September's Patch Tuesday Was Record-Sized — And the Same Week Hit the Tools That Run Your Business
September 16, 2026
Microsoft’s September 2026 Patch Tuesday was the largest of the year — roughly 964 CVEs in a single release, with more than a hundred rated critical. Two of those Windows flaws were already being exploited before the patches shipped. The same week, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, and two of them had nothing to do with a typical Windows endpoint: one hit Adobe Commerce / Magento storefronts, and one hit N-able N-central, the remote monitoring and management platform many MSPs use to manage client environments.
If the August SharePoint and vCenter stories were about how fast an internet-facing server can be taken over after a PoC appears, this week’s story is broader. The patch queue is no longer just “Windows and Office.” It includes the e-commerce stack your sales team lives on, and the management console that can reach every workstation you support.
A record Patch Tuesday with two Windows zero-days
On September 8, 2026, Microsoft shipped security updates covering about 964 CVEs — more than any other Patch Tuesday this year, according to Tenable’s count. Elevation of privilege dominated by volume, but the two that matter most right now are the ones already used in real attacks:
- CVE-2026-81963 — a link-following elevation of privilege in the Windows Update Stack (CVSS 7.8). An attacker with a foothold can elevate to SYSTEM. Microsoft and CISA both treat it as exploited in the wild.
- CVE-2026-85880 — a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), also CVSS 7.8 and also exploited before the patch. Same outcome: local access becomes SYSTEM.
Neither requires a user to click anything clever once the attacker is already on the machine. That is why they sit in CISA’s KEV catalog with a federal remediation deadline of September 22, 2026. For a mid-sized business, the practical translation is simple: do not park September’s Windows updates in next month’s maintenance window.
The release also included several network-facing issues Microsoft rated as more likely to be exploited soon, including a critical Windows DNS Server remote code execution flaw (CVE-2026-69730, CVSS 9.8). Even if those never make the same headlines as the zero-days, DNS, Remote Desktop Services, Kerberos, Exchange, and SQL Server are the roles you want verified patched first — not left for a quiet Saturday three weeks later.
CISA’s same-day KEV batch went beyond Windows
The same September 8 alert that captured the two Windows flaws also listed:
- CVE-2026-75650 — an actively exploited Adobe Commerce / Magento template-engine flaw that can lead to unauthenticated remote code execution on storefronts. Adobe shipped an emergency hotfix; CISA’s federal deadline for this one was September 11.
- CVE-2026-86218 — a maximum-severity (CVSS 10.0) static code injection issue in N-able N-central that can allow pre-authentication remote code execution on the N-central server.
That second item is the one every MSP — and every business whose IT partner runs N-central — should treat as an emergency, not a newsletter item.
N-central: when the management plane is the target
N-able released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to address CVE-2026-86218. Hosted N-central instances were patched by N-able. On-premises servers need that build applied immediately. The company’s public advisory said it had no confirmed production exploitation at the time of the writeup; a separate urgent customer notice, and reporting from Huntress and others, treated the issue as exploited or strongly suspected in the wild. CISA’s KEV listing settles the operational question either way: treat unpatched internet-reachable N-central as an active risk.
Earlier the same weekend, N-able also shipped fixes for two authentication-bypass issues (CVE-2026-86206 and CVE-2026-86207) that Rapid7’s Stephen Fewer publicly analyzed. Chained with a remote code execution path, those bugs are exactly the kind of combination that turns a management console into a beachhead across every client endpoint it can reach.
This is why RMM and PSA platforms get disproportionate attacker attention. Compromise one console and you inherit legitimate remote-access pathways into dozens of businesses. Patching the management plane is not “vendor hygiene.” It is protecting the keys to the kingdom.
What this means for a mid-sized business
A few concrete checks, in order:
- Confirm September Windows updates are installed on servers and workstations — especially anything that already had a foothold risk (shared desktops, RDP hosts, jump boxes). Prioritize the Update Stack and ALPC fixes; do not wait for the next change window.
- Ask your MSP whether N-central (or any other RMM) is current. If it is hosted, ask when the vendor confirmed the hotfix. If it is on-premises, ask for the build number and whether it is at least 2026.3.1.14. Then ask whether they audited for unexpected admin accounts after the weekend of September 5–8.
- If you run Adobe Commerce or Magento, apply Adobe’s emergency hotfix for CVE-2026-75650, rotate encryption keys and protected credentials as Adobe directs, and check for compromise that may have happened before the patch.
- Treat CISA KEV additions as same-week work, not as interesting reading. The federal deadlines (September 11 for Magento and N-central, September 22 for the Windows zero-days) are a useful private-sector yardstick even when BOD 26-04 does not legally bind you.
- Remember that internet-facing management and e-commerce stacks age in hours now, not in maintenance calendars. The August SharePoint and vCenter cases made that point for infrastructure. September’s N-central and Magento cases make it for the tools that sit above and beside that infrastructure.
For businesses without a dedicated security team watching Patch Tuesday, vendor hotfixes, and KEV updates every week, this is the gap a managed IT partner is supposed to close — not by forwarding headlines after the fact, but by already knowing which of your systems and which of their own tools were in scope before the alert hit your inbox.