972 fixes in one Patch Tuesday, and two were already exploited
Key takeaways
- September 2026 Patch Tuesday covered 972 vulnerabilities, 113 rated critical, with two zero-days already being exploited in the wild.
- CVE-2026-73009 is an unauthenticated remote code execution flaw in the Windows SSTP service rated 9.8. Patch it first.
- SonicWall SMA 1000 gateways carry CVE-2026-83548, a pre-authentication SSRF rated a full 10.0.
- Both of the worst flaws sit at the network edge, which is exactly where small networks patch least often.
972 vulnerabilities in a single Patch Tuesday. 113 of them critical, and two already being exploited before the fixes shipped.
September 2026 is the largest single patch cycle on record, and the volume is the least useful thing about it. What matters is the order you work through it in, because two of these flaws sit on the network edge and one of them scores a perfect 10.
Patch this first: CVE-2026-73009
The Windows Secure Socket Tunneling Protocol service carries a remote code execution flaw rated 9.8 and exploitable without authentication. No credentials, no user interaction.
SSTP is a VPN protocol that tunnels over TLS on port 443, which is exactly why it gets left exposed. It looks like ordinary HTTPS traffic to a firewall rule written in a hurry. If a Windows server is terminating SSTP connections from the internet, treat this as the job for today rather than the job for this week.
The 10.0 outside Microsoft
SonicWall addressed CVE-2026-83548 and CVE-2026-83549 in its SMA 1000 remote access gateways. The first is a pre-authentication server-side request forgery rated a full 10.0, which is as bad as the scale goes.
A separate flaw, CVE-2026-5430, also scores 9.8 and involves improper verification of cryptographic signatures leading to account takeover. Remote access appliances are a recurring theme this year. We saw the same pattern with the N-able N-central RCE and with the Cisco ISE zero-day, and in each case the device sitting between the internet and everything else was the one running months-old firmware.
The order to work in
Start with anything internet-facing that terminates a session: VPN concentrators, remote access gateways, management interfaces. Then domain controllers and anything holding credentials. Then workstations, which are important but rarely reachable directly.
Cross-check against the CISA Known Exploited Vulnerabilities catalogue before you start. A KEV listing turns a theoretical priority into a confirmed one, and it is the cheapest filter available for a list this long.
The breaches that landed alongside it
Thomson Reuters disclosed unauthorised access to C-Track court case-management files covering courts in eleven US states and Canada. CenterPoint Energy confirmed a customer data breach after a claimed leak of 7.49 million records.
Neither is connected to the patch cycle, but both are the same story told from the other end. Court records and utility customer data are held in systems that almost nobody outside the organisation thinks about, and they are increasingly where the volume is, as the Florida DMV breach earlier this year showed.
The part worth sitting with is where the two worst flaws live. SSTP and an SMA gateway are both edge devices, and edge devices are the ones a small business or a home lab patches last, if at all. The 972 number will be forgotten by Friday. Those two will not.