Launches

Microsoft's September Update Breaks Records With 974 Patches, Two Already Under Attack

Microsoft's latest security release addresses nearly 1,000 flaws in a single month, but two vulnerabilities are already being actively exploited in the wild.

·3 min read
Microsoft Fixes 974 Flaws in Record Patch Tuesday
Microsoft Fixes 974 Flaws in Record Patch Tuesday

The September 2026 Patch Tuesday from Microsoft has set a new benchmark for vulnerability remediation, with the company releasing fixes for 974 security flaws simultaneously. This unprecedented volume includes 119 vulnerabilities rated as critical, alongside 723 issues impacting Windows and 111 affecting Office. The release dwarfs previous months, which saw 570 vulnerabilities in July and 400 in August, a pattern that security experts attribute partly to Microsoft's expanding reliance on artificial intelligence for flaw detection.

Two zero-days need immediate attention

Among the hundreds of fixes, two vulnerabilities stand out as requiring urgent action: CVE-2026-81963 and CVE-2026-85880. Both are already being weaponized by threat actors in real-world attacks. CVE-2026-81963 represents an elevation-of-privilege vulnerability within the Windows Update Stack, while CVE-2026-85880 is a heap-based buffer overflow affecting Windows Advanced Local Procedure Call (ALPC). Each flaw potentially grants attackers SYSTEM-level access to compromised machines.

According to Jack Bicer of Action1, CVE-2026-81963 permits a low-privileged local attacker to escalate to SYSTEM privileges without requiring user involvement. Similarly, Mike Walters from Action1 explained that CVE-2026-85880 enables attackers to break out of low-privilege AppContainer sandboxes and obtain SYSTEM privileges. Amol Sarwate of Cohesity emphasized their criticality, stating that "In a record-setting Patch Tuesday of [974] fixes, top priority goes to the two actively exploited Windows flaws (CVE-2026-85880 and CVE-2026-81963)," because they allow adversaries to deepen control over Windows systems from an initial compromise.

The bigger enterprise risk

Beyond the exploited pair, researchers have flagged 20 additional flaws as potentially capable of spreading without authentication or user interaction. CVE-2026-69730, a Windows DNS Server vulnerability with a CVSS score of 9.8, has drawn particular concern. Dustin Childs of Trend Micro's Zero Day Initiative drew a parallel to SigRed, the severe DNS Server flaw from 2020, warning that "We haven't seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed, that reality could change fast."

Critical infrastructure components beyond DNS are also at risk, including DHCP, Remote Desktop Services, Netlogon, NFS and Exchange Server. CVE-2026-55007 in Exchange Server deserves special attention, as it permits remote code execution when servers process malicious Visio attachments. Though the attack requires sustained low-memory conditions to succeed, no user action is necessary once the attachment reaches the server.

Patch priority matters more than the headline number

The sheer volume of September's release carries an important lesson for IT departments: treating all 974 patches with equal urgency is neither practical nor necessary. Organizations must first address the two actively exploited zero-days, followed by infrastructure components including DNS, DHCP, Remote Desktop, Exchange, Netlogon and identity systems. For the remaining Office and endpoint vulnerabilities, IT teams should leverage Microsoft's guidance and their own asset inventories to rank fixes according to organizational exposure and business importance.

While artificial intelligence is enabling Microsoft to identify and fix vulnerabilities at an accelerating pace, enterprise teams remain constrained by finite deployment resources and time. The convergence of actively exploited flaws and potentially wormable vulnerabilities in this month's release underscores why strategic prioritization has become essential.