Microsoft’s September Patch Tuesday Brings Record-Breaking 966 Fixes, Including Two Zero-Day Vulnerabilities
In a major security update, Microsoft has released patches for an astonishing 966 flaws, marking the largest ever Patch Tuesday release. Among these fixes are two zero-day vulnerabilities that have been actively exploited by attackers. The updates address critical issues in Windows and other Microsoft products, highlighting the ongoing threat of cyber attacks and the importance of regular patching.
The sheer number of vulnerabilities patched this month is staggering, with 105 classified as “Critical” and 81 of those being remote code execution flaws. This means that hackers could potentially take control of affected systems without needing to authenticate or authorize access. The other critical vulnerabilities include elevation of privilege, information disclosure, and security feature bypass issues.
Microsoft’s decision to use an AI-powered vulnerability discovery system has clearly paid off, as the number of patches released this month far exceeds previous records. In July, Microsoft fixed 570 security flaws, while August saw 400 patches released. The increased focus on identifying vulnerabilities is likely a response to the growing threat landscape and the need for more proactive security measures.
Two zero-day vulnerabilities have been addressed in this Patch Tuesday update, both of which allow attackers to gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack, while CVE-2026-85880 targets the Windows Advanced Local Procedure Call (ALPC). In each case, Microsoft has provided patching guidance, but the details of how these vulnerabilities were exploited in attacks remain unclear.
The inclusion of zero-day vulnerabilities highlights the importance of keeping systems up-to-date. Attackers often target newly discovered flaws before patches are available, so it’s essential that users and administrators apply patches as soon as possible. In this case, Microsoft has taken a proactive approach by addressing two actively exploited vulnerabilities, demonstrating its commitment to prioritizing security.
Other companies have also released updates and advisories in recent weeks, including Adobe, Cisco, ConnectWise, CrowdStrike, Google, Hewlett Packard Enterprise (HPE), and MicroTik. These patches address various flaws, from remote code execution vulnerabilities to high-severity zero-day exploits. The breadth of these releases underscores the ongoing threat landscape and the need for vigilance in maintaining security.
In light of this Patch Tuesday update, it’s essential that users take immediate action to protect their systems. This includes applying all available patches, enabling updates, and ensuring that antivirus software is up-to-date. Regularly reviewing system logs and monitoring network traffic can also help identify potential threats before they become major issues. By staying informed and proactive, individuals and organizations can reduce the risk of cyber attacks and ensure the security of their data and systems.
Source: Bleeping Computer — 2026-09-08