September brought a lot of vulnerabilities. During the month we identified 1,374 unique vulnerabilities across 77 applications, and vendors released 166 patched versions to fix them. That is a big swing from August, which landed at 853, so month over month the count rose by roughly 61%. It puts September second only to July in everything we have ever recorded, ahead of June, and far above the 80 to 140 range that was completely normal through 2024 and 2025.
So, the brief dip in August really was just a breather, not a change in direction. The shape of this month is worth a closer look though. The vulnerability count climbed high while the number of affected applications actually came down, from 85 in August to 77 in September. In other words, a lot more vulnerabilities landed on slightly fewer products, which is a strong sign that the activity was packed into a small number of very busy vendors.
Just like in recent months, most of this comes from the large, coordinated security releases that Chromium-based browsers ship. Chromium products on their own accounted for about 811 of the 1,374 vulnerabilities, and once you add Firefox, Waterfox, and Pale Moon, the browser category makes up close to three quarters of everything we saw. What stood out this month is that Brave led the pack with 761 vulnerabilities across seven releases, ahead of Microsoft Edge at 652 and Google Chrome at 466. This was because Brave shipped several Chromium version bumps during the month, and each one pulled in another batch of upstream fixes.
The single biggest update was Microsoft Edge 153.0.4234.32, which closed 466 vulnerabilities on its own. Because Chromium fixes flow down into every browser built on top of it, one upstream release spreads the same hundreds of fixes across several products and channels, so these numbers say more about how Chromium coordinates its patching than about hundreds of separate findings. That same effect is why fewer applications can carry so many more vulnerabilities, and why one busy month for Chromium moves our totals so sharply.

Notable vulnerabilities in September third-party patches
The vulnerabilities below stand out either because a working exploit already exists or because they carry an elevated EPSS score above 0.1. Both raise the odds of real-world abuse and shorten the time you have to patch safely, so they are the ones worth prioritizing. This month four cleared the bar, and all already have known exploits and sit in CISA’s Known Exploited Vulnerabilities catalog, so none of these are theoretical.
CVE-2026-85046 is the standout this month, and it’s a textbook example of the patch gap in action. It’s a high-severity type confusion vulnerability in V8, the JavaScript engine inside Google Chrome and Chromium-based Microsoft Edge. It lets a remote attacker run code inside the browser sandbox through a crafted web page. It carries a CVSS score of 8.8, is confirmed exploited in the wild, sits in CISA’s Known Exploited Vulnerabilities catalog, and holds the highest EPSS score we saw all month at about 0.49. What makes it notable isn’t the bug on its own, but how it was used. According to Microsoft Threat Intelligence, several China-based threat actors, including Violet Typhoon, chained this flaw with a second Chromium bug (CVE-2026-87491) and a Windows local privilege escalation zero day (CVE-2026-85880) to move from a single malicious web page all the way to full SYSTEM control.
The victims were reached through spear phishing links that quietly redirected them to the final browser exploit. The timing is the real lesson. Google shipped the underlying V8 fixes on August 7 and 11, but the Chromium browsers built on top, including Edge and Chrome, didn’t deliver them to users until early September because of their own release cycles. Attackers started using the chain on August 20, right inside that gap when the fix existed but had not reached most machines yet. This is exactly the pattern we keep warning about: The patch was available, but the time it took to actually land on endpoints is what opened the door. It affects Chrome before 152.0.7977.82, and Edge users got the fix in the September release. Anyone running a Chromium-based browser should make sure it’s fully up to date. More information is available in CISA’s KEV entry, the Google Chrome release notes, and the Volexity report.
CVE-2026-87491 is the second browser zero day this month and the other Chromium half of the exploit chain described above. It’s a high severity out of bounds write in V8, again affecting Google Chrome and Chromium-based browsers. Like the first one, it allows code execution inside the sandbox through a crafted web page. It carries a CVSS score of 8.8, a working exploit exists in the wild, and it’s listed in CISA’s KEV catalog. It affects Chrome before 153.0.8010.36. Its EPSS score is still low at about 0.03, but the confirmed real-world exploitation is the reason it earns a mention. It’s fixed in a later update than CVE-2026-85046, so Chrome needs to be on version 153.0.8010.36 or newer to close both. More information is available in CISA’s KEV entry and the Google Chrome release notes.
CVE-2026-82078 is the most severe of the group by score. Like the browser bugs above, it was put to work in the wild almost right away. It’s a critical vulnerability in PaperCut MF and NG print management software, rated CVSS 9.4, where unsafe handling in the server code lets an attacker run arbitrary code in the security context of the PaperCut server. A known exploit exists and is listed in CISA’s KEV catalog. What stands out is how it was used. GreyNoise tracked a campaign, later picked up by Microsoft Threat Intelligence, in which a likely Russian speaking actor used AI agents and public offensive tools to build, test, and automate exploitation of this flaw together with CVE-2026-81578.
Starting around the end of August the actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, then moved deeper with credential theft, LSASS memory access, and registry secret collection. They were able to reach full domain administrator control in twelve of those organizations. PaperCut has been a favorite target before, and past intrusions have ended in extortion, so this one deserves quick attention. PaperCut disclosed both bugs on August 27 and warned they were already being exploited, telling customers to treat exposed servers as potentially breached. The fix ships in PaperCut MF and NG versions 24.1.10, 25.0.13, and 26.0.5. More information is available in the PaperCut security advisory, CISA’s KEV entry, and the GreyNoise report.
CVE-2026-81578 is the second PaperCut MF and NG flaw this month and the partner of the critical bug above. It’s a high-severity authentication bypass rated CVSS 8.8. In the same AI driven campaign, the attacker used it to slip past login before chaining the code execution flaw to take over the server. A known exploit exists and is listed in CISA’s KEV catalog. The fix ships in PaperCut MF and NG versions 24.1.10, 25.0.13, and 26.0.5. More information is available in the PaperCut security advisory and CISA’s KEV entry.
Taken together, these four show both sides of what we’ve been talking about all year. The Chrome chain shows the patch gap at work, where the fix existed upstream but had not yet reached endpoints when attackers moved in. The PaperCut campaign shows attackers using AI agents to turn fresh vulnerabilities into mass exploitation within days. In both cases what mattered most was how quickly the fix actually reached the machine.

Browser security updates in September 2026
Browser updates were once again the biggest driver of vulnerability activity in September, following the same pattern we’ve seen all year. The table below breaks the counts down by browser. This month Brave led the way with 761 vulnerabilities addressed across seven releases, with Microsoft Edge close behind at 652 across seven, and Google Chrome at 466. Because all these browsers are built on Chromium, most of these fixes trace back to the same upstream security releases, so the counts are better read as one coordinated patching effort than as separate findings. Mozilla-based browsers were much quieter by comparison. Mozilla Firefox fixed 173 vulnerabilities, and its 115, 140, and 153 branches handled another 72, 54, and 43. Waterfox, which is also built on Firefox, remediated another 88, and Pale Moon added 12. Interestingly, Vivaldi and Opera didn’t ship updates that reached our catalog this month, which is a small reminder that not every Chromium browser moves on the same schedule. Put together, these browser numbers make up the large majority of everything fixed this month, which is why a single busy month for Chromium can move our totals so sharply.
| Browser | Vulnerabilities | Updates |
| Google Chrome | 466 | 6 |
| Microsoft Edge | 652 | 7 |
| Brave Browser | 761 | 7 |
| Mozilla Firefox | 173 | 3 |
| Mozilla Firefox 115 | 72 | 3 |
| Mozilla Firefox 140 | 54 | 2 |
| Mozilla Firefox 153 | 43 | 1 |
| Pale Moon | 12 | 2 |
| Waterfox | 88 | 3 |
Microsoft product updates included in September 2026 third-party patches
Microsoft issued security updates for several other products:
- Microsoft .NET Runtime 10.0
- Microsoft .NET Runtime 8.0
- Microsoft .NET Runtime 9.0
- Microsoft .NET SDK 10.0
- Microsoft .NET SDK 8.0
- Microsoft .NET SDK 9.0
- Microsoft 365 Access Runtime
- Microsoft 365 Apps
- Microsoft ASP.NET Core Runtime 10.0
- Microsoft ASP.NET Core Runtime 8.0
- Microsoft ASP.NET Core Runtime 9.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 10.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 8.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 9.0
- Microsoft Edge for Business
- Microsoft Project
- Microsoft Visio
- Microsoft Visual Studio 2019 Enterprise
- Microsoft Visual Studio 2019 Professional
- Microsoft Visual Studio 2022 Enterprise
- Microsoft Visual Studio 2022 Professional
- Microsoft Visual Studio Code
- Microsoft Windows Desktop Runtime 10.0
- Microsoft Windows Desktop Runtime 8.0
- Microsoft Windows Desktop Runtime 9.0
Detailed list of September third-party patches
| ProductName | Version Name | Vulnerabilities remediated |
| 7-Zip | 26.03 | 1 |
| Apache Tomcat 10 | 10.1.60 | 12 |
| Apache Tomcat 11 | 11.0.26 | 12 |
| Apache Tomcat 9 | 9.0.122 | 12 |
| Autodesk AutoCAD 2024 | 2024.1.9 | 27 |
| Autodesk AutoCAD 2025 | 2025.1.4 | 24 |
| Autodesk AutoCAD 2026 | 2026.1.2 | 4 |
| Autodesk AutoCAD LT 2024 | 2024.1.9 | 7 |
| Autodesk AutoCAD LT 2025 | 2025.1.4 | 4 |
| Brave Browser | 1.94.117 | 327 |
| Brave Browser | 1.94.119 | 26 |
| Brave Browser | 1.94.121 | 12 |
| Brave Browser | 1.95.101 | 230 |
| Brave Browser | 1.95.102 | 42 |
| Brave Browser | 1.95.104 | 16 |
| Brave Browser | 1.96.59 | 108 |
| Brave Origin | 1.94.117 | 327 |
| Brave Origin | 1.94.119 | 26 |
| Brave Origin | 1.94.121 | 12 |
| Brave Origin | 1.95.101 | 230 |
| Brave Origin | 1.95.102 | 42 |
| Brave Origin | 1.95.104 | 16 |
| Brave Origin | 1.96.59 | 108 |
| Devolutions Remote Desktop Manager | 2026.2.18.0 | 1 |
| dnGrep | 5.0.57.0 | 1 |
| Docker Desktop | 4.90.0 | 2 |
| Docker Desktop | 4.90.0.238679 | 2 |
| Docker Desktop | 4.92.0 | 1 |
| Docker Desktop | 4.92.0.240144 | 1 |
| EcoStruxure IT Data Center Expert | 9.2.0 | 2 |
| Electron | 42.11.1 | 15 |
| EnterpriseDB Corporation PostgreSQL 14 | 14.24.3 | 24 |
| EnterpriseDB Corporation PostgreSQL 14 | 14.24.4 | 24 |
| EnterpriseDB Corporation PostgreSQL 15 | 15.19.3 | 24 |
| EnterpriseDB Corporation PostgreSQL 15 | 15.19.4 | 24 |
| EnterpriseDB Corporation PostgreSQL 16 | 16.15.3 | 25 |
| EnterpriseDB Corporation PostgreSQL 16 | 16.15.4 | 25 |
| EnterpriseDB Corporation PostgreSQL 17 | 17.11 | 50 |
| EnterpriseDB Corporation PostgreSQL 17 | 17.11.3 | 25 |
| EnterpriseDB Corporation PostgreSQL 17 | 17.11.4 | 25 |
| EnterpriseDB Corporation PostgreSQL 18 | 18.6.3 | 28 |
| EnterpriseDB Corporation PostgreSQL 18 | 18.6.4 | 28 |
| Erlang OTP | 28.5.0.6 | 16 |
| Erlang OTP | 28.5.0.7 | 3 |
| Erlang OTP | 29.0.6.0 | 16 |
| Erlang OTP | 29.1.1.0 | 3 |
| GoLand | 2026.2.2.1 | 1 |
| Google Chrome | 152.0.7977.76 | 24 |
| Google Chrome | 152.0.7977.76 | 25 |
| Google Chrome | 152.0.7977.76 | 2 |
| Google Chrome | 152.0.7977.83 | 12 |
| Google Chrome | 153.0.8010.36 | 230 |
| Google Chrome | 153.0.8010.37 | 230 |
| Google Chrome | 153.0.8010.47 | 42 |
| Google Chrome | 153.0.8010.48 | 42 |
| Google Chrome | 153.0.8010.52 | 16 |
| Google Chrome | 153.0.8010.53 | 16 |
| Google Chrome | 154.0.8037.57 | 108 |
| Google Chrome | 154.0.8037.58 | 108 |
| Google Chrome | 154.0.8037.93 | 32 |
| Google Chrome | 153.0.8010.36 | 230 |
| Google Chrome for Business | 152.0.7977.76 | 12 |
| Google Chrome for Business | 152.0.7977.76 | 26 |
| Google Chrome for Business | 153.0.8010.37 | 230 |
| Google Chrome for Business | 153.0.8010.37 | 229 |
| Google Chrome for Business | 153.0.8010.48 | 42 |
| Google Chrome for Business | 153.0.8010.53 | 16 |
| Google Chrome for Business | 154.0.8037.58 | 108 |
| Google Chrome for Business | 154.0.8037.93 | 32 |
| Google Chrome for Consumers | 152.0.7977.76 | 26 |
| Google Chrome for Consumers | 152.0.7977.76 | 3 |
| Google Chrome for Consumers | 153.0.8010.37 | 230 |
| Google Chrome for Consumers | 153.0.8010.48 | 42 |
| Google Chrome for Consumers | 153.0.8010.53 | 16 |
| Google Chrome for Consumers | 154.0.8037.58 | 108 |
| Google Chrome for Consumers | 154.0.8037.93 | 32 |
| Google Chrome for Education | 152.0.7977.76 | 26 |
| Google Chrome for Education | 152.0.7977.76 | 13 |
| Google Chrome for Education | 153.0.8010.37 | 229 |
| Google Chrome for Education | 153.0.8010.37 | 230 |
| Google Chrome for Education | 153.0.8010.48 | 42 |
| Google Chrome for Education | 153.0.8010.53 | 16 |
| Google Chrome for Education | 154.0.8037.58 | 108 |
| Google Chrome for Education | 154.0.8037.93 | 32 |
| IntelliJ IDEA | 2026.2.2 | 5 |
| IntelliJ IDEA | 2026.2.3 | 1 |
| Microsoft .NET Runtime 10.0 | 10.0.12 | 6 |
| Microsoft .NET Runtime 8.0 | 8.0.31 | 5 |
| Microsoft .NET Runtime 8.0 | 8.0.31.36420 | 5 |
| Microsoft .NET Runtime 9.0 | 9.0.20 | 6 |
| Microsoft .NET SDK 10.0 | 10.0.401 | 6 |
| Microsoft .NET SDK 8.0 | 8.0.425 | 5 |
| Microsoft .NET SDK 8.0 | 8.4.2526.42109 | 5 |
| Microsoft .NET SDK 9.0 | 9.0.318 | 6 |
| Microsoft 365 Access Runtime | 2608 (Build 16.0.20326.20144) | 100 |
| Microsoft 365 Apps | 2608 (Build 16.0.20326.20142) | 100 |
| Microsoft 365 Apps | 2608 (Build 16.0.20326.20144) | 100 |
| Microsoft 365 Apps | 2608 (Build 16.0.20326.20144) | 85 |
| Microsoft ASP.NET Core Runtime 10.0 | 10.0.12 | 6 |
| Microsoft ASP.NET Core Runtime 8.0 | 8.0.31 | 5 |
| Microsoft ASP.NET Core Runtime 8.0 | 8.0.31.26421 | 5 |
| Microsoft ASP.NET Core Runtime 9.0 | 9.0.20 | 6 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 | 10.0.12 | 6 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 | 8.0.31.26421 | 5 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 | 9.0.20 | 6 |
| Microsoft Edge for Business | 152.0.4191.62 | 278 |
| Microsoft Edge for Business | 152.0.4191.62 | 23 |
| Microsoft Edge for Business | 152.0.4191.66 | 255 |
| Microsoft Edge for Business | 152.0.4191.66 | 7 |
| Microsoft Edge for Business | 152.0.4191.66 | 8 |
| Microsoft Edge for Business | 153.0.4234.32 | 210 |
| Microsoft Edge for Business | 153.0.4234.32 | 466 |
| Microsoft Edge for Business | 153.0.4234.46 | 35 |
| Microsoft Edge for Business | 153.0.4234.46 | 294 |
| Microsoft Edge for Business | 153.0.4234.48 | 269 |
| Microsoft Edge for Business | 153.0.4234.48 | 14 |
| Microsoft Edge for Business | 154.0.4258.37 | 94 |
| Microsoft Edge for Business | 154.0.4258.37 | 93 |
| Microsoft Edge for Business | 154.0.4258.37 | 352 |
| Microsoft Edge for Business | 154.0.4258.48 | 2 |
| Microsoft Edge for Business | 154.0.4258.48 | 255 |
| Microsoft Project | 2608 (Build 16.0.20326.20144) | 100 |
| Microsoft Visio | 2608 (Build 16.0.20326.20142) | 100 |
| Microsoft Visio | 2608 (Build 16.0.20326.20142) | 96 |
| Microsoft Visio | 2608 (Build 16.0.20326.20144) | 100 |
| Microsoft Visual Studio 2019 Enterprise | 16.11.37627.13 | 2 |
| Microsoft Visual Studio 2019 Professional | 16.11.37627.13 | 2 |
| Microsoft Visual Studio 2022 Enterprise | 17.14.37628.2 | 9 |
| Microsoft Visual Studio 2022 Professional | 17.14.37628.2 | 9 |
| Microsoft Visual Studio Code | 1.136.2 | 12 |
| Microsoft Windows Desktop Runtime 10.0 | 10.0.12 | 6 |
| Microsoft Windows Desktop Runtime 8.0 | 8.0.31.36421 | 5 |
| Microsoft Windows Desktop Runtime 9.0 | 9.0.20 | 6 |
| Mozilla Firefox | 155.0 | 26 |
| Mozilla Firefox | 156.0 | 56 |
| Mozilla Firefox | 156.0 | 55 |
| Mozilla Firefox | 156.0 | 16 |
| Mozilla Firefox | 156.0 | 58 |
| Mozilla Firefox | 156.0 | 15 |
| Mozilla Firefox | 156.0 | 5 |
| Mozilla Firefox | 156.0 | 62 |
| Mozilla Firefox | 156.0 | 68 |
| Mozilla Firefox | 156.0 | 51 |
| Mozilla Firefox | 156.0 | 12 |
| Mozilla Firefox | 156.0 | 3 |
| Mozilla Firefox | 156.0 | 4 |
| Mozilla Firefox | 156.0 | 50 |
| Mozilla Firefox | 157.0 | 75 |
| Mozilla Firefox ESR 115 | 115.40.0 | 11 |
| Mozilla Firefox ESR 115 | 115.41.0 | 4 |
| Mozilla Firefox ESR 115 | 115.41.0 | 3 |
| Mozilla Firefox ESR 115 | 115.41.0 | 5 |
| Mozilla Firefox ESR 115 | 115.41.0 | 16 |
| Mozilla Firefox ESR 115 | 115.41.0 | 12 |
| Mozilla Firefox ESR 115 | 115.41.0 | 2 |
| Mozilla Firefox ESR 115 | 115.42.0 | 43 |
| Mozilla Firefox ESR 140 | 140.15.0 | 11 |
| Mozilla Firefox ESR 140 | 140.17.0 | 43 |
| Mozilla Firefox ESR 153 | 153.4.0 | 43 |
| Mozilla Thunderbird | 155.0 | 26 |
| Mozilla Thunderbird | 155.0 | 28 |
| Mozilla Thunderbird | 155.0 | 30 |
| Mozilla Thunderbird | 155.0 | 29 |
| Mozilla Thunderbird | 156.0 | 75 |
| Mozilla Thunderbird | 157.0 | 75 |
| Mozilla Thunderbird | 157.0 | 76 |
| Mozilla Thunderbird | 157.0 | 76 |
| Mozilla Thunderbird ESR 140 | 140.15.0 | 14 |
| Mozilla Thunderbird ESR 140 | 140.16.0 | 31 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 26 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 3 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 12 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 5 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 2 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 16 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 22 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 15 |
| Mozilla Thunderbird ESR 153 | 153.2.0 | 4 |
| Mozilla Thunderbird ESR 153 | 153.3.0 | 31 |
| Mozilla Thunderbird ESR 153 | 153.3.1 | 31 |
| nginx | 1.30.5 | 1 |
| nginx | 1.31.6 | 1 |
| OpenSSL | 3.4.8 | 12 |
| OpenSSL | 3.5.9 | 13 |
| OpenSSL | 3.6.5 | 13 |
| OpenSSL | 4.0.3 | 14 |
| OpenSSL Light | 3.4.8 | 12 |
| OpenSSL Light | 3.5.9 | 13 |
| OpenSSL Light | 3.6.5 | 13 |
| OpenSSL Light | 4.0.3 | 14 |
| Pale Moon | 35.0.0 | 7 |
| Pale Moon | 35.0.1 | 5 |
| PaperCut MF | 24.1.10.76610 | 2 |
| PaperCut MF | 25.0.13.76604 | 2 |
| PaperCut MF | 26.0.5.76602 | 2 |
| PaperCut NG | 24.1.10.76611 | 2 |
| PaperCut NG | 25.0.13.76605 | 2 |
| PaperCut NG | 26.0.5.76603 | 2 |
| pgAdmin 4 | 9.18 | 5 |
| Python 3.13 | 3.13.16 | 4 |
| Python 3.13 | 3.13.16 | 1 |
| Python 3.13 | 3.13.16 | 3 |
| Python 3.14 | 3.14.8 | 3 |
| Python 3.14 | 3.14.8 | 7 |
| TeamCity | 2026.2 | 3 |
| TeamViewer | 15.64.8.0 | 5 |
| TeamViewer | 15.82.6.0 | 5 |
| TeamViewer Host | 15.82.6 | 5 |
| TeamViewer Host | 15.82.6.0 | 5 |
| VisualSVN Server | 5.4.9 | 28 |
| Waterfox | 6.7.2 | 48 |
| Waterfox | 6.7.2 | 24 |
| Waterfox | 6.7.3 | 63 |
| Waterfox | 6.7.3 | 126 |
| Waterfox | 6.7.5 | 1 |
| Waterfox | 6.7.5 | 2 |
| Wireshark | 4.4.19 | 51 |
| Wireshark | 4.6.9 | 60 |
| Zulu JRE | 16.32.15.0 | 3 |