Microsoft shipped 973 fixes on 9 September. For 82 of them, anyone running Office on a Mac got a note instead of a patch.
That count comes from Angela Gunn, a senior threat researcher at Sophos X-Ops, who reads the monthly release in full. In her breakdown of the September haul, 68 Office patches carried a notice in Microsoft's own summary saying the vulnerability applies to Office for Mac but the fix was not ready. Two of those are Critical-severity, 9.8 CVSS Base issues. Thirteen more also have no Mac patch version yet and list the Preview Pane as a vector. One more has no Mac patch and, as Gunn puts it, simply viewing the message in Outlook is a vector.
Why a preview pane changes the math
A vulnerability that needs somebody to open a booby-trapped document is asking for a mistake. One that fires from the preview pane is not: the mail client renders the content to show you what arrived, and that is enough. For the fourteen entries in that group, a Mac user has no patch to apply and no click to avoid. Gunn's read is that Microsoft simply ran out of runway on these, not that they were judged unimportant.
Nobody said Windows was the whole story
The Mac gap sits inside a release that is enormous by any earlier standard. Gunn counts 973 CVEs across 39 product families, 718 of them in Windows, 114 rated Critical by Microsoft and 284 carrying a CVSS Base score of 8.0 or higher. None were publicly disclosed before the patches landed. Two were already under attack, both Important-severity elevation-of-privilege bugs in Windows, and we covered that pair when the release shipped.
Gunn's argument is that the machinery was not built for what she calls the AI-finder age. The average CVSS Base score per month has drifted down from a rock-steady 7.8 in the pre-AI era to 7.4, which is the signature of more bugs found rather than worse ones: the volume climbs while the typical severity eases. September is traditionally one of the lighter months in the Patch Tuesday rhythm. This one was not.
What a Mac Office user can actually do
Not a great deal, which is the point. Sophos lists all 82 pending entries on a dedicated sheet in the workbook it publishes alongside the analysis, and Microsoft's habit with these is to ship the Mac fix later and update the published CVE information when it arrives. Until then the honest advice is to track those CVE pages and treat Office on macOS as carrying known, unfixed issues rather than assume Patch Tuesday covered the estate. Mac administrators have had a full fortnight of this already, with 257 fixes across iOS 27 and macOS 27 the week before.
A month with 973 fixes in it is easy to file away as a big number and move on. The part worth remembering is the 82 that were not fixes at all.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.