Microsoft’s September 2026 Patch Tuesday has set a new record, delivering fixes for 974 security vulnerabilities across Windows and a broad range of enterprise products, including two zero-day flaws that the company says are already being exploited in the wild.[3][7][8] In its own breakdown of the release, Microsoft also flags another 58 vulnerabilities as “more likely to be exploited,” underscoring the elevated risk facing unpatched systems in the weeks ahead.[9][11][15]
The official tally of 974 Microsoft CVEs for the September release is reflected in the company’s Security Update Guide and multiple independent analyses, though researchers note slight discrepancies depending on how shared advisories and cloud-only issues are counted.[3][6][11] One detailed breakdown attributes 723 of the vulnerabilities to Windows, with 111 in Office, 62 in SQL Server, 22 in Developer Tools, 16 in SharePoint Server, 12 in Azure, 10 in Skype for Business, nine in Exchange Server, and nine in other product families, highlighting how widely the risk surface extends across typical enterprise deployments.[9] Several tracking firms report totals ranging from 964 to 973 CVEs when they exclude issues Microsoft patches directly in its own infrastructure, but all agree this is the largest Patch Tuesday on record.[2][6][12]
The two exploited zero-days at the center of the update – CVE-2026-85880 and CVE-2026-81963 – are both elevation-of-privilege bugs in core Windows components, making them particularly valuable for attackers seeking to move from initial footholds to full system compromise.[3][4][7] CVE-2026-85880 affects the Windows Advanced Local Procedure Call (ALPC) system and allows a local attacker to escalate privileges, a flaw that several vendors say has already been used in real-world attacks.[3][4][8] CVE-2026-81963 targets the Windows Update Stack and is rated with a CVSS v3 score of 7.8 and an “Important” severity, but it likewise enables privilege escalation and has been observed under active exploitation prior to the patches becoming available.[7][10][11] Multiple analyses point out that neither zero-day was publicly disclosed ahead of Patch Tuesday, giving defenders an opportunity to close these holes before exploitation broadens beyond targeted campaigns.[8][9][15]
Beyond the two zero-days, Microsoft and external researchers highlight a long tail of high-risk vulnerabilities that warrant rapid attention, including 20 “wormable” bugs that could enable self-propagating attacks if weaponized.[5][9][12] Security researchers also draw attention to a critical remote code execution issue in Exchange Server that can be triggered via a specially crafted Visio email attachment, a classic delivery vector for phishing campaigns that target corporate mail infrastructure.[5][7][9] With dozens more vulnerabilities classified by Microsoft as likely to be exploited, organizations face a substantial risk if they leave widely deployed services such as Windows, Office, and Exchange unpatched.[11][12][15]
The sheer size of this Patch Tuesday release is already testing patch-management processes, especially for IT teams that must balance urgent remediation against the risk of operational disruption from such a large volume of changes.[2][6][12] Analyses of Microsoft’s severity ratings suggest that roughly 100 or more of the patched vulnerabilities fall into the “Critical” category – those most likely to result in remote code execution or complete system takeover – with the remainder generally classified as “Important,” reflecting meaningful but more constrained impact.[6][8][10] External tallies from threat-intelligence and vulnerability-management vendors also point out that a non-trivial subset of the flaws are being addressed not only on desktops and servers but in cloud services, which Microsoft patches directly and which may fall outside traditional patch windows.[2][6][9]
For defenders, the immediate priority is to deploy updates for the two exploited zero-days and any vulnerabilities rated Critical on systems that are exposed to the internet or widely reachable inside the network, focusing first on Windows, Exchange, and Office installations.[3][5][7] Security teams should also review Microsoft’s exploitability assessments to identify the 58 vulnerabilities flagged as likely to be targeted and incorporate them into near-term patch cycles, while monitoring for new exploit code or indicators related to CVE-2026-85880 and CVE-2026-81963.[11][14][15] Given the unprecedented scale of this Patch Tuesday, organizations that cannot patch everything at once will need to lean on asset inventories, threat modeling, and compensating controls such as stricter access controls and endpoint detection to buy time, but the consensus from researchers is clear: September’s Microsoft updates mark a high-water line that defenders ignore at their peril.[1][5][8]
References
- Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in Septembe
- 974 Patches Just Exceeded Your Test Window – IPBan Pro
- September 2026 Patch Tuesday fixes 974 Microsoft CVEs
- Microsoft breaks Patch Tuesday record with 974-CVE deluge
- Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
- Microsoft fixes record 964 flaws, including 2 exploited zero- …
- Microsoft Patches Record 974 Vulnerabilities, Including …
- Microsoft Plugs Nearly 1,000 Security Holes
- ap7i.com | Microsoft’s September 2026 Patch Tuesday: 974 …
- Microsoft Security Update Summary (8. September 2026)
- Patch Tuesday September 2026: 973 CVEs, 2 Zero-Days
- Microsoft Patch Tuesday hits 999 flaws with two exploited
- Must Read – Security Affairs
- IntelFreed.com | Cybersecurity Intelligence Weather Report
