Microsoft's September Patch Tuesday release addresses a record 966 flaws across its products, including two zero-day vulnerabilities that were already being exploited before the fix was released.
- What it is: A large security update for Windows and related Microsoft products, including a critical Windows Update Stack elevation of privilege flaw that lets an attacker gain full system control.
- Who is affected: Any business running Windows 10 or Windows 11 devices, and Windows Server infrastructure.
- What the risk is: The zero-day flaws were being used in attacks before Microsoft's fix was available, so unpatched machines remain exposed.
- What action is needed: Install this month's Windows updates as soon as practical. CISA has also set a 22 September deadline for one of the related flaws.
We recommend confirming your devices are set to install updates automatically, or checking with us if you manage patching centrally.