Microsoft's September 2026 Patch Tuesday set a new record with approximately 972 vulnerabilities fixed — 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities, and last month brought roughly 620. The spike has become what researcher Dustin Childs of the Zero Day Initiative calls "the new normal."
The record patch batch
Among the critical fixes: CVE-2026-55007 in Exchange Server, where a remote unauthenticated attacker could achieve code execution by sending an email with a malicious Visio attachment. CVE-2026-80097 is a local privilege escalation in Microsoft Authenticator — described by Childs as "the worst type of privilege escalation as it uses a bug in the authentication system itself." Roughly 17 distinct vulnerabilities in Microsoft Office SharePoint allowed remote code execution, and CVE-2026-65669 was one of 60 SQL Server privilege escalation vulnerabilities patched this month.
ShieldCrash: a zero-day hours after patching
Hours after Microsoft rolled out its September updates, an anonymous security researcher known as Nightmare Eclipse released a new Microsoft Defender zero-day exploit named "ShieldCrash." It is a bypass for the ShieldBreak Defender privilege escalation flaw that Microsoft patched on Thursday — which itself bypassed RoguePlanet, another Defender flaw disclosed in June and patched in July.
According to Nightmare Eclipse, the ShieldCrash proof-of-concept exploit lets attackers gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems — though it does not grant write access to the compromised systems. The researcher described it as a skeleton PoC, saying he might rework it later into a full SYSTEM PoC but was "feeling a bit lazy" for now.
The Nightmare Eclipse dispute
Nightmare Eclipse has been releasing zero-day exploits since April as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. The researcher has disclosed a long string of zero-day flaws including ShieldBreak, LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend — targeting Microsoft Defender, BitLocker, and other Windows components.
Microsoft fixed ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, but the other vulnerabilities disclosed by Nightmare Eclipse still lack an official patch. Microsoft responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to its customers, prompting many to believe the company was directly threatening the security researcher.
AI-assisted vulnerability discovery
The record patch numbers coincide with a broader trend: AI-assisted vulnerability discovery shows no signs of slowing down. Two weeks before this Patch Tuesday, OpenAI, Anthropic, AWS, Google, Microsoft, and 100 other companies published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first.
Childs cautioned that "we have not seen a correlating spike in active exploits — yet." The gap between discovery volume and active exploitation may not hold much longer.
What organizations should do
The September Patch Tuesday includes two actively exploited Windows zero-days. Organizations should prioritize patching Exchange Server, SharePoint, SQL Server, and Microsoft Authenticator — and treat the Defender ShieldBreak fix as urgent even though ShieldCrash bypasses it. The CISA KEV catalog added seven new entries on September 2, spanning Sangoma Switchvox, Kludex Starlette, Kestra, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances.