>Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81953<\/td>\n<td>Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.8<\/td>\n<td>CVE-2026-81959<\/td>\n<td>Microsoft Excel Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>7.5<\/td>\n<td>CVE-2026-77898<\/td>\n<td>Microsoft Office Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>6.5<\/td>\n<td>CVE-2026-78520<\/td>\n<td>Microsoft Office Outlook Information Disclosure Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerability in Windows Secure Socket Tunneling Protocol<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73009\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73009<\/a> is a <b>Critical<\/b> RCE vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) service and has a <b>CVSS<\/b> score of <b>9.8<\/b>. An unauthenticated attacker can send a specially crafted packet to the SSTP listener and execute code on the target system.<\/p>\n<p>SSTP is the Microsoft-native VPN protocol supported out-of-the-box by Windows Server\u2019s Routing and Remote Access Service (RRAS). Organizations that offer SSTP-based remote-access VPN typically expose the vulnerable service directly to the internet on TCP\/443, which means exploitation does not require prior network access or credential theft. A compromise of SSTP is a perimeter breach with immediate lateral-movement opportunity.<\/p>\n<p>Edge-facing VPN infrastructure has historically been a favored target for both nation-state threat actors and ransomware operators because a single exploited gateway can bypass significant internal segmentation work.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 9. Critical RCE vulnerability in Windows Secure Socket Tunneling Protocol<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>9.8<\/td>\n<td>CVE-2026-73009<\/td>\n<td>Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerability in Windows Kerberos<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69676\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69676<\/a> is a <b>Critical<\/b> RCE vulnerability in Windows Kerberos and has a <b>CVSS<\/b> score of <b>8.8<\/b>. The flaw stems from an authentication bypass via capture-replay: An attacker who has already obtained low-privileged credentials in the target environment can intercept a legitimate Kerberos authentication exchange and replay a modified variant back to the server, which processes it as authentic and executes attacker-controlled code. No further user interaction is required.<\/p>\n<p>Kerberos issues authentication tickets for every domain-joined resource in an Active Directory environment. A code execution flaw in this component can provide an attacker with a foothold inside the authentication layer that every domain service implicitly trusts. Successful exploitation could allow an adversary to forge or manipulate ticket-granting operations, potentially enabling lateral movement across the entire forest. Kerberos-layer attacks have historically been a preferred technique in both ransomware intrusions and targeted campaigns because they offer persistent, stealthy access that survives individual host remediation.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 10. Critical RCE vulnerability in Windows Kerberos<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69676<\/td>\n<td>Windows Kerberos Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerabilities and Elevation of Privilege Vulnerability in Windows Hyper-V<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69603\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69603<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-80083\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-80083<\/a>, and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72961\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72961<\/a> are <b>Critical<\/b> vulnerabilities in Windows Hyper-V and have <b>CVSS<\/b> scores of <b>8.8<\/b>, <b>8.8<\/b>, and <b>8.2<\/b>, respectively. CVE-2026-69603 allows arbitrary code execution through a heap-based buffer overflow via a malformed hypercall payload size. CVE-2026-80083 allows arbitrary code execution on the host through an untrusted pointer dereference reachable from a guest application. CVE-2026-69603 and CVE-2026-80083 enable an attacker operating inside a guest VM to breach the hypervisor isolation boundary. CVE-2026-72961 exploits a buffer overflow in virtual TPM state handling to escalate from host admin to Virtual Trust Level 1 (VTL1) privileges.<\/p>\n<p>A guest-to-host escape compromises the hypervisor, which means the attacker can inspect or manipulate memory for all co-resident VMs, extract secrets from isolated tenants, and persist below the operating-system layer where most endpoint detection stops. In multi-tenant or shared-infrastructure environments, this class of flaw converts a single compromised workload into a platform-wide incident. Hypervisor-escape vulnerabilities have historically been a priority target for sophisticated adversaries because the payoff scales with consolidation density.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 11. Critical vulnerabilities in Windows Hyper-V<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69603<\/td>\n<td>Windows Hyper-V Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-80083<\/td>\n<td>Windows Hyper-V Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.2<\/td>\n<td>CVE-2026-72961<\/td>\n<td>Windows Hyper-V Elevation of Privilege Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Critical RCE Vulnerability in Windows Remote Desktop<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69518\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69518<\/a> is a <b>Critical<\/b> RCE vulnerability in Windows Remote Desktop and has a <b>CVSS<\/b> score of <b>8.8<\/b>. An attacker who joins a Remote Desktop sharing session can send specially crafted clipboard data to the sharing host and execute code on the host system. User interaction is required only to the extent that a sharing session must be active; the attacker does not need additional prompts or clicks once connected.<\/p>\n<p>The attack-surface concern here is the clipboard channel, a feature enabled by default in most RDP configurations because it supports legitimate productivity workflows. Environments that permit clipboard redirection between client and host (the default) are exposed whenever a sharing session is active. This includes help-desk scenarios, remote-support tools built on RDP, and any third-party application that leverages the Remote Desktop API for screen sharing. RDP services have historically been a primary initial-access vector for ransomware operators and opportunistic attackers scanning for exposed endpoints, though this particular flaw requires session participation rather than unauthenticated network access.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"0\">\n<caption>Table 12. Critical RCE vulnerability in Windows Remote Desktop<\/caption>\n<tbody>\n<tr class=\"top-row bg-orange\">\n<td><b>Severity<\/b><\/td>\n<td><b>CVSS Score<\/b><\/td>\n<td><b>CVE<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<td><b>Action Required?<\/b><\/td>\n<\/tr>\n<tr>\n<td><b style=\"\tcolor: red;\n\">Critical<\/b><\/td>\n<td>8.8<\/td>\n<td>CVE-2026-69518<\/td>\n<td>Windows Remote Desktop Remote Code Execution Vulnerability<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Additional Critical Vulnerabilities Addressed This Month<\/h2>\n<ul>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-66302\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-66302<\/a>, Skype for Business RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69590\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69590<\/a>, Windows Routing and Remote Access Service (RRAS) RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69769\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69769<\/a>, Windows HTTP Print Provider RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69829\">CVE-2026-69829<\/a>, Windows Shell RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-70296\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-70296<\/a>, Windows Imaging Component RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72983\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72983<\/a>, Internet Connection Sharing (ICS) RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73010\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73010<\/a>, Microsoft Failover Cluster RCE vulnerability (CVSS 9.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65669\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-65669<\/a>, Microsoft SQL Server elevation of privilege vulnerability (CVSS 9.6)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69854\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69854<\/a>, Spring Cloud Azure elevation of privilege vulnerability (CVSS 9.0)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65772\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-65772<\/a>, Microsoft Dynamics 365 On-Premises RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-67631\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-67631<\/a>, Microsoft SQL Server RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-67643\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-67643<\/a>, Microsoft SQL Server RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69499\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69499<\/a>, Windows Imaging Component RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69601\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69601<\/a>, Microsoft Windows Media Foundation RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69649\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69649<\/a>, Raw Image Extension RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69712\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69712<\/a>, Windows Key Distribution Center RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69740\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69740<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69784\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69784<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69860\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69860<\/a>, Windows Imaging Component RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-70203\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-70203<\/a>, Windows Media Player RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-70351\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-70351<\/a>, Microsoft WebP Image Extension RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-70586\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-70586<\/a>, Windows Paint RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72950\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72950<\/a>, Windows Routing and Remote Access Service (RRAS) RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72959\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72959<\/a>, Windows Routing and Remote Access Service (RRAS) RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72960\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72960<\/a>, Windows Media Player RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72986\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72986<\/a>, Graphic Fonts RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73006\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73006<\/a>, DirectWrite RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73013\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73013<\/a>, Windows Imaging Component RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73018\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73018<\/a>, Graphic Fonts RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73023\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73023<\/a>, Windows Imaging Component RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-77495\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-77495<\/a>, Windows Imaging Component RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-77504\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-77504<\/a>, Microsoft Office Word RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-81352\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-81352<\/a>, Web Media Extensions RCE vulnerability (CVSS 8.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-67378\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-67378<\/a>, Microsoft SQL Server RCE vulnerability (CVSS 8.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-67636\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-67636<\/a>, Microsoft SQL Server RCE vulnerability (CVSS 8.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69820\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69820<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69846\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69846<\/a>, Windows Secure Kernel Mode elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69874\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69874<\/a>, Windows ALPC elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69906\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69906<\/a>, Windows Secure Kernel Mode elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72958\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72958<\/a>, Windows Credential Guard elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72962\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72962<\/a>, Windows USB Video Driver elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-81354\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-81354<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-83939\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-83939<\/a>, Windows Secure Kernel Mode elevation of privilege vulnerability (CVSS 8.2)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69530\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69530<\/a>, Windows Reliable Multicast Transport Driver (RMCAST) RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69813\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69813<\/a>, Windows DNS Server RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69827\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69827<\/a>, Windows DNS Server RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69858\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69858<\/a>, Windows DNS Server RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72981\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72981<\/a>, IP Helper RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72987\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72987<\/a>, Windows DNS RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-77505\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-77505<\/a>, Windows DNS Server RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-78444\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-78444<\/a>, Microsoft Failover Cluster RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-78449\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-78449<\/a>, Windows Reliable Multicast Transport Driver (RMCAST) RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-78450\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-78450<\/a>, Windows Reliable Multicast Transport Driver (RMCAST) RCE vulnerability (CVSS 8.1)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-58599\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-58599<\/a>, HEVC Video Extensions RCE vulnerability (CVSS 7.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69725\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69725<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 7.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69799\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69799<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 7.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69864\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69864<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 7.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72957\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72957<\/a>, Windows Deployment Services RCE vulnerability (CVSS 7.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-83498\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-83498<\/a>, Windows Virtualization-Based Security (VBS) Enclave elevation of privilege vulnerability (CVSS 7.8)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69710\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69710<\/a>, Windows Hello elevation of privilege vulnerability (CVSS 7.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69852\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69852<\/a>, Windows Routing and Remote Access Service (RRAS) RCE vulnerability (CVSS 7.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69890\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69890<\/a>, Windows Virtual Trusted Platform Module elevation of privilege vulnerability (CVSS 7.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72954\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72954<\/a>, Windows Deployment Services RCE vulnerability (CVSS 7.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-73017\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-73017<\/a>, Graphics Kernel RCE vulnerability (CVSS 7.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-81355\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-81355<\/a>, Virtual Hard Disk (VHD) Miniport Driver RCE vulnerability (CVSS 7.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69501\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69501<\/a>, Windows Secure Kernel Mode elevation of privilege vulnerability (CVSS 7.0)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-70585\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-70585<\/a>, Windows Services for NFS ONCRPC XDR Driver RCE vulnerability (CVSS 7.0)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-83501\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-83501<\/a>, Windows Virtualization-Based Security (VBS) information disclosure vulnerability (CVSS 5.5)<\/li>\n<li><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-72980\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-72980<\/a>, Windows Hello Security feature bypass vulnerability (CVSS 4.4)<\/li>\n<\/ul>\n<h2>Publicly Disclosed Microsoft Defender Zero-Day (ShieldCrash)<\/h2>\n<p>Approximately two hours after Microsoft released its Patch Tuesday patches, purported researcher MSNightmare (of the Nightmare-Eclipse persona) released a new proof-of-concept (PoC) zero-day exploit targeting Microsoft Defender. MSNightmare purports that Microsoft\u2019s patch for the ShieldBreak vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69414\" rel=\"noopener noreferrer\" target=\"_blank\">CVE-2026-69414<\/a>) was incomplete, and that this PoC follows an unpatched attack path to allow for SYSTEM-level file reads, with the potential to be converted into a full SYSTEM privilege escalation exploit. MSNightmare\u2019s claims are currently being reviewed, and analysis is ongoing; however, historically this purported researcher\u2019s claims have been found to be accurate. There is no patch or mitigation available at the time of this writing.<\/p>\n<h2>Patch Tuesday Dashboard in the Falcon Platform<\/h2>\n<p>For a visual overview of the systems impacted by this month\u2019s vulnerabilities, you can use our Patch Tuesday dashboard. This can be found in the CrowdStrike Falcon\u00ae platform within the Exposure Management &gt; Vulnerability Management &gt; Dashboards page. The preset dashboards show the most recent three months of Patch Tuesday vulnerabilities.<\/p>\n<h2>Not All Relevant Vulnerabilities Have Patches: Consider Mitigation Strategies<\/h2>\n<p>As we have learned with other notable vulnerabilities, such as <a href=\"https:\/\/www.crowdstrike.com\/log4j2\/\" rel=\"noopener noreferrer\" target=\"_blank\">Log4j<\/a>, not every highly exploitable vulnerability can be easily patched. As is the case for the <a href=\"https:\/\/www.crowdstrike.com\/blog\/owassrf-exploit-analysis-and-recommendations\/\" rel=\"noopener noreferrer\" target=\"_blank\">ProxyNotShell<\/a> vulnerabilities, it\u2019s critically important to develop a response plan for how to defend your environments when no patching protocol exists.\u00a0<\/p>\n<p>Regular review of your patching strategy should still be a part of your program, but you should also look more holistically at your organization\u2019s methods for cybersecurity and improve your overall security posture.<\/p>\n<p>The CrowdStrike Falcon platform regularly collects and analyzes trillions of endpoint events every day from millions of sensors deployed across 176 countries. <a href=\"https:\/\/go.crowdstrike.com\/product-demo-platform.html\" rel=\"noopener noreferrer\" target=\"_blank\">Watch this demo to see the Falcon platform in action<\/a>.<\/p>\n<h2>Learn More<\/h2>\n<p>Learn more about how CrowdStrike Falcon\u00ae Exposure Management can help you quickly and easily discover and prioritize vulnerabilities and other types of exposures <a href=\"https:\/\/www.crowdstrike.com\/products\/exposure-management\/falcon-exposure-management\/\" rel=\"noopener noreferrer\" target=\"_blank\">here<\/a>.<\/p>\n<h3>About CVSS Scores<\/h3>\n<p>The <a href=\"https:\/\/www.first.org\/cvss\/\" rel=\"noopener noreferrer\" target=\"_blank\">Common Vulnerability Scoring System<\/a> (CVSS) is a free and open industry standard that CrowdStrike and many other cybersecurity organizations use to assess and communicate software vulnerabilities\u2019 severity and characteristics. The CVSS Base Score ranges from 0.0 to 10.0, and the <a href=\"https:\/\/nvd.nist.gov\/\" rel=\"noopener noreferrer\" target=\"_blank\">National Vulnerability Database<\/a> (NVD) adds a severity rating for CVSS scores. Learn more about vulnerability scoring <a href=\"https:\/\/www.crowdstrike.com\/epp-101\/vulnerability-management-programs\/\" rel=\"noopener noreferrer\" target=\"_blank\">in this article<\/a>.\u00a0<\/p>\n<h4>Additional Resources<\/h4>\n<ul>\n<li><i>For more information on which products are in Microsoft\u2019s Extended Security Updates program, refer to the vendor guidance <a href=\"https:\/\/learn.microsoft.com\/en-us\/lifecycle\/faq\/extended-security-updates\" rel=\"noopener noreferrer\" target=\"_blank\">here<\/a>.<\/i><\/li>\n<li><i>Learn how\u00a0<a href=\"https:\/\/www.crowdstrike.com\/products\/exposure-management\/falcon-exposure-management\/\" rel=\"noopener noreferrer\" target=\"_blank\">Falcon Exposure Management<\/a> can help you discover and manage vulnerabilities and other exposures in your environments.\u00a0<\/i><\/li>\n<li><i>Make prioritization painless and efficient. Watch how Falcon Exposure Management enables IT staff to improve visibility with\u00a0<a href=\"https:\/\/www.crowdstrike.com\/tech-hub\/?category=exposure-management\" rel=\"noopener noreferrer\" target=\"_blank\">custom filters and team dashboards.<\/a><\/i><\/li>\n<li><i>Test CrowdStrike next-gen antivirus for yourself with a\u00a0<a href=\"https:\/\/go.crowdstrike.com\/try-falcon-prevent.html\" rel=\"noopener noreferrer\" target=\"_blank\">free trial of CrowdStrike\u00ae Falcon Prevent\u2122<\/a>.<\/i><\/li>\n<\/ul>\n<p><\/span>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"sociallinks aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-social-links\" data-target-location=\"false\" id=\"sociallinks-en-us\">\n<a class=\"cmp-social-links__link\" href=\"https:\/\/www.linkedin.com\/shareArticle\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<svg class=\"cmp-social-links__link__icon\">\n<use href=\"#linked-in\" xlink:href=\"#linked-in\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<\/a><br \/>\n<a class=\"cmp-social-links__link\" href=\"https:\/\/twitter.com\/share\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<svg class=\"cmp-social-links__link__icon\">\n<use href=\"#twitter-x-logo\" xlink:href=\"#twitter-x-logo\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><\/use>\n<\/svg><br \/>\n<\/a><br \/>\n<!-- Personal Website Section -->\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"separator aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-separator\" data-cmp-is=\"separator\" data-is-vertical=\"false\" data-separator-color=\"#C4C4C4\" data-separator-height=\"1\" data-separator-width=\"1\" data-target-location=\"false\" id=\"separator-separator-134c17cf63\">\n<hr class=\"cmp-separator__horizontal-rule\" data-cmp-hook-separator=\"hr\"\/>\n<\/div>\n<\/div>\n<div class=\"container responsivegrid aem-GridColumn aem-GridColumn--default--12\">\n<div data-attribute-name=\"data-promo-xf\" data-cmp-is=\"xf-container\" data-target-location=\"false\">\n<\/div>\n<\/div>\n<div class=\"relatedcontent aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"cmp-wp-related-content\" data-target-location=\"false\" id=\"relatedcontent-en-us\">\n<h4>Related Content<\/h4>\n<div class=\"row recent_articles\">\n<a class=\"col-12 col-md-4 recent_articles_item\" href=\"\/en-us\/blog\/patch-tuesday-analysis-august-2026\/\"><\/p>\n<div class=\"post_image\">\n<img alt=\"August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs\" decoding=\"async\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-PT-2025?wid=1060&amp;hei=698&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/>\n<\/div>\n<div class=\"post_info\">\n<div class=\"excerpt\">\n                        Exposure Management | Aug 11, 2026\n                    <\/div>\n<h6>August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs<\/h6>\n<\/div>\n<p><\/a><br \/>\n<a class=\"col-12 col-md-4 recent_articles_item\" href=\"\/en-us\/blog\/crowdstrike-falcon-platform-helps-meet-us-government-mandates-cisa-bod-26-04\/\"><\/p>\n<div class=\"post_image\">\n<img alt=\"CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04 \" decoding=\"async\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-Gov-Scroll?wid=1060&amp;hei=698&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/>\n<\/div>\n<div class=\"post_info\">\n<div class=\"excerpt\">\n                        Public Sector | Jul 22, 2026\n                    <\/div>\n<h6>CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04 <\/h6>\n<\/div>\n<p><\/a><br \/>\n<a class=\"col-12 col-md-4 recent_articles_item\" href=\"\/en-us\/blog\/patch-tuesday-analysis-july-2026\/\"><\/p>\n<div class=\"post_image\">\n<img alt=\"July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days\" decoding=\"async\" src=\"https:\/\/assets.crowdstrike.com\/is\/image\/crowdstrikeinc\/Blog-PT-2025?wid=1060&amp;hei=698&amp;fmt=png-alpha&amp;qlt=95,0&amp;resMode=sharp2&amp;op_usm=3.0,0.3,2,0\"\/>\n<\/div>\n<div class=\"post_info\">\n<div class=\"excerpt\">\n                        Exposure Management | Jul 14, 2026\n                    <\/div>\n<h6>July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days<\/h6>\n<\/div>\n<p><\/a>\n<\/div>\n<\/div>\n<div style=\"display: none;\">\n<\/div>\n<\/div>\n<div class=\"responsivegrid aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEsSeptember 08, 2026\u2022Falcon Exposure Management Team\u2022Exposure ManagementMicrosoft has addressed 972 vulnerabilities in its September 2026 security update release, over double the number of CVEs released in August, and a new Patch Tuesday record. This month&#8217;s patches include fixes for two exploited zero-day vulnerabilities and 113 Critical vulnerabilities, along with 857 additional vulnerabilities o<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32776],"tags":[],"class_list":["post-26226","post","type-post","status-publish","format-standard","hentry","category-crowdstrike"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26226"}],"version-history":[{"count":1,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26226\/revisions"}],"predecessor-version":[{"id":26231,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26226\/revisions\/26231"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}