- Microsoft has released its largest Patch Tuesday security update to date, addressing 974 vulnerabilities across Windows and other products, including two privilege-escalation flaws that attackers were already exploiting before fixes became available.
- The September 2026 release contains 105 vulnerabilities classified as Critical, including dozens of weaknesses capable of enabling remote code execution.
- The two actively exploited zero-days, tracked as CVE-2026-81963 and CVE-2026-85880, affect fundamental Windows components and could allow attackers who already have some access to a device to obtain SYSTEM-level privileges.
- CISA added both zero-days to its Known Exploited Vulnerabilities catalog, requiring FCEB agencies to patch by September 22, 2026.
- In June, Microsoft addressed approximately 200 vulnerabilities.
- In July, Microsoft addressed between 570 and 620 vulnerabilities.
- In August, Microsoft published 421 vulnerabilities, including one flaw known to have been exploited in the wild.
Microsoft's September Patch Tuesday update has set a new record by addressing 974 vulnerabilities, including two zero-days that have been actively exploited. This unprecedented release includes 105 critical vulnerabilities and highlights the growing impact of AI on vulnerability research and patch management.13
The two zero-days, tracked as CVE-2026-81963 and CVE-2026-85880, affect fundamental Windows components. The first flaw, CVE-2026-81963, involves improper link resolution in the Windows Update Stack, allowing attackers to elevate privileges to SYSTEM. The second, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), also enabling SYSTEM-level access.

Microsoft has not disclosed the identities of the threat actors exploiting these vulnerabilities or the scale of the attacks. However, the urgency of the situation has led the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both flaws to its Known Exploited Vulnerabilities catalog, mandating that Federal Civilian Executive Branch agencies apply the fixes by September 22, 2026.4
This September update surpasses previous records set in June, July, and August, with a total of 999 vulnerabilities resolved, including 723 in Windows, 111 in Office, and 62 in SQL. The rapid adoption of AI-assisted vulnerability research is reshaping software security and enterprise patch management, as noted by experts in the field.567
“The two zero-days, CVE-2026-81963 and CVE-2026-85880, are local privilege-escalation flaws in the Windows Update Stack and ALPC, respectively, both allowing SYSTEM-level access. CISA has mandated federal agencies patch them by September 22, 2026, while Microsoft has not disclosed the attackers or attack scale.”






