Microsoft September 2026 Patch Tuesday has set an unwelcome record: 966 vulnerabilities patched in a single update cycle, including two actively exploited zero-days. That figure eclipses every previous Patch Tuesday in the company’s history, and the sheer scale of it is starting to raise questions about what is driving the volume.

A Record-Breaking Microsoft September 2026 Patch Tuesday

Of the 966 flaws addressed, 105 are rated Critical. Within that Critical tier, 81 are remote code execution vulnerabilities, 20 are elevation of privilege, two are information disclosure, and one is a security feature bypass. Across all severity levels, the breakdown runs to 438 elevation of privilege vulnerabilities, 258 remote code execution, 173 information disclosure, 56 denial of service, 19 security feature bypass, and 16 spoofing.

Malwarebytes puts the CVE count at 964, with 104 rated Critical and 860 rated Important, a slight variance from the totals above, likely reflecting which pre-released fixes each tracker includes in its tally. Either way, the headline number dwarfs the 570 flaws fixed in July and the 400 addressed in August.

Worth noting: today’s total does not include a further 204 flaws fixed earlier this month in products such as Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Edge, Microsoft Fabric, and Power Automate. Microsoft counts those separately from its Patch Tuesday totals.

The surge in volume follows Microsoft‘s decision to deploy an AI-powered vulnerability discovery system across its software portfolio. When you give a machine the job of finding bugs at scale, it finds bugs at scale, and they all need patching eventually.

The Two Zero-Days: Windows Update Stack and ALPC

Both actively exploited vulnerabilities this month are elevation of privilege flaws, meaning an attacker already on a system can use them to climb to SYSTEM-level privileges. Neither requires remote access to trigger, but that is cold comfort when attackers routinely chain initial access with local privilege escalation.

CVE-2026-81963 affects the Windows Update Stack. Microsoft describes it as an improper link resolution before file access (a ‘link following’ bug) that allows an authorised attacker to elevate privileges locally. The flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre (MSTIC). According to CCB Belgium, this is the first Windows Update Stack elevation of privilege vulnerability exploited as a zero-day since 2022, a gap that makes its reappearance worth flagging for defenders. Microsoft has not shared details on how the flaw was used in attacks.

CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). The flaw allows an authorised attacker to elevate privileges locally, and was discovered by Volexity and by Mark Kelly, David Galazin, and Jeremy Hedges. Again, Microsoft has not disclosed how it was exploited. Both CVE-2026-81963 and CVE-2026-85880 carry a CVSS score of 7.8, according to Rapid7.

Defenders should treat both as priority patches regardless of CVSS scores. Active exploitation means real attackers have working code, and SYSTEM privileges are about as bad as it gets for post-compromise impact.

What Else Landed This Month

The breadth of this update is striking even by recent standards. Highlights beyond the zero-days include Critical-rated remote code execution vulnerabilities in Windows Hello, Windows Imaging Component, Windows DHCP Server, Windows Hyper-V, Skype for Business, Microsoft Office Outlook, and multiple Windows DNS components. The Windows Biometric Service alone accounts for dozens of elevation of privilege entries in this month’s list.

Several other vendors also shipped notable fixes around the same period. Adobe released a patch for a maximum-severity zero-day in Adobe Commerce, tracked as StyleSmuggler, which was exploited to backdoor websites. SonicWall addressed two SMA1000 zero-days being chained in remote code execution attacks. Google pushed Chrome updates for an actively exploited high-severity flaw in the V8 engine. ConnectWise shared mitigations for a ScreenConnect Remote Access vulnerability it plans to patch shortly. N-able released an emergency hotfix for a maximum-severity remote code execution flaw in its N-central remote monitoring and management platform.

For Windows administrators, the immediate priorities are clear: patch the two actively exploited zero-days first, then work through the Critical-rated RCE vulnerabilities in internet-facing and identity-related components. With 204 additional fixes already shipped earlier in the month, the full scope of September’s remediation work is considerably larger than the headline figure alone suggests.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version