
September 2026 Patch Tuesday: Microsoft, Adobe, Ivanti, and Fortinet Release Critical Security Updates
This September 9th, 2026 Patch Tuesday episode covers multiple vendors releasing security updates. Microsoft patched a record 973 vulnerabilities with 113 rated critical, including numerous Office and Outlook remote code execution vulnerabilities, a webp image format vulnerability, and DNS service issues, though only nine vulnerabilities don't require user action. Adobe addressed 170 vulnerabilities, including one in Adobe Commerce already exploited since late last week, a remote code execution flaw in ColdFusion, and privilege escalation issues in Acrobat and Reader. Ivanti released patches for endpoint manager and neurons for ITSM, with the latter containing critical deserialization vulnerabilities allowing remote code execution without authentication. Fortinet patched a single vulnerability in its ZeroTrust ZTNA product involving improper certificate validation. The presenter advises focusing on patching products actually in use rather than analyzing individual vulnerability severity, as exploits for newly patched vulnerabilities typically emerge within days.