Tyler RegulyDavid GalazinSatnam NarangJack BicerMark KellyAdam BarnettRomain DeperneJeremy HedgesOpenAIFortraRapid7MicrosoftVolexityMicrosoft Threat Intelligence CenterProofpointTenableU.S. Cybersecurity and Infrastructure Security AgencyAirbus HelicoptersAnthropicAction1

Microsoft's record September Patch Tuesday fixes 974 flaws, including two Windows zero-days already exploited in the wild; CISA adds both to KEV catalog

Microsoft's September Patch Tuesday update addresses a record 974 vulnerabilities, including two zero-days exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency has added these flaws to its Known Exploited Vulnerabilities catalog, mandating fixes by September 22, 2026.

LinkedIn LinkedIn+1 source9 September 2026 · 07:39 UTC
CuriousCats Full Story

Microsoft's September Patch Tuesday update has set a new record by addressing 974 vulnerabilities, including two zero-days that have been actively exploited. This unprecedented release includes 105 critical vulnerabilities and highlights the growing impact of AI on vulnerability research and patch management.13

The two zero-days, tracked as CVE-2026-81963 and CVE-2026-85880, affect fundamental Windows components. The first flaw, CVE-2026-81963, involves improper link resolution in the Windows Update Stack, allowing attackers to elevate privileges to SYSTEM. The second, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), also enabling SYSTEM-level access.

Microsoft has not disclosed the identities of the threat actors exploiting these vulnerabilities or the scale of the attacks. However, the urgency of the situation has led the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both flaws to its Known Exploited Vulnerabilities catalog, mandating that Federal Civilian Executive Branch agencies apply the fixes by September 22, 2026.4

This September update surpasses previous records set in June, July, and August, with a total of 999 vulnerabilities resolved, including 723 in Windows, 111 in Office, and 62 in SQL. The rapid adoption of AI-assisted vulnerability research is reshaping software security and enterprise patch management, as noted by experts in the field.567

Key Insight
“The two zero-days, CVE-2026-81963 and CVE-2026-85880, are local privilege-escalation flaws in the Windows Update Stack and ALPC, respectively, both allowing SYSTEM-level access. CISA has mandated federal agencies patch them by September 22, 2026, while Microsoft has not disclosed the attackers or attack scale.”
CuriousCats studied:
1
LinkedInLinkedIn
“Microsoft has released its largest Patch Tuesday security update to date, addressing over 900 vulnerabilities across Windows and other products, including two privilege-escalation flaws that attackers were already exploiting before fixes became available.”
LinkedIn →
2
The Hacker NewsThe Hacker News
“Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.”
The Hacker News →
Ask CuriousCats
What vulnerabilities were fixed in September?
Who are the attackers behind the zero-days?
Why is CISA involved in this patch update?
Are these zero-days common in software?
How does this impact other Windows vulnerabilities?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats