Microsoft’s September 2026 Patch Tuesday Marks Record-Breaking 966 Fixes, Including Two Zero-Days
In a massive security update, Microsoft has released patches for an astonishing 966 flaws, including two actively exploited zero-day vulnerabilities. This record-breaking number far surpasses previous months’ totals, with the company’s AI-powered vulnerability discovery system likely contributing to the surge in identified weaknesses.
The patch release addresses 105 “Critical” vulnerabilities, with a staggering breakdown of 438 elevation of privilege, 258 remote code execution, and 173 information disclosure vulnerabilities. The update also includes patches for two zero-day flaws that have been exploited by attackers: CVE-2026-81963 and CVE-2026-85880.
CVE-2026-81963 is an elevation of privilege vulnerability in the Windows Update Stack, allowing attackers to gain SYSTEM privileges with ease. Microsoft warns that this flaw was due to improper link resolution before file access, a subtle yet critical mistake that has been exploited by malicious actors. The company credits Romain Deperne and its Threat Intelligence Centre (MSTIC) for discovering the issue.
The second zero-day vulnerability, CVE-2026-85880, affects Windows Advanced Local Procedure Call (ALPC). Microsoft explains that this flaw is due to a heap-based buffer overflow in ALPC, enabling attackers to elevate privileges locally. Unfortunately, no details have been shared on how these flaws were exploited in attacks, leaving users with more questions than answers.
While the sheer number of patches may seem daunting, it’s essential to note that many of these vulnerabilities are not unique to September’s Patch Tuesday. In fact, Microsoft has already fixed 204 flaws earlier this month, including those affecting Azure AI Language and Microsoft Edge (Chromium-based). This influx of updates underscores the importance of staying up-to-date with security patches and being proactive in defending against emerging threats.
Other notable vendors have also released significant security updates in August, including Adobe’s fix for a zero-day Commerce vulnerability, Cisco’s updates for various products, and Google’s Chrome security patches. As always, it’s crucial to remain vigilant and stay informed about the latest security developments to ensure your systems are protected from these and future threats.
In light of this Patch Tuesday, users should prioritize installing the latest security updates as soon as possible. While it may seem overwhelming, taking proactive steps towards patching vulnerabilities will significantly reduce the risk of exploitation by malicious actors. Consider implementing a robust vulnerability management strategy that includes regular monitoring, testing, and deployment of patches to stay ahead of emerging threats.
Source: Bleeping Computer — 2026-09-08