Home / Blog / Recast Blog / September 2026 Third-Party Vulnerabilities and Patches 

September 2026 Third-Party Vulnerabilities and Patches 

Published On Oct 9, 2026 by Tuukka Tiainen Tuukka Tiainen
5 min

September brought a lot of vulnerabilities. During the month we identified 1,374 unique vulnerabilities across 77 applications, and vendors released 166 patched versions to fix them. That is a big swing from August, which landed at 853, so month over month the count rose by roughly 61%. It puts September second only to July in everything we have ever recorded, ahead of June, and far above the 80 to 140 range that was completely normal through 2024 and 2025.  

So, the brief dip in August really was just a breather, not a change in direction. The shape of this month is worth a closer look though. The vulnerability count climbed high while the number of affected applications actually came down, from 85 in August to 77 in September. In other words, a lot more vulnerabilities landed on slightly fewer products, which is a strong sign that the activity was packed into a small number of very busy vendors. 

Just like in recent months, most of this comes from the large, coordinated security releases that Chromium-based browsers ship. Chromium products on their own accounted for about 811 of the 1,374 vulnerabilities, and once you add Firefox, Waterfox, and Pale Moon, the browser category makes up close to three quarters of everything we saw. What stood out this month is that Brave led the pack with 761 vulnerabilities across seven releases, ahead of Microsoft Edge at 652 and Google Chrome at 466. This was because Brave shipped several Chromium version bumps during the month, and each one pulled in another batch of upstream fixes.  

The single biggest update was Microsoft Edge 153.0.4234.32, which closed 466 vulnerabilities on its own. Because Chromium fixes flow down into every browser built on top of it, one upstream release spreads the same hundreds of fixes across several products and channels, so these numbers say more about how Chromium coordinates its patching than about hundreds of separate findings. That same effect is why fewer applications can carry so many more vulnerabilities, and why one busy month for Chromium moves our totals so sharply. 

Notable vulnerabilities in September third-party patches 

The vulnerabilities below stand out either because a working exploit already exists or because they carry an elevated EPSS score above 0.1. Both raise the odds of real-world abuse and shorten the time you have to patch safely, so they are the ones worth prioritizing. This month four cleared the bar, and all already have known exploits and sit in CISA’s Known Exploited Vulnerabilities catalog, so none of these are theoretical. 

CVE-2026-85046 is the standout this month, and it’s a textbook example of the patch gap in action. It’s a high-severity type confusion vulnerability in V8, the JavaScript engine inside Google Chrome and Chromium-based Microsoft Edge. It lets a remote attacker run code inside the browser sandbox through a crafted web page. It carries a CVSS score of 8.8, is confirmed exploited in the wild, sits in CISA’s Known Exploited Vulnerabilities catalog, and holds the highest EPSS score we saw all month at about 0.49. What makes it notable isn’t the bug on its own, but how it was used. According to Microsoft Threat Intelligence, several China-based threat actors, including Violet Typhoon, chained this flaw with a second Chromium bug (CVE-2026-87491) and a Windows local privilege escalation zero day (CVE-2026-85880) to move from a single malicious web page all the way to full SYSTEM control.  

The victims were reached through spear phishing links that quietly redirected them to the final browser exploit. The timing is the real lesson. Google shipped the underlying V8 fixes on August 7 and 11, but the Chromium browsers built on top, including Edge and Chrome, didn’t deliver them to users until early September because of their own release cycles. Attackers started using the chain on August 20, right inside that gap when the fix existed but had not reached most machines yet. This is exactly the pattern we keep warning about: The patch was available, but the time it took to actually land on endpoints is what opened the door. It affects Chrome before 152.0.7977.82, and Edge users got the fix in the September release. Anyone running a Chromium-based browser should make sure it’s fully up to date. More information is available in CISA’s KEV entry, the Google Chrome release notes, and the Volexity report. 

CVE-2026-87491 is the second browser zero day this month and the other Chromium half of the exploit chain described above. It’s a high severity out of bounds write in V8, again affecting Google Chrome and Chromium-based browsers. Like the first one, it allows code execution inside the sandbox through a crafted web page. It carries a CVSS score of 8.8, a working exploit exists in the wild, and it’s listed in CISA’s KEV catalog. It affects Chrome before 153.0.8010.36. Its EPSS score is still low at about 0.03, but the confirmed real-world exploitation is the reason it earns a mention. It’s fixed in a later update than CVE-2026-85046, so Chrome needs to be on version 153.0.8010.36 or newer to close both. More information is available in CISA’s KEV entry and the Google Chrome release notes. 

CVE-2026-82078 is the most severe of the group by score. Like the browser bugs above, it was put to work in the wild almost right away. It’s a critical vulnerability in PaperCut MF and NG print management software, rated CVSS 9.4, where unsafe handling in the server code lets an attacker run arbitrary code in the security context of the PaperCut server. A known exploit exists and is listed in CISA’s KEV catalog. What stands out is how it was used. GreyNoise tracked a campaign, later picked up by Microsoft Threat Intelligence, in which a likely Russian speaking actor used AI agents and public offensive tools to build, test, and automate exploitation of this flaw together with CVE-2026-81578.  

Starting around the end of August the actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, then moved deeper with credential theft, LSASS memory access, and registry secret collection. They were able to reach full domain administrator control in twelve of those organizations. PaperCut has been a favorite target before, and past intrusions have ended in extortion, so this one deserves quick attention. PaperCut disclosed both bugs on August 27 and warned they were already being exploited, telling customers to treat exposed servers as potentially breached. The fix ships in PaperCut MF and NG versions 24.1.10, 25.0.13, and 26.0.5. More information is available in the PaperCut security advisory, CISA’s KEV entry, and the GreyNoise report. 

CVE-2026-81578 is the second PaperCut MF and NG flaw this month and the partner of the critical bug above. It’s a high-severity authentication bypass rated CVSS 8.8. In the same AI driven campaign, the attacker used it to slip past login before chaining the code execution flaw to take over the server. A known exploit exists and is listed in CISA’s KEV catalog. The fix ships in PaperCut MF and NG versions 24.1.10, 25.0.13, and 26.0.5. More information is available in the PaperCut security advisory and CISA’s KEV entry. 

Taken together, these four show both sides of what we’ve been talking about all year. The Chrome chain shows the patch gap at work, where the fix existed upstream but had not yet reached endpoints when attackers moved in. The PaperCut campaign shows attackers using AI agents to turn fresh vulnerabilities into mass exploitation within days. In both cases what mattered most was how quickly the fix actually reached the machine. 

Browser security updates in September 2026 

Browser updates were once again the biggest driver of vulnerability activity in September, following the same pattern we’ve seen all year. The table below breaks the counts down by browser. This month Brave led the way with 761 vulnerabilities addressed across seven releases, with Microsoft Edge close behind at 652 across seven, and Google Chrome at 466. Because all these browsers are built on Chromium, most of these fixes trace back to the same upstream security releases, so the counts are better read as one coordinated patching effort than as separate findings. Mozilla-based browsers were much quieter by comparison. Mozilla Firefox fixed 173 vulnerabilities, and its 115, 140, and 153 branches handled another 72, 54, and 43. Waterfox, which is also built on Firefox, remediated another 88, and Pale Moon added 12. Interestingly, Vivaldi and Opera didn’t ship updates that reached our catalog this month, which is a small reminder that not every Chromium browser moves on the same schedule. Put together, these browser numbers make up the large majority of everything fixed this month, which is why a single busy month for Chromium can move our totals so sharply. 

Browser Vulnerabilities Updates 
Google Chrome 466 6 
Microsoft Edge 652 7 
Brave Browser 761 7 
Mozilla Firefox 173 3 
Mozilla Firefox 115 72 3 
Mozilla Firefox 140 54 2 
Mozilla Firefox 153 43 1 
Pale Moon 12 2 
Waterfox 88 3 

Microsoft product updates included in September 2026 third-party patches 

Microsoft issued security updates for several other products: 

  • Microsoft .NET Runtime 10.0 
  • Microsoft .NET Runtime 8.0 
  • Microsoft .NET Runtime 9.0 
  • Microsoft .NET SDK 10.0 
  • Microsoft .NET SDK 8.0 
  • Microsoft .NET SDK 9.0 
  • Microsoft 365 Access Runtime 
  • Microsoft 365 Apps 
  • Microsoft ASP.NET Core Runtime 10.0 
  • Microsoft ASP.NET Core Runtime 8.0 
  • Microsoft ASP.NET Core Runtime 9.0 
  • Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 
  • Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 
  • Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 
  • Microsoft Edge for Business 
  • Microsoft Project 
  • Microsoft Visio 
  • Microsoft Visual Studio 2019 Enterprise 
  • Microsoft Visual Studio 2019 Professional 
  • Microsoft Visual Studio 2022 Enterprise 
  • Microsoft Visual Studio 2022 Professional 
  • Microsoft Visual Studio Code 
  • Microsoft Windows Desktop Runtime 10.0 
  • Microsoft Windows Desktop Runtime 8.0 
  • Microsoft Windows Desktop Runtime 9.0 

Detailed list of September third-party patches 

ProductName Version Name Vulnerabilities remediated 
7-Zip 26.03 1 
Apache Tomcat 10 10.1.60 12 
Apache Tomcat 11 11.0.26 12 
Apache Tomcat 9 9.0.122 12 
Autodesk AutoCAD 2024 2024.1.9 27 
Autodesk AutoCAD 2025 2025.1.4 24 
Autodesk AutoCAD 2026 2026.1.2 4 
Autodesk AutoCAD LT 2024 2024.1.9 7 
Autodesk AutoCAD LT 2025 2025.1.4 4 
Brave Browser 1.94.117 327 
Brave Browser 1.94.119 26 
Brave Browser 1.94.121 12 
Brave Browser 1.95.101 230 
Brave Browser 1.95.102 42 
Brave Browser 1.95.104 16 
Brave Browser 1.96.59 108 
Brave Origin 1.94.117 327 
Brave Origin 1.94.119 26 
Brave Origin 1.94.121 12 
Brave Origin 1.95.101 230 
Brave Origin 1.95.102 42 
Brave Origin 1.95.104 16 
Brave Origin 1.96.59 108 
Devolutions Remote Desktop Manager 2026.2.18.0 1 
dnGrep 5.0.57.0 1 
Docker Desktop 4.90.0 2 
Docker Desktop 4.90.0.238679 2 
Docker Desktop 4.92.0 1 
Docker Desktop 4.92.0.240144 1 
EcoStruxure IT Data Center Expert 9.2.0 2 
Electron 42.11.1 15 
EnterpriseDB Corporation PostgreSQL 14 14.24.3 24 
EnterpriseDB Corporation PostgreSQL 14 14.24.4 24 
EnterpriseDB Corporation PostgreSQL 15 15.19.3 24 
EnterpriseDB Corporation PostgreSQL 15 15.19.4 24 
EnterpriseDB Corporation PostgreSQL 16 16.15.3 25 
EnterpriseDB Corporation PostgreSQL 16 16.15.4 25 
EnterpriseDB Corporation PostgreSQL 17 17.11 50 
EnterpriseDB Corporation PostgreSQL 17 17.11.3 25 
EnterpriseDB Corporation PostgreSQL 17 17.11.4 25 
EnterpriseDB Corporation PostgreSQL 18 18.6.3 28 
EnterpriseDB Corporation PostgreSQL 18 18.6.4 28 
Erlang OTP 28.5.0.6 16 
Erlang OTP 28.5.0.7 3 
Erlang OTP 29.0.6.0 16 
Erlang OTP 29.1.1.0 3 
GoLand 2026.2.2.1 1 
Google Chrome 152.0.7977.76 24 
Google Chrome 152.0.7977.76 25 
Google Chrome 152.0.7977.76 2 
Google Chrome 152.0.7977.83 12 
Google Chrome 153.0.8010.36 230 
Google Chrome 153.0.8010.37 230 
Google Chrome 153.0.8010.47 42 
Google Chrome 153.0.8010.48 42 
Google Chrome 153.0.8010.52 16 
Google Chrome 153.0.8010.53 16 
Google Chrome 154.0.8037.57 108 
Google Chrome 154.0.8037.58 108 
Google Chrome 154.0.8037.93 32 
Google Chrome 153.0.8010.36 230 
Google Chrome for Business 152.0.7977.76 12 
Google Chrome for Business 152.0.7977.76 26 
Google Chrome for Business 153.0.8010.37 230 
Google Chrome for Business 153.0.8010.37 229 
Google Chrome for Business 153.0.8010.48 42 
Google Chrome for Business 153.0.8010.53 16 
Google Chrome for Business 154.0.8037.58 108 
Google Chrome for Business 154.0.8037.93 32 
Google Chrome for Consumers 152.0.7977.76 26 
Google Chrome for Consumers 152.0.7977.76 3 
Google Chrome for Consumers 153.0.8010.37 230 
Google Chrome for Consumers 153.0.8010.48 42 
Google Chrome for Consumers 153.0.8010.53 16 
Google Chrome for Consumers 154.0.8037.58 108 
Google Chrome for Consumers 154.0.8037.93 32 
Google Chrome for Education 152.0.7977.76 26 
Google Chrome for Education 152.0.7977.76 13 
Google Chrome for Education 153.0.8010.37 229 
Google Chrome for Education 153.0.8010.37 230 
Google Chrome for Education 153.0.8010.48 42 
Google Chrome for Education 153.0.8010.53 16 
Google Chrome for Education 154.0.8037.58 108 
Google Chrome for Education 154.0.8037.93 32 
IntelliJ IDEA 2026.2.2 5 
IntelliJ IDEA 2026.2.3 1 
Microsoft .NET Runtime 10.0 10.0.12 6 
Microsoft .NET Runtime 8.0 8.0.31 5 
Microsoft .NET Runtime 8.0 8.0.31.36420 5 
Microsoft .NET Runtime 9.0 9.0.20 6 
Microsoft .NET SDK 10.0 10.0.401 6 
Microsoft .NET SDK 8.0 8.0.425 5 
Microsoft .NET SDK 8.0 8.4.2526.42109 5 
Microsoft .NET SDK 9.0 9.0.318 6 
Microsoft 365 Access Runtime 2608 (Build 16.0.20326.20144) 100 
Microsoft 365 Apps 2608 (Build 16.0.20326.20142) 100 
Microsoft 365 Apps 2608 (Build 16.0.20326.20144) 100 
Microsoft 365 Apps 2608 (Build 16.0.20326.20144) 85 
Microsoft ASP.NET Core Runtime 10.0 10.0.12 6 
Microsoft ASP.NET Core Runtime 8.0 8.0.31 5 
Microsoft ASP.NET Core Runtime 8.0 8.0.31.26421 5 
Microsoft ASP.NET Core Runtime 9.0 9.0.20 6 
Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 10.0.12 6 
Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 8.0.31.26421 5 
Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 9.0.20 6 
Microsoft Edge for Business 152.0.4191.62 278 
Microsoft Edge for Business 152.0.4191.62 23 
Microsoft Edge for Business 152.0.4191.66 255 
Microsoft Edge for Business 152.0.4191.66 7 
Microsoft Edge for Business 152.0.4191.66 8 
Microsoft Edge for Business 153.0.4234.32 210 
Microsoft Edge for Business 153.0.4234.32 466 
Microsoft Edge for Business 153.0.4234.46 35 
Microsoft Edge for Business 153.0.4234.46 294 
Microsoft Edge for Business 153.0.4234.48 269 
Microsoft Edge for Business 153.0.4234.48 14 
Microsoft Edge for Business 154.0.4258.37 94 
Microsoft Edge for Business 154.0.4258.37 93 
Microsoft Edge for Business 154.0.4258.37 352 
Microsoft Edge for Business 154.0.4258.48 2 
Microsoft Edge for Business 154.0.4258.48 255 
Microsoft Project 2608 (Build 16.0.20326.20144) 100 
Microsoft Visio 2608 (Build 16.0.20326.20142) 100 
Microsoft Visio 2608 (Build 16.0.20326.20142) 96 
Microsoft Visio 2608 (Build 16.0.20326.20144) 100 
Microsoft Visual Studio 2019 Enterprise 16.11.37627.13 2 
Microsoft Visual Studio 2019 Professional 16.11.37627.13 2 
Microsoft Visual Studio 2022 Enterprise 17.14.37628.2 9 
Microsoft Visual Studio 2022 Professional 17.14.37628.2 9 
Microsoft Visual Studio Code 1.136.2 12 
Microsoft Windows Desktop Runtime 10.0 10.0.12 6 
Microsoft Windows Desktop Runtime 8.0 8.0.31.36421 5 
Microsoft Windows Desktop Runtime 9.0 9.0.20 6 
Mozilla Firefox 155.0 26 
Mozilla Firefox 156.0 56 
Mozilla Firefox 156.0 55 
Mozilla Firefox 156.0 16 
Mozilla Firefox 156.0 58 
Mozilla Firefox 156.0 15 
Mozilla Firefox 156.0 5 
Mozilla Firefox 156.0 62 
Mozilla Firefox 156.0 68 
Mozilla Firefox 156.0 51 
Mozilla Firefox 156.0 12 
Mozilla Firefox 156.0 3 
Mozilla Firefox 156.0 4 
Mozilla Firefox 156.0 50 
Mozilla Firefox 157.0 75 
Mozilla Firefox ESR 115 115.40.0 11 
Mozilla Firefox ESR 115 115.41.0 4 
Mozilla Firefox ESR 115 115.41.0 3 
Mozilla Firefox ESR 115 115.41.0 5 
Mozilla Firefox ESR 115 115.41.0 16 
Mozilla Firefox ESR 115 115.41.0 12 
Mozilla Firefox ESR 115 115.41.0 2 
Mozilla Firefox ESR 115 115.42.0 43 
Mozilla Firefox ESR 140 140.15.0 11 
Mozilla Firefox ESR 140 140.17.0 43 
Mozilla Firefox ESR 153 153.4.0 43 
Mozilla Thunderbird 155.0 26 
Mozilla Thunderbird 155.0 28 
Mozilla Thunderbird 155.0 30 
Mozilla Thunderbird 155.0 29 
Mozilla Thunderbird 156.0 75 
Mozilla Thunderbird 157.0 75 
Mozilla Thunderbird 157.0 76 
Mozilla Thunderbird 157.0 76 
Mozilla Thunderbird ESR 140 140.15.0 14 
Mozilla Thunderbird ESR 140 140.16.0 31 
Mozilla Thunderbird ESR 153 153.2.0 26 
Mozilla Thunderbird ESR 153 153.2.0 3 
Mozilla Thunderbird ESR 153 153.2.0 12 
Mozilla Thunderbird ESR 153 153.2.0 5 
Mozilla Thunderbird ESR 153 153.2.0 2 
Mozilla Thunderbird ESR 153 153.2.0 16 
Mozilla Thunderbird ESR 153 153.2.0 22 
Mozilla Thunderbird ESR 153 153.2.0 15 
Mozilla Thunderbird ESR 153 153.2.0 4 
Mozilla Thunderbird ESR 153 153.3.0 31 
Mozilla Thunderbird ESR 153 153.3.1 31 
nginx 1.30.5 1 
nginx 1.31.6 1 
OpenSSL 3.4.8 12 
OpenSSL 3.5.9 13 
OpenSSL 3.6.5 13 
OpenSSL 4.0.3 14 
OpenSSL Light 3.4.8 12 
OpenSSL Light 3.5.9 13 
OpenSSL Light 3.6.5 13 
OpenSSL Light 4.0.3 14 
Pale Moon 35.0.0 7 
Pale Moon 35.0.1 5 
PaperCut MF 24.1.10.76610 2 
PaperCut MF 25.0.13.76604 2 
PaperCut MF 26.0.5.76602 2 
PaperCut NG 24.1.10.76611 2 
PaperCut NG 25.0.13.76605 2 
PaperCut NG 26.0.5.76603 2 
pgAdmin 4 9.18 5 
Python 3.13 3.13.16 4 
Python 3.13 3.13.16 1 
Python 3.13 3.13.16 3 
Python 3.14 3.14.8 3 
Python 3.14 3.14.8 7 
TeamCity 2026.2 3 
TeamViewer 15.64.8.0 5 
TeamViewer 15.82.6.0 5 
TeamViewer Host 15.82.6 5 
TeamViewer Host 15.82.6.0 5 
VisualSVN Server 5.4.9 28 
Waterfox 6.7.2 48 
Waterfox 6.7.2 24 
Waterfox 6.7.3 63 
Waterfox 6.7.3 126 
Waterfox 6.7.5 1 
Waterfox 6.7.5 2 
Wireshark 4.4.19 51 
Wireshark 4.6.9 60 
Zulu JRE 16.32.15.0 3 

Share