Security NEXT•September 9, 2026•🇯🇵Translated from Japanese

Microsoft Addresses 973 Vulnerabilities in September Security Update

Microsoft released its September monthly security updates on September 8, 2026, addressing a total of 973 vulnerabilities tracked under CVE identifiers. The company also resolved four additional flaws affecting third-party software.

The update was published on the second Tuesday of the month, known as Patch Tuesday. It covers a wide range of products including Windows, Office, SQL Server, Azure, Microsoft Dynamics, SharePoint Server, and multiple development tools.

Impact analysis shows 258 vulnerabilities permit remote code execution, while 438 allow privilege escalation. Additional categories include 173 information disclosure issues, 56 denial-of-service flaws, 19 security feature bypass problems, 16 spoofing vulnerabilities, and 13 memory-related weaknesses.

Severity distribution indicates 113 vulnerabilities rated Critical, exceeding the 100 mark, with the remaining 860 classified as Important. Some of the patched flaws have already been confirmed as actively exploited in the wild.

Related articles

Security NEXT•Vulnerabilities & Exploits

Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks

Apple has issued security updates for multiple macOS versions to address a serious vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, involves an out-of-bounds write that could allow arbitrary code execution when processing specially crafted files. The company also noted that the same issue may have been exploited in sophisticated, targeted attacks against older versions of iOS. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. Patches are now available in macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, and the latest macOS Golden Gate 27.0.1 release.

Security NEXT•Vulnerabilities & Exploits

Apple Releases iOS 26.7.1 and iPadOS 26.7.1 to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted Attacks

Apple has issued iOS 26.7.1 and iPadOS 26.7.1 to address a high-severity vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when processing a specially crafted file due to an out-of-bounds write. The company stated that the issue may have been exploited in sophisticated, targeted attacks against specific individuals on versions prior to iOS 27. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. On the same day, Apple also released iOS 27.0.1 and iPadOS 27.0.1, though those updates did not reference CVE-2026-86950. The patches close a vector that could be abused for remote code execution in image rendering components.

Habr•Vulnerabilities & Exploits

Fundamental Flaw in File Monitoring APIs Exposes Keystrokes and App Activity Across Windows, Linux, Android, and macOS

Researchers from Graz University of Technology demonstrated how built-in file change notification mechanisms can leak sensitive user activity without requiring elevated privileges. The affected subsystems include inotify on Linux, FileObserver on Android, ReadDirectoryChangesW on Windows, and FSEvents on macOS. On Linux the technique enables reconstruction of typed text with 93-100% accuracy by monitoring /dev/input/event4 timestamps. Android apps can break sandbox isolation to observe messaging events, while Windows monitoring of browser cache files reveals visited websites at 97.8% accuracy. Only partial mitigations have been deployed in Linux and Windows, with no fixes available for Android or macOS. Additional attacks remain possible, including detection of password prompts to facilitate phishing overlays.

AntiMalware•Vulnerabilities & Exploits

16-Year-Old Researcher Discovers Authentication Bypass in Microsoft Titan Analytics Platform

A 16-year-old security researcher using the pseudonym Faav identified a critical flaw in Microsoft Titan, the company's internal analytics platform. The vulnerability allowed an attacker to submit forged JSON Web Tokens that bypassed signature verification and granted administrator privileges. With these rights, the researcher could execute arbitrary SQL queries against connected databases containing metadata from nearly 10,000 tables. Microsoft received the report on September 5, disabled public API access four days later, and issued a $5,000 bounty on September 17. No evidence has emerged that the issue was exploited by malicious actors before remediation. The researcher accessed only limited metadata and a small number of records during testing and did not exfiltrate customer personal data.