Security1 publisher2 min readPublished
Microsoft expects 58 of September's 973 CVEs to be exploited within 30 days
Microsoft rated 114 of the 973 Critical, but 284 score 8.0 or higher and two Important-severity Windows bugs are already under attack. One 9.1 advisory in the same cycle came from outside Microsoft.
The Watch · Security desk

What happened
- Microsoft released 973 patches affecting 39 product families on September 9. All of the flaws were still undisclosed when the fixes shipped.
- Microsoft expects 58 of the CVEs to be exploited within 30 days. Two Important-severity Windows vulnerabilities in the release are already being exploited.
- Nine Microsoft CVEs were patched before September 9, all rated Critical and two scoring 10.0, in Azure, Copilot, Discovery Studio, Entra, Fabric and Power Automate.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction Severity labels pointed away from the attacks this month: the exploited pair is rated Important, while the two perfect 10.0 scores were fixed before the cycle opened, so a queue built on Microsoft's ratings starts in the wrong place.
- decision Choosing CVSS 8.0 as the trigger instead of the vendor's Critical flag is a 170-CVE difference in test load.
- constraint Test capacity sets the ceiling: with 964 CVEs left for administrators to evaluate, somebody has to decide which 8.0-plus items stay unpatched for weeks.
- exposure An estate whose September work is defined by the Microsoft update catalogue carries the 9.1 OpenSSL CMS flaw without ever seeing it in a queue.
Triage order is the decision this month. The two labels available for it point in different directions. Microsoft marked 114 of the 973 Critical [2]. A CVSS base score of 8.0 or higher covers 284 [5]. Queue by score and you have 170 more items to test than the vendor's own label hands you [2]. Both flaws already under exploitation are rated Important [3]. Sophos did not name them in the overview section of its writeup.
Nine of the 973 were fixed before September 9 [10]. All nine are Critical, two score a flat 10.0, and they sit in Azure, Copilot, Discovery Studio, Entra, Fabric and Power Automate [10]. Sophos said they are "fortunately not items the average administrator need address in any fashion" [11]. Those nine also skew the month's numbers: they average 9.0 against 7.4 for the other 964 [12].
Reading the release is itself work. Microsoft's analyst summary for September would run 3,002 pages in print [16], about three pages per CVE [3]. The cycle runs wider than the Microsoft count. The Chrome team shipped 24 Edge-related patches in the days before Patch Tuesday [13], Adobe moved 21 Acrobat patches with the main release [14], and the servicing stack update ADV990001 went out as usual [15].
CVE-2026-34182 is the item a Windows-focused cycle will step over. It came from the OpenSSL Software Foundation: improper validation of an integrity-check value, CWE-354, in CMS data in certain containers, scored 9.1 [7]. Sophos called it the only eyebrow-raising advisory item in the release [8]. The patch belongs to OpenSSL, so it lands outside the Microsoft queue, and finding it means knowing where OpenSSL's CMS handling runs in the estate. MITRE also flagged CVE-2025-70873, an information disclosure bug in SQLite v3.51.1 [9].
Sophos put the volume down to how bugs are now found, writing that "the system was not built for the AI-finder age" [17], alongside a chart of 60 months of Patch Tuesday volumes in which the last six stand out [18].
The same post spells it out: shipping a fix reveals that the vulnerability exists, and the work of testing and applying it then belongs to the customer [19]. Some of that work ends without a patch. Fixes sometimes cover only part of a userbase, including out-of-support systems and less common builds such as Office for Mac [20].
What to watch
- Whether more of the 58 CVEs Microsoft flagged for 30-day exploitation move into active attack before the October release.
- Whether October's count stays near 1,000 or the six-month volume spike breaks.
- Whether the OpenSSL CMS flaw shows up in third-party product advisories from vendors that embed the library.