Microsoft Patches Record 974 Flaws, Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two Windows zero-days under active exploitation. The U.S.

Microsoft fixed a record 974 security flaws in its September 2026 Patch Tuesday update, including two Windows zero-day vulnerabilities that attackers are already exploiting. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both exploited flaws to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by September 22, 2026.
This monthly release shatters previous records. According to the source, The Hacker News, Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May. Satnam Narang, a senior staff research engineer at Tenable, noted this month's total is a nearly 70% increase over the previous record of 569 set in July. The Zero Day Initiative reports Microsoft has patched 2,760 flaws so far in 2026, more than double the total for the entire record-setting year of 2020.
Two Actively Exploited Windows Zero-Days
The update patches two vulnerabilities that Microsoft confirmed are being exploited in the wild. Both are local privilege escalation flaws with a CVSS score of 7.8.
CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC). Microsoft's advisory states an attacker with code execution in a low-privilege AppContainer could exploit this to escape the sandbox and gain SYSTEM privileges without additional user interaction. Cybersecurity firms Volexity and Proofpoint reported this bug.
CVE-2026-81963 is an improper link resolution flaw in the Windows Update Stack. Adam Barnett, lead software engineer at Rapid7, said the patch for all supported Windows versions "presumably tightens up controls to prevent the Windows Update Stack from following a malicious link." Tenable notes this is the first zero-day and first exploited flaw in the Windows Update Stack since 2022. Romain Deperne of Airbus Helicopters and Microsoft's own Threat Intelligence Center discovered it.
Microsoft detected exploitation efforts but did not disclose the actors behind them or any confirmed victim breaches.
Breakdown of the Massive Patch Batch
The 974 vulnerabilities span Microsoft's software portfolio. Over 110 of them are rated critical. Three vulnerability types account for nearly 90% of the fixes: privilege escalation, remote code execution, and information disclosure.
| Product Category | Number of Flaws Patched |
|---|---|
| Windows | 723 |
| Office & Office 2016 | 111 |
| SQL | 62 |
| Developer Tools | 22 |
Including fixes for 25 non-Microsoft CVEs, the total number of vulnerabilities resolved reaches 999.
Other Notable Critical Vulnerabilities
Beyond the zero-days, the update addresses several other high-severity flaws across Microsoft's ecosystem. These include multiple critical remote code execution vulnerabilities with CVSS scores as high as 9.8.
- CVE-2026-55007 (CVSS 8.1): A double free vulnerability in Microsoft Exchange Server allowing network-based code execution.
- CVE-2026-80097 (CVSS 8.6): An improper authentication flaw in Microsoft Authenticator enabling local privilege escalation.
- CVE-2026-69465 (CVSS 8.8): A missing authorization bug in Microsoft Office SharePoint permitting authorized attackers to execute code over a network.
- CVE-2026-65669 (CVSS 9.6): An injection vulnerability in SQL Server allowing unauthorized network privilege escalation.
Several use-after-free and buffer overflow flaws in core Windows services like Remote Desktop, DNS, DHCP, and the Shell also received critical patches.
The Overwhelming Scale and Prioritization Challenge
The unprecedented volume presents a major challenge for IT and security teams. "At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first," said Jack Bicer, director of vulnerability research at Action1. He emphasized the need to quickly separate vulnerabilities demanding immediate action from those that can follow normal deployment cycles.
Despite the huge count, the number of flaws expected to impact most organizations remains low, and there is no reported correlating spike in active exploits. Narang stressed that organizations must understand which vulnerabilities apply to their systems, assess if they are reachable over the internet, and prioritize based on this risk context.
Tyler Reguly, associate director of Security R&D at Fortra, suggested the high numbers indicate positive progress. "We need to remember that these large CVE counts are a good thing as we're reducing the attack surface before attackers get a chance," he said. Reguly believes that once long-standing, hard-to-find vulnerabilities are fixed, Patch Tuesday will return to a more typical cadence.
The update is now available through all standard Microsoft distribution channels.





