Patch Tuesday cycleSeptember 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

September 2026 Patch Tuesday catalogue.

Complete for the active automated Patch Tuesday cohort: Microsoft, Adobe and SAP. 159 operational patch records link 1196 unique CVEs. No claim is made for vendors outside that cohort. 3 candidate records are withheld pending correction or publication review. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

159Patch recordsStable operational entries, not CVE duplicates
1196Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
13Accelerated actionsAccelerated, within 72 hours
17Revised entriesCanonical history remains visible

September 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
159 matching recordsPage 1 of 8
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-119 · Updated 2026-09-08
Product and releaseAdobe ColdFusion2025.0.13, 2023.0.24
Review linked CVEs (9) No confirmed exploitation stated

Operational summary

Adobe published APSB26-119 on Patch Tuesday for Adobe ColdFusion. The bulletin links 9 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-119
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Vendor Accelerated Guidance

Vendor signal: Critical; CVSS 9.9; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
  • Adobe Priority 1 applies to the bulletin; it does not confirm exploitation of every linked CVE.
Vendor-linked CVEs (9)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.9
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Commerce to the fixed Adobe releaseAPSB26-138 · Updated 2026-09-08
Product and releaseAdobe Commerce2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep, 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep, 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
Review linked CVEs (9) No confirmed exploitation stated

Operational summary

Adobe published APSB26-138 on Patch Tuesday for Adobe Commerce. The bulletin links 9 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-138
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.3; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (9)1 confirmed exploited · 0 with PoC or lab evidence · max CVSS 10.0
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Experience Manager to the fixed Adobe releaseAPSB26-98 · Updated 2026-09-08
Product and releaseAdobe Experience ManagerAEM Cloud Service (CS) Release 2026.8.0, 6.5 LTS Service Pack 3, 6.5 Service Pack 25
Review linked CVEs (109) No confirmed exploitation stated

Operational summary

Adobe published APSB26-98 on Patch Tuesday for Adobe Experience Manager. The bulletin links 109 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-98
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 9.9; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (109)0 confirmed exploited · 2 with PoC or lab evidence · max CVSS 9.9
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Photoshop Mobile to the fixed Adobe releaseAPSB26-136 · Updated 2026-09-08
Product and releaseAdobe Photoshop Mobile1.7.0.2302
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-136 on Patch Tuesday for Adobe Photoshop Mobile. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-136
Platform
Android
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 7.4; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.4
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Photoshop to the fixed Adobe releaseAPSB26-130 · Updated 2026-09-08
Product and releaseAdobe Photoshop27.7, 26.11.7
Review linked CVEs (8) No confirmed exploitation stated

Operational summary

Adobe published APSB26-130 on Patch Tuesday for Adobe Photoshop. The bulletin links 8 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-130
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (8)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-131 · Updated 2026-09-08
Product and releaseAdobe Illustrator29.8.11, 30.8
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

Adobe published APSB26-131 on Patch Tuesday for Adobe Illustrator. The bulletin links 3 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-131
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Animate to the fixed Adobe releaseAPSB26-132 · Updated 2026-09-08
Product and releaseAdobe Animate23.0.17, 24.0.15
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-132 on Patch Tuesday for Adobe Animate. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-132
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.2; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.2
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Acrobat and Reader to the fixed Adobe releaseAPSB26-141 · Updated 2026-09-08
Product and releaseAdobe Acrobat and Reader26.002.21901, 24.001.30429
Review linked CVEs (35) No confirmed exploitation stated

Operational summary

Adobe published APSB26-141 on Patch Tuesday for Adobe Acrobat and Reader. The bulletin links 35 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-141
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.8; Adobe priority 2

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Campaign Classic to the fixed Adobe releaseAPSB26-142 · Updated 2026-09-08
Product and releaseAdobe Campaign ClassicACC v7 7.4.4 build 9402
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-142 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-142
Platform
Windows, Linux
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Vendor Accelerated Guidance

Vendor signal: Critical; CVSS 10.0; Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
  • Adobe Priority 1 applies to the bulletin; it does not confirm exploitation of every linked CVE.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 10.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Microsoft Authenticator for AndroidMSRC-2026-09-apps-release-notes · Updated 2026-09-08
Product and releaseMicrosoft Authenticator for Android16.3.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Authenticator for Android.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Apps update for Xbox Gaming ServicesMSRC-2026-09-apps-store · Updated 2026-09-08
Product and releaseXbox Gaming Services37.114.10001.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Xbox Gaming Services.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-apps-store
Platform
Apps
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Arc SQL Server ExtensionMSRC-2026-09-azure-release-notes · Updated 2026-09-08
Product and releaseAzure Arc SQL Server Extension1.1.3518.465
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Arc SQL Server Extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Spring Cloud AzureMSRC-2026-09-azure-release-notes · Updated 2026-09-08
Product and releaseSpring Cloud Azure7.4.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Spring Cloud Azure.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.2MSRC-2026-09-azure-release-notes · Updated 2026-09-08
Product and releaseAzure CycleCloud 8.9.28.9.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.2.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.7
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure HDInsightMSRC-2026-09-azure-release-notes · Updated 2026-09-08
Product and releaseAzure HDInsight2606012120
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure HDInsight.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Azure CLIMSRC-2026-09-azure-release-notes · Updated 2026-09-08
Product and releaseMicrosoft Azure CLI2.2.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Azure CLI.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Authentication Library (MSAL) for Node.jsMSRC-2026-09-azure-release-notes · Updated 2026-09-08
Product and releaseMicrosoft Authentication Library (MSAL) for Node.js5.6.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Authentication Library (MSAL) for Node.js.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.4
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Browser update for Microsoft Edge (Chromium-based)MSRC-2026-09-browser-release-notes · Updated 2026-09-08
Product and releaseMicrosoft Edge (Chromium-based)152.0.4191.62
Review linked CVEs (23) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Microsoft Edge (Chromium-based).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-09-browser-release-notes
Platform
Browser
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5123099KB5123099 · Updated 2026-09-08
Product and releaseMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 20162.0.50727.8984 & 3.0.30729.8980 & 4.7.4145.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5123099
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5126043KB5126043 · Updated 2026-09-08
Product and releaseMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, plus 1 more2.0.50727.9070 & 3.0.30729.9068 & 4.7.4145.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5126043
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0