5 minNews
Microsoft's September Patch Tuesday Sets Record With Nearly 1,000 Fixes, Including Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday delivered nearly 1,000 security fixes, including two zero-day vulnerabilities under active exploitation, a critical remote code execution flaw in the Windows shell, and a long-standing DNS bug, raising fresh concerns about how companies can apply such a massive update quickly.
Microsoft's monthly Patch Tuesday update for September 2026 has shattered previous records with nearly 1,000 security fixes, including two zero-day vulnerabilities that are already being exploited in the wild. The sheer volume of patches marks a dramatic reversal from August, when the update appeared to signal a slowdown in new bug discoveries.
Both zero-days allow privilege escalation on Windows, a class of vulnerability that lets attackers turn a minor flaw in an application or game into full administrator access. That level of control enables attackers to establish persistence on a system and deploy ransomware, making any other vulnerability significantly more dangerous.
Among the fixes is a vulnerability rated 9.8 on the CVSS severity scale that permits remote code execution in the Windows shell with no user interaction and no authentication required. Another patch addresses a remotely exploitable DNS bug that has existed since Windows Server 2012 and Windows 10, which security analysts expect to see exploited soon. More than a hundred additional bugs in the update are rated critical.
The record-breaking patch set raises questions about Microsoft's recent guidance urging companies to apply updates immediately. With such a large number of fixes, organizations may struggle to deploy them quickly, especially if the patches introduce new behavior or issues that disrupt operations.
In a separate investigation, Gamers Nexus has published a multi-hour report on the data collection practices of LG televisions and monitors. The findings suggest that LG's smart devices gather far more user data than many consumers might expect, and that some data is transmitted even when collection settings are turned off.
According to the investigation, LG executives have described the company's strategy in pitches to advertisers as owning the glass and the living room, with the goal of correlating devices, household members, and viewing habits so that ads can be served simultaneously to televisions and mobile devices in the same room. When tracking is enabled, the TVs capture telemetry on which applications are used and continuously record displayed video, sending fingerprints to LG servers and advertising partners. This monitoring extends to HDMI inputs, meaning the screen content is tracked even when the TV is used as a PC monitor. If voice control is active, the TV also records and analyzes audio.
The devices continually scan the local network and nearby Wi-Fi networks, reporting host names, MAC addresses, and sometimes software details. Nearby Wi-Fi signals can provide precise geolocation, giving LG effective knowledge of each customer's location. While much of this ad technology is limited if users decline the end-user license agreement, the underlying infrastructure has security flaws. Gamers Nexus demonstrated that an LG TV can be exploited to gain local root access, after which it can record audio from attached devices even when the primary microphone is muted. On some models, muting the microphone does not disconnect it but merely lowers the gain, leaving audio recoverable through amplification.
Separately, the Shai-Halud worm has returned to the NPM repository after 111 days of quiet. The worm was one of several that hit package repositories in the spring of 2026, installing backdoors, stealing cryptocurrency wallets, and harvesting login credentials and authentication tokens before infecting every package those tokens could reach. On September 7, 2026, four additional packages uploaded to NPM were found infected with the original Shai-Halud code, matching known public signatures rather than a new variant. The discovery suggests that NPM's stated practice of scanning every uploaded package did not catch an exact match for a known major threat, raising doubts about how effectively the repository could detect a new one.
Meanwhile, an apparent ransomware attack against Boston Scientific continues to affect the company, with the full scope of the incident still unfolding. The combination of a massive Microsoft patch load, persistent supply chain threats, and ongoing corporate breaches underscores a challenging week for security teams across industries.
