Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 342, Issue 1IT NewsSecurity

September 2026 Patch Tuesday Forecast: All We Need Is More Time

Help Net Security, Friday, September 4th, 2026

August set a record at 398 CVEs resolved, and the binding constraint on patching is now testing and deployment time.

Todd Schell's monthly forecast describes an ongoing patch apocalypse driven by AI-accelerated vulnerability discovery, with August 2026 setting a record of 398 resolved CVEs even though actual exploitation stayed limited to one confirmed exploited flaw and two publicly disclosed ahead of patches.

Notable recent items include chained SharePoint flaws enabling authentication bypass and RCE, an Exchange Server elevation-of-privilege bug, CVSS 10.0 issues in Azure Arc and Exchange Online, and a Microsoft Defender vulnerability with public proof-of-concept code.

His recommendation is to treat network controls as a meaningful defensive layer while risk-driven remediation catches up, and he flags October end-of-support dates for Windows 11 24H2, Server 2012/R2 and Exchange 2016/2019.

more →  ·  More from Security →