September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message – Computerworld



Microsoft released 24 CVEs across its developer tooling this month, 23 rated important and one critical. Security feature bypasses are the main focus with eight CVE entries, with remote code execution and information disclosure at four each.

  • The single critical entry is CVE-2026-34182 at CVSS 9.1, a flaw in CMS AuthEnvelopedData processing that allows forged messages to be accepted. It reaches Visual Studio 2017 through 2022.
  • The highest-scoring entry in this family is not the critical one. CVE-2026-81376, a Visual Studio Code security feature bypass, reaches CVSS 9.6 while carrying an important rating. It is a useful reminder that severity labels and CVSS scores answer different questions.
  • Visual Studio Code and its Copilot extensions take 10 entries, mostly security feature bypasses. Update the editor and confirm workspace trust prompts, extension installation and remote sessions behave as configured.
  • .NET ships SDK updates on all three supported lines, x64 and x86: 8.0.131 and 8.0.425, 9.0.121 and 9.0.318, and 10.0.112 and 10.0.401. Install them, then build and run a representative project to check for regressions. Keep the 10 November date for .NET 8 in view while you are in there.
  • The .NET Framework ships monthly rollups per operating system: Windows Server 2012 (KB5126147), Server 2012 R2 (KB5126148), Windows 10 1809 (KB5126144), 21H2 (KB5126145), 22H2 (KB5126146) and Server 2022 (KB5126149). One gap worth noting: the 4.7.2 package for Windows 10 1607 is listed as pending and will follow, so estates still on 1607 will not complete their Framework patching this cycle.

Add these to your standard release schedule, behind this month’s Windows, Office and SQL Server priorities. Keep the 10 November date for .NET 8 and PowerShell 7.4 in view while you are in the developer estate, because a patch this month does not extend either branch.

Adobe (and third-party updates)

September is the largest release of the year, and this (crazy, super high) volume is the least interesting thing about it. The 963 CVEs matter less than the 55 entries Microsoft flags as high risk, and those sit in printing and fonts. Adobe shipped two Acrobat builds one digit apart and only the second is a security update (nothing to worry about here). Of the CVEs Microsoft republished, 25 are not Microsoft’s. A version number tells you very little about the work in front of you. So, given my (super-secret knowledge) of how Microsoft operates over the summer, here is my prediction for next month (October). It won’t be as big as this month – but just you wait – November is going to be big. Let’s up those numbers (or not).



Source link