Microsoft Shipped 974 Fixes in One Day (09/09/2026)
- › Microsoft patched 974 vulnerabilities in a single Patch Tuesday, a record, including two Windows flaws already under active exploitation.
- › Google patched 230 Chrome vulnerabilities including CVE-2026-87491, a V8 out-of-bounds bug being exploited in the wild.
- › SAP fixed CVE-2026-44756, a CVSS 10.0 kernel flaw in Extended Passport processing allowing unauthenticated remote code execution.
- › A researcher published a Microsoft Defender zero-day named ShieldCrash granting SYSTEM access, hours after the September updates shipped.
- › Infostealer logs are being mined for AI service tokens that replay without ever meeting a multi-factor prompt.
Nine hundred and seventy four fixes landed from one vendor on one day, which is more than most organizations process in a quarter. The number is worth sitting with because patch programs are built around an assumption of steady volume, and the two flaws in that pile that are already being exploited do not announce themselves any louder than the other 972.
Top 5 Critical Security Alerts
1. Microsoft Breaks Its Own Patch Tuesday Record at 974 CVEs
Microsoft addressed 974 vulnerabilities across its portfolio in the September release, including two that the company says are under active exploitation in the wild, with 723 of the fixes landing in Windows itself alongside 111 in Office and 62 in SQL. A release this size defeats the ordinary triage habit of reading the summary and deciding what matters, because nobody is reading 974 entries before Thursday. Pull the two exploited items and the remote code execution set first, then treat everything remaining as the normal monthly cycle. The Hacker News has the breakdown and Infosecurity Magazine covers the scale.
Operator Note: Your patch SLA was written against a normal month, so decide now whether a release this size resets the clock or gets triaged against it, and put that decision in writing before the next one arrives.
2. Chrome Patches a V8 Zero-Day Already Under Attack
Google released updates covering 230 vulnerabilities, among them CVE-2026-87491, an out-of-bounds bug in the V8 JavaScript engine that is being actively exploited. The flaw allows code execution inside the browser sandbox and not an escape from it, which sounds like a limitation until you remember how much of an employee’s working day now happens entirely inside that sandbox. Browser updates apply on restart, and the population of machines that never restart is the one worth chasing directly instead of counting in a report. The Hacker News has the advisory detail.
Operator Note: Report browser version compliance the same way you report endpoint patching, because a browser that has been open for three weeks is running the version from three weeks ago.
3. SAP Closes a CVSS 10.0 Kernel Flaw
SAP patched CVE-2026-44756, a maximum severity flaw in Extended Passport processing in the SAP kernel that permits unauthenticated remote code execution against the confidentiality, integrity, and availability of the application. A perfect score on an unauthenticated path into an ERP kernel is about as serious as the scale allows, and these systems tend to sit deep enough in the estate that they were never in the monthly patch rhythm to begin with. The change window for an ERP platform is the real constraint here, since the fix has been available since Tuesday and the outage to apply it has not. The Hacker News has the CVE detail and Infosecurity Magazine has the wider release.
4. A Defender Zero-Day Landed Hours After Patch Tuesday
An anonymous researcher operating as Nightmare Eclipse published a Microsoft Defender zero-day exploit called ShieldCrash that grants SYSTEM access, releasing it immediately after the September updates shipped, and separately demonstrated that an earlier Defender patch can still be bypassed. The endpoint security agent runs with the highest privilege on the machine by design, so a flaw in it converts the control into the shortest available path to the thing it was protecting. Timing a release for the day after a patch cycle maximizes the exposure window on purpose. BleepingComputer has the exploit and The Hacker News has the bypass proof of concept.
Operator Note: Know which of your controls run as SYSTEM or root, because that list is also the list of products whose vulnerabilities skip every intermediate step of an attack.
5. Stolen AI Tokens Replay Straight Past MFA
Criminals are mining infostealer logs from families like Lumma Stealer and Vidar for authentication tokens belonging to AI services from Google, Anthropic, and other model providers, then replaying those tokens to reach the accounts without ever meeting a multi-factor prompt. A token issued after successful authentication carries the result of that authentication, so replaying it is not an attack on MFA so much as an arrival after MFA has already finished. Every AI account in your environment that somebody created with a personal login sits outside whatever session policy you believed you had. The Hacker News has the research.
Operator Note: Inventory the AI services your teams actually log into, then check which of them are governed by your identity provider rather than by a password saved in a browser profile.
Additional Security Alerts
Threat Intelligence
- Four China-linked groups used the same Chrome zero-day: Researchers found at least four separate espionage crews exploiting a single Chrome bug identified in August, which points to a shared supplier rather than four independent discoveries. The Record
- Non-human identities are now the leading way in: SpyCloud reports that service accounts, API keys, and machine credentials have overtaken human accounts as the most likely route into an enterprise. Infosecurity Magazine
- ClickFix has moved into the browser: A campaign is injecting JavaScript into pages and staging through Google Sheets to steal cryptocurrency, which puts the social engineering step inside a site the user already trusted. Infosecurity Magazine
Security Breaches and Incidents
- Veradigm discloses a patient data breach through a vendor: The healthcare technology company said a third-party incident exposed patient data, with access limited to a specific interface rather than its networks, servers, or databases. BleepingComputer and The Record
- Cisco Secure Firewall Management Center is under active exploitation: Talos is tracking live attacks against two FMC vulnerabilities, in a product that manages the enforcement point rather than sitting behind it. Cisco Talos
Security Standards and Frameworks
- CISA added the N-able N-central flaw to KEV with a September 11 deadline: The maximum severity pre-auth flaw we covered as a hotfix is now a federal remediation requirement, which is the clearest available signal that exploitation is real and ongoing. The Hacker News
- A cPanel flaw lets one hosting account reach root: An authenticated account with mail privileges can write files through EmailTrack and then execute as the root user, which collapses the boundary between tenants on a shared server. The Hacker News
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.