Act
active
September 2026 Patch Tuesday: Two Exploited Zero-Days, 972 CVEs
- Engineer — Act: Two actively exploited zero-days in this cycle demand immediate triage: identify which products are affected via the Microsoft Security Update Guide and patch those before the rest of the 113 criticals. Prioritize any edge or identity-plane components first.
- SOC/IR — Act: Actively exploited zero-days mean potential in-progress intrusions — pull the Microsoft advisories for the two exploited CVEs, map their TTPs to ATT&CK, and run a retrospective hunt for exploitation attempts since the last Patch Tuesday cycle.
- Leader — Plan: Two exploited zero-days in a large Patch Tuesday release warrants confirming your teams have a clear patching priority order this week; escalate to Act only if either zero-day turns out to affect a critical, board-visible system or triggers SEC material-incident evaluation.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.