Patch Monday September 2026 - Zero Days from Apple and Chrome

Unsubscribe

Welcome to my September 2026 edition of Patch Monday.

This month’s patch cycle includes security updates from Adobe, Apple, Google Chrome and Mozilla. We have zero days from Apple and Google.

For Google Chrome we have two zero days:

Google Chrome had another exceptionally busy month. In the past 30 days alone, Chrome has addressed 418 vulnerabilities. This may sound like a large number of updates but remember that last month had almost double that. Chrome also received five separate version updates during that period, addressing 21 Critical-rated vulnerabilities.

Apple had one zero day in the past 30 days.

Mozilla & Zoom: Business as Usual For Mozilla

September was a relatively normal patch cycle for Mozilla. There were various updates in the past 30 days for Firefox and Thunderbird. I've put the latest of the updates in the below. If you see a link below that says "Multiple CVE's" and you click on it and there is only one CVE listed then there are other updates on a different date for the same software. Phew! That sentence was almost as long as the chart below!

Thanks as always for your continued support. Feel free to register for my next webinar: "Understanding Entra Privileged Identity Management, What PIM Covers and Where It Stops". Register now!

3rd Party Patch Priorities for September

If you're trying to prioritize your September patch workload, I'd put these two at the top:

1. Google Chrome — Two zero days. Patch immediately if affected.
2. Apple iOS, iPadOS, Tahoe and Sequoia — One zero day. Get endpoints updated.

As always, review the complete table below for affected products, versions, CVEs, severity ratings, and recommended updates.

Stay secure, stay patched, and happy patching!

Follow randyfsmith on X

Subscribe to Randy Franklin Smith on Facebook

So, without further ado, here’s the chart of non-Microsoft 3rd party patches that affect Windows platforms in the past month.

Patch data provided by:

Identifier

Vendor/
Product

Affected Versions

Date Released
by Vendor

Vulnerability Info

Vender Severity / Our Recommendation

Multiple CVE's

Adobe Bridge

15.1.7 (LTS) and earlier

16.0.6 and earlier

9/22/2026

Arbitrary Code Execution,
Memory Exposure
Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Connect

12.11 and earlier

Android Mobile App 4.4 and earlier

9/22/2026

Arbitrary Code Execution,
Arbitrary File System Read,
Privilege Escalation,
Security Feature Bypass

Critical Priority 2: Update within 30 days

Multiple CVE's

Adobe Content Credentials

Rust SDK c2pa-v0.89.2 and earlier

C2PA Tool c2patool-v0.26.70 and earlier

9/22/2026

Application Denial of Service,
Security Feature Bypass,

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Experience Manager

AEM 6.5 LTS Forms SP2 and earlier

AEM .5 Forms 6.5.25 and earlier

9/22/2026

Arbitrary Code Execution,
Privilege Escalation,
Security Feature Bypass

Critical Priority 2: Update within 30 days

Multiple CVE's

Adobe InDesign

ID21.5 and earlier

ID20.5.4 and earlier

9/22/2026 Application Denial of Service Important Priority 3: Update at admins discretion

CVE-2026-84395

Adobe Premiere Pro

Premiere 26.3.2 and earlier

Premiere Pro 25.6.5 and earlier

9/22/2026 Security Feature Bypass

Critical Priority 3: Update at admins discretion

Multiple CVE's

Adobe Substance 3D Modeler

1.22.6 and earlier

9/22/2026 Arbitrary Code Execution

Critical Priority 3: Update at admins discretion

Multiple CVE's

Apple iOS and iPadOS

Before 27

Before 26.7.1

9/28/2026 Arbitrary Code Execution,
Authentication Issue,
Authorization Issue,
Buffer Overflow,
Cross Site Scripting,
Data Leak,
Denial of Service,
Information Disclosure,
Input Validation Issue,
Integer Overflow,
Logic Issue,
Memory Disclosure,
Out of Bounds,
Path Traversal,
Permissions Issue,
Privacy Issue,
Race Condition,
Security Feature Bypass,
System Termination,
Type Confusion,
Use After Free

Update ASAP

Multiple CVE's

Apple macOS Tahoe

Before 26.7.1

9/28/2026 Authentication Issue,
Authorization Issue,
Buffer Overflow,
Code Injection,
Denial of Service,
Double Free,
File Quarantine Bypass,
Information Disclosure,
Input Validation Issue,
Integer Overflow,
Logic Issue,
Logging Issue,
Memory Corruption,
Out of Bounds,
Parsing issue,
Path Traversal Issue,
Permissions issue,
Privacy Issue,
Race condition,
Resource Exhaustion,
Type Confusion,
Uninitialized Memory,
Use After Free,
Validation Issue

Update ASAP

Multiple CVE's

Apple macOS Sequoia

Before 15.8.1

9/28/2026 Authentication Issue,
Authorization Issue,
Buffer Overflow,
Certificate Validation Issue,
Denial of Service,
Double Free,
File Quarantine Bypass,
Information Disclosure,
Input Validation Issue,
Integer Overflow,
Logic Issue,
Logging Issue,
Memory Corruption,
Memory Initialization,
Out of Bounds,
Parsing Issue,
Path Traversal Issue,
Permissions Issue,
Privacy Issue,
Race Condition,
Resource Exhaustion,
Type Confusion,
Use-After-Free,
Validation Issue

Update ASAP

Multiple CVE's

Apple macOS Golden Gate

Before 27

9/14/2026 Authentication Issue,
Authorization Issue,
Buffer Overflow,
Credential-handling Issue,
Cross-origin Issue,
Data-protection Issue,
Gatekeeper Bypass,
Improper Entitlement Verification,
Information Disclosure,
Input Validation Issue,
Integer Overflow,
Logging Issue,
Logic Issue,
Memory Corruption,
Out-of-bounds,
Path Traversal,
Path Validation Issue,
Permissions Issue,
Quarantine Bypass,
Race Condition,
Sandbox Escape,
Security Feature Bypass,
Symlink Handling Issue,
Type Confusion,
Uninitialized Memory,
Use After Free,
Validation Issue

Update After Testing

Multiple CVE's

Apple tvOS

Before 27

9/14/2026 Access Control Issue,
Authorization Issue,
Buffer Overflow,
Certificate Validation Issue,
Cryptographic Issue,
Double Free,
Information Disclosure,
Information Leakage,
Integer Overflow,
Logic Issue,
Logging Issue,
Memory Corruption Issue,
Memory Initialization Issue,
Out of Bounds,
Permissions Issue,
Privacy Issue,
Race Condition,
Type Confusion,
Uninitialized Memory
Use After Free

Update After Testing

Multiple CVE's

Apple watchOS

Before 27

9/14/2026 Access Control Issue,
Authorization Issue,
Buffer Overflow,
Certificate Validation Issue,
Cryptographic Issue,
Double Free,
File Quarantine Bypass,
Information Disclosure,
Information Leakage,
Integer Overflow,
Logic Issue,
Logging Issue,
Memory Corruption Issue,
Memory Initialization Issue,
Null Pointer Dereference,
Out of Bounds,
Path Traversal,
Permissions Issue,
Privacy Issue,
Race Condition,
Type Confusion,
Use After Free

Update After Testing

Multiple CVE's

Apple visionOS

Before 27

9/14/2026 Access Control Issue,
Authentication Issue,
Authorization Issue,
Buffer Overflow,
Certificate Validation Issue,
Double Free,
File Quarantine Bypass,
Heap Buffer Overflow,
Information Disclosure,
Information Leakage,
Integer Overflow,
Logic Issue,
Logging Issue,
Memory Corruption,
Memory Initialization,
Null Pointer Dereference,
Out Of Bounds,
Path Handling Issue,
Permissions Issue,
Privacy Issue,
Race Condition,
Type Confusion,
Uninitialized Memory,
Use After Free

Update After Testing

Multiple CVE's

Apple Safari

Before 27

9/14/2026 Cross Site Scripting,
Information Leak,
Permissions Issue,
Process Termination,
Use After Free

Update After Testing

CVE-2026-65393

Apple Xcode

Before 27

9/14/2026 Permissions Issue

Update After Testing

Multiple CVE's

Google
Chrome

Before 154.0.8037.57/.58 (Windows/Mac)

Before
154.0.8037.57 (Linux)

9/22/2026

Buffer Overflow,
Clickjacking,
Code Injection,
Confused Deputy,
Cross Site Request Forgery,
Cross Site Scripting,
Improper Input,
Inappropriate Implementation,
Incorrect Authorization,
Incomplete Cleanup,
Information Leak,
Insufficient Policy,
Integer Overflow,
Memory Corruption,
Missing Authorization,
Observable Discrepancy,
Out of Bounds Read/Write,
Privilege Elevation,
Race Condition,
Type Confusion,
UI Misrepresentation,
Uninitialized Use,
Use After Free
Update ASAP

Multiple CVE's

Mozilla Thunderbird

Before 155

9/16/2026

Buffer Overflow,
Clickjacking

Denial of Service,
Incorrect Boundary,
Information Disclosure,
Memory Safety Violation,
Mitigation Bypass,
Out of Bounds,
Privilege Escalation,
Race Condition,
Sandbox Escape,
Security Feature Bypass,
Site Isolation Issue,
Spoofing,
Use After Free

Update after testing

Multiple CVE's

Mozilla Firefox

Before 156

9/15/2026

Clickjacking,
Denial of Service,
Incorrect Boundary,
Information Disclosure,
Integer Overflow,
Mitigation Bypass,
Privilege Escalation,
Race Condition,
Sandbox Escape,
Site Isolation Issue,
Spoofing,
Use After Free

Update after testing

Multiple CVE's

Mozilla Firefox ESR

Before 153.3

9/15/2026

Clickjacking,
Denial of Service,
Incorrect Boundary,

Information Disclosure,
Mitigation Bypass,
Privilege Escalation,
Race Condition,
Sandbox Escape,
Site Isolation Issue,
Spoofing,
Use After Free

Update after testing

Multiple CVE's

Mozilla Firefox for iOS

Before 155.1

9/8/2026

Denial of Service

Update after testing

Thanks as always for reading and best wishes on security,

Randy Franklin Smith

Follow randyfsmith on Twitter Subscribe to Randy Franklin Smith on Facebook

Click here to unsubscribe

Ultimate Windows Security is a division of Monterey Technology Group, Inc. ©2006-2026 Monterey Technology Group, All rights reserved. You may forward this email in its entirety but all other rights reserved.

1162 Manus Chapel Road, Mill Springs, NC 28756

Note: We do our best to provide quality information and expert commentary but use all information at your own risk.