BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
September 2026 Patch Tuesday catalogue.
Complete for the active automated Patch Tuesday cohort: Microsoft, Adobe and SAP. 159 operational patch records link 1196 unique CVEs. No claim is made for vendors outside that cohort. 3 candidate records are withheld pending correction or publication review. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
September 2026 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-119 · Updated 2026-09-08Product and releaseAdobe ColdFusion2025.0.13, 2023.0.24Review linked CVEs (9) No confirmed exploitation stated
Operational summary
Adobe published APSB26-119 on Patch Tuesday for Adobe ColdFusion. The bulletin links 9 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-119
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Vendor Accelerated Guidance
Vendor signal: Critical; CVSS 9.9; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- Adobe Priority 1 applies to the bulletin; it does not confirm exploitation of every linked CVE.
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB26-138 · Updated 2026-09-08Product and releaseAdobe Commerce2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep, 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep, 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sepReview linked CVEs (9) No confirmed exploitation stated
Operational summary
Adobe published APSB26-138 on Patch Tuesday for Adobe Commerce. The bulletin links 9 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-138
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.3; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB26-98 · Updated 2026-09-08Product and releaseAdobe Experience ManagerAEM Cloud Service (CS) Release 2026.8.0, 6.5 LTS Service Pack 3, 6.5 Service Pack 25Review linked CVEs (109) No confirmed exploitation stated
Operational summary
Adobe published APSB26-98 on Patch Tuesday for Adobe Experience Manager. The bulletin links 109 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-98
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 9.9; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- CVE-2025-64542
- CVE-2025-64584
- CVE-2025-64588
- CVE-2025-64589
- CVE-2025-64610
- CVE-2025-64618
- CVE-2025-64830
- CVE-2025-64838
- CVE-2025-64854
- CVE-2025-64866
- CVE-2025-64868
- CVE-2025-66516
- CVE-2026-18401
- CVE-2026-19232
- CVE-2026-19479
- CVE-2026-19612
- CVE-2026-19644
- CVE-2026-19713
- CVE-2026-27222
- CVE-2026-27227
- CVE-2026-27238
- CVE-2026-27258
- CVE-2026-71356
- CVE-2026-71357
- CVE-2026-71388
- CVE-2026-71440
- CVE-2026-71565
- CVE-2026-72626
- CVE-2026-72627
- CVE-2026-75629
- CVE-2026-75635
- CVE-2026-75636
- CVE-2026-75637
- CVE-2026-75639
- CVE-2026-75640
- CVE-2026-75642
- CVE-2026-75643
- CVE-2026-75644
- CVE-2026-75646
- CVE-2026-75647
- CVE-2026-75651
- CVE-2026-75652
- CVE-2026-75657
- CVE-2026-75659
- CVE-2026-75660
- CVE-2026-75661
- CVE-2026-75666
- CVE-2026-75667
- CVE-2026-75668
- CVE-2026-75669
- CVE-2026-75670
- CVE-2026-75671
- CVE-2026-75672
- CVE-2026-75674
- CVE-2026-75675
- CVE-2026-75677
- CVE-2026-75678
- CVE-2026-75679
- CVE-2026-75680
- CVE-2026-75681
- CVE-2026-75683
- CVE-2026-75685
- CVE-2026-75687
- CVE-2026-75690
- CVE-2026-75691
- CVE-2026-75692
- CVE-2026-75693
- CVE-2026-75694
- CVE-2026-75695
- CVE-2026-75696
- CVE-2026-75700
- CVE-2026-75701
- CVE-2026-75702
- CVE-2026-75704
- CVE-2026-75705
- CVE-2026-75706
- CVE-2026-75707
- CVE-2026-75708
- CVE-2026-75709
- CVE-2026-75710
- CVE-2026-75711
- CVE-2026-75712
- CVE-2026-75713
- CVE-2026-75714
- CVE-2026-75715
- CVE-2026-75716
- CVE-2026-75717
- CVE-2026-75718
- CVE-2026-75719
- CVE-2026-75720
- CVE-2026-75722
- CVE-2026-75724
- CVE-2026-75725
- CVE-2026-75726
- CVE-2026-75727
- CVE-2026-75729
- CVE-2026-75730
- CVE-2026-75731
- CVE-2026-75733
- CVE-2026-75734
- CVE-2026-75735
- CVE-2026-75736
- CVE-2026-75737
- CVE-2026-75738
- CVE-2026-75739
- CVE-2026-75740
- CVE-2026-75741
- CVE-2026-75742
- CVE-2026-79905
AdobeUpdate Adobe Photoshop Mobile to the fixed Adobe releaseAPSB26-136 · Updated 2026-09-08Product and releaseAdobe Photoshop Mobile1.7.0.2302Review linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-136 on Patch Tuesday for Adobe Photoshop Mobile. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-136
- Platform
- Android
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 7.4; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB26-130 · Updated 2026-09-08Product and releaseAdobe Photoshop27.7, 26.11.7Review linked CVEs (8) No confirmed exploitation stated
Operational summary
Adobe published APSB26-130 on Patch Tuesday for Adobe Photoshop. The bulletin links 8 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-130
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-131 · Updated 2026-09-08Product and releaseAdobe Illustrator29.8.11, 30.8Review linked CVEs (3) No confirmed exploitation stated
Operational summary
Adobe published APSB26-131 on Patch Tuesday for Adobe Illustrator. The bulletin links 3 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-131
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB26-132 · Updated 2026-09-08Product and releaseAdobe Animate23.0.17, 24.0.15Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-132 on Patch Tuesday for Adobe Animate. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-132
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.2; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Acrobat and Reader to the fixed Adobe releaseAPSB26-141 · Updated 2026-09-08Product and releaseAdobe Acrobat and Reader26.002.21901, 24.001.30429Review linked CVEs (35) No confirmed exploitation stated
Operational summary
Adobe published APSB26-141 on Patch Tuesday for Adobe Acrobat and Reader. The bulletin links 35 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-141
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.8; Adobe priority 2
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- CVE-2026-47952
- CVE-2026-47965
- CVE-2026-48373
- CVE-2026-79907
- CVE-2026-79908
- CVE-2026-79909
- CVE-2026-79910
- CVE-2026-80159
- CVE-2026-80160
- CVE-2026-80161
- CVE-2026-80162
- CVE-2026-81973
- CVE-2026-81975
- CVE-2026-81976
- CVE-2026-81977
- CVE-2026-81978
- CVE-2026-81979
- CVE-2026-81980
- CVE-2026-81981
- CVE-2026-81982
- CVE-2026-81983
- CVE-2026-81984
- CVE-2026-81985
- CVE-2026-81986
- CVE-2026-81987
- CVE-2026-81988
- CVE-2026-81989
- CVE-2026-81990
- CVE-2026-81991
- CVE-2026-81992
- CVE-2026-81993
- CVE-2026-81994
- CVE-2026-81996
- CVE-2026-81997
- CVE-2026-82001
AdobeUpdate Adobe Campaign Classic to the fixed Adobe releaseAPSB26-142 · Updated 2026-09-08Product and releaseAdobe Campaign ClassicACC v7 7.4.4 build 9402Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-142 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-142
- Platform
- Windows, Linux
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Vendor Accelerated Guidance
Vendor signal: Critical; CVSS 10.0; Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
- Adobe Priority 1 applies to the bulletin; it does not confirm exploitation of every linked CVE.
MicrosoftDeploy Microsoft Apps update for Microsoft Authenticator for AndroidMSRC-2026-09-apps-release-notes · Updated 2026-09-08Product and releaseMicrosoft Authenticator for Android16.3.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Authenticator for Android.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-apps-release-notes
- Platform
- Apps
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Apps update for Xbox Gaming ServicesMSRC-2026-09-apps-store · Updated 2026-09-08Product and releaseXbox Gaming Services37.114.10001.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Xbox Gaming Services.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-apps-store
- Platform
- Apps
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Arc SQL Server ExtensionMSRC-2026-09-azure-release-notes · Updated 2026-09-08Product and releaseAzure Arc SQL Server Extension1.1.3518.465Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Arc SQL Server Extension.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Spring Cloud AzureMSRC-2026-09-azure-release-notes · Updated 2026-09-08Product and releaseSpring Cloud Azure7.4.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Spring Cloud Azure.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.2MSRC-2026-09-azure-release-notes · Updated 2026-09-08Product and releaseAzure CycleCloud 8.9.28.9.2Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.2.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure HDInsightMSRC-2026-09-azure-release-notes · Updated 2026-09-08Product and releaseAzure HDInsight2606012120Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure HDInsight.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft Azure CLIMSRC-2026-09-azure-release-notes · Updated 2026-09-08Product and releaseMicrosoft Azure CLI2.2.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Azure CLI.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Microsoft Authentication Library (MSAL) for Node.jsMSRC-2026-09-azure-release-notes · Updated 2026-09-08Product and releaseMicrosoft Authentication Library (MSAL) for Node.js5.6.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Authentication Library (MSAL) for Node.js.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Browser update for Microsoft Edge (Chromium-based)MSRC-2026-09-browser-release-notes · Updated 2026-09-08Product and releaseMicrosoft Edge (Chromium-based)152.0.4191.62Review linked CVEs (23) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Microsoft Edge (Chromium-based).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-09-browser-release-notes
- Platform
- Browser
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
- CVE-2026-84323
- CVE-2026-84324
- CVE-2026-84325
- CVE-2026-84326
- CVE-2026-84327
- CVE-2026-84328
- CVE-2026-84329
- CVE-2026-84331
- CVE-2026-84332
- CVE-2026-84334
- CVE-2026-84335
- CVE-2026-84347
- CVE-2026-84348
- CVE-2026-84349
- CVE-2026-84350
- CVE-2026-84351
- CVE-2026-84353
- CVE-2026-84354
- CVE-2026-84355
- CVE-2026-84356
- CVE-2026-84357
- CVE-2026-84358
- CVE-2026-84359
MicrosoftDeploy Microsoft Developer Tools security update KB5123099KB5123099 · Updated 2026-09-08Product and releaseMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 20162.0.50727.8984 & 3.0.30729.8980 & 4.7.4145.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5123099
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft Developer Tools security update KB5126043KB5126043 · Updated 2026-09-08Product and releaseMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, plus 1 more2.0.50727.9070 & 3.0.30729.9068 & 4.7.4145.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5126043
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.