Microsoft shattered previous Patch Tuesday thresholds by issuing fixes for 974 software vulnerabilities, including two zero-day flaws actively exploited in the wild, according to official company releases and security reports from September 2026.
Did you know?
According to Tenable, Microsoft’s September updates pushed the year’s total past 2,600 vulnerabilities—more than double the previous record set in 2020, with three months left in the year.
Two Zero-Day Flaws Under Active Attack
According to Microsoft security advisories, the September 2026 update addresses two zero-day vulnerabilities that attackers have weaponized in real-world campaigns. The first, tracked as CVE-2026-85880 with a CVSS score of 7.8, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting the bug. Microsoft noted that an authorized attacker executing code in a low-privilege AppContainer can exploit this flaw locally to escape the sandbox and gain SYSTEM privileges without user interaction.
The second zero-day, tracked as CVE-2026-81963 with a CVSS score of 7.8, involves improper link resolution in the Windows Update Stack. Attribution for this second security defect has been assigned jointly to the Microsoft Threat Intelligence Center (MSTIC) and Romain Deperne, an offensive security researcher working at Airbus Helicopters. Rapid7 lead software engineer Adam Barnett stated that the patch “pressumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter.” Tenable notes that CVE-2026-81963 stands out as the first zero-day and the initial instance of active exploitation among the seven privilege escalation vulnerabilities identified in the Windows Update Stack since 2022.

U.S. Mandate and Federal Deadlines
Following the release, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply the fixes by September 22, 2026.
Pro Tip for IT Administrators
Action1 director of vulnerability research Jack Bicer recommends that IT and security professionals carefully distinguish between urgent flaws requiring immediate deployment and those fitting standard update cycles, helping them avoid paralysis caused by massive patch volumes.
Breakdown of the September 2026 Patch Volume
The massive software update spans multiple product lines. According to published metrics, Windows received 723 patches, Office and Office 2016 accounted for 111 fixes, SQL Server absorbed 62, and Developer Tools received 22. When including 25 non-Microsoft CVEs, the total count reaches 999 resolved security shortcomings. Nearly 90% of the patches fall into three primary categories: privilege escalation, remote code execution, and information disclosure.
Other notable vulnerabilities fixed this month include:
* CVE-2026-55007: A double free vulnerability in Microsoft Exchange Server (CVSS 8.1) enabling network remote code execution.
* CVE-2026-80097: An improper authentication vulnerability in Microsoft Authenticator (CVSS 8.6) allowing local privilege escalation.
* CVE-2026-69465: A missing authorization vulnerability in Microsoft Office SharePoint (CVSS 8.8) permitting remote code execution.
* CVE-2026-69525: A use-after-free vulnerability in Windows Remote Desktop Services (CVSS 9.8) allowing network-based code execution.
Industry Reaction to AI-Driven Vulnerability Discovery
Security researchers attribute the soaring patch volumes largely to automated testing and artificial intelligence. TrendAI’s Zero Day Initiative noted that Microsoft has patched a total of 2,760 security flaws this year alone. Fortra associate director of Security R&D Tyler Reguly observed that large vendors are actively reducing the attack surface.
“Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence,” Reguly stated. Satnam Narang, senior staff research engineer at Tenable, added that organizations must prioritize remediation based on real-world reachability and risk context rather than raw CVE counts.

Frequently Asked Questions
What are the two zero-day vulnerabilities patched in September 2026?
Microsoft patched CVE-2026-85880, an ALPC heap-based buffer overflow, and CVE-2026-81963, a Windows Update Stack link resolution flaw. Both allow local attackers to gain SYSTEM privileges and were actively exploited in the wild.
How many total vulnerabilities did Microsoft patch in September 2026?
Microsoft addressed 974 vulnerabilities across its software portfolio, which reached 999 total fixes when including non-Microsoft CVEs.
What did CISA require agencies to do regarding these updates?
CISA added the two zero-day flaws to its Known Exploited Vulnerabilities catalog, ordering Federal Civilian Executive Branch agencies to deploy patches by September 22, 2026.
Why are Microsoft patch counts increasing so dramatically?
Industry analysts point to automated discovery methods and AI-assisted vulnerability research as key drivers behind the record-breaking number of patches released in 2026.
Join the Discussion
How is your IT department managing record-high patch counts this year? Share your strategy in the comments below or subscribe to our newsletter for weekly enterprise security updates.