September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

2026-09-14T07:23:27Z•3c07638b8dbbd076cdf610deae50b504737092b132d22649c0bf594d81b145e0
agentic-socai-securitybotnet-disruptioncloud-workload-protectioncritical-vulnerabilitiescvedetection-triageendpoint-securityexploited-vulnerabilityidentity-securitypatch-tuesdaysality-botnetsoftware-supply-chain-securityzero-day

What happened

CrowdStrike’s September 2026 Patch Tuesday analysis reports 972 CVEs, including 113 rated critical and two exploited zero-days. The feed also covers botnet disruption, software supply-chain attacks, endpoint and cloud workload security, identity security, and AI-driven SOC and detection capabilities. Specific CVE identifiers and technical exploitation details are not present in the supplied metadata.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
3c07638b8dbbd076cdf610deae50b504737092b132d22649c0bf594d81b145e0
Enrichment time
2026-09-14T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.