Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday
Microsoft Fixes 966 Vulnerabilities in Record-Breaking September Patch Tuesday
Microsoft September Patch Tuesday 2026: Microsoft has released its September 2026 security updates, fixing a record 966 vulnerabilities across its products. The massive security release includes 105 Critical vulnerabilities and two actively exploited zero-day vulnerabilities.
The September 8, 2026 release is being reported as Microsoft’s largest Patch Tuesday security update to date, surpassing recent large releases including 570 vulnerabilities in July and 400 in August.
Microsoft September 2026 Patch Tuesday: Key Highlights
| Particular | Details |
|---|---|
| Patch Tuesday Date | September 8, 2026 |
| Total Vulnerabilities Fixed | 966 |
| Critical Vulnerabilities | 105 |
| Actively Exploited Zero-Days | 2 |
| Elevation of Privilege | 438 |
| Remote Code Execution | 258 |
| Information Disclosure | 173 |
| Denial of Service | 56 |
| Security Feature Bypass | 19 |
| Spoofing | 16 |
Microsoft’s September release addresses vulnerabilities across multiple security categories. The figures above count vulnerabilities released in the September Patch Tuesday update itself; additional Microsoft vulnerabilities had already been addressed earlier in the month. :contentReference[oaicite:1]{index=1}
Two Actively Exploited Microsoft Zero-Days
The most urgent aspect of the September security release is the patching of two actively exploited zero-day vulnerabilities.
CVE-2026-81963 — Windows Update Stack
CVE: CVE-2026-81963
Product: Windows Update Stack
Vulnerability Type: Elevation of Privilege
Status: Actively Exploited
Microsoft patched an elevation-of-privilege vulnerability in the Windows Update Stack that can allow an authorized attacker to elevate privileges locally and potentially obtain SYSTEM-level privileges.
The vulnerability involves improper link resolution before file access, also known as link following. Microsoft has not publicly disclosed detailed information about how the vulnerability was exploited in attacks. :contentReference[oaicite:2]{index=2}
CVE-2026-85880 — Windows ALPC
CVE: CVE-2026-85880
Product: Windows Advanced Local Procedure Call (ALPC)
Vulnerability Type: Elevation of Privilege
Status: Actively Exploited
The second zero-day affects Windows ALPC and involves a heap-based buffer overflow that can allow an authorized attacker to elevate privileges locally.
Microsoft has also not disclosed detailed information about the exploitation observed in attacks. :contentReference[oaicite:3]{index=3}
Why These Zero-Days Are Important
Both vulnerabilities are classified as Elevation of Privilege flaws. These vulnerabilities may be particularly valuable to attackers who already have some level of access to a compromised Windows system.
Successful exploitation can potentially allow an attacker to move from limited privileges to highly privileged access.
This makes the vulnerabilities particularly relevant to:
- Windows desktops and laptops
- Windows servers
- Domain-connected systems
- Administrative workstations
- High-value enterprise systems
- Systems already compromised through another attack vector
105 Critical Vulnerabilities Fixed
The September 2026 Patch Tuesday release includes 105 vulnerabilities rated Critical. Of those Critical vulnerabilities, 81 are remote code execution issues, 20 are elevation-of-privilege issues, two involve information disclosure and one is a security feature bypass. :contentReference[oaicite:4]{index=4}
| Vulnerability Category | Count |
|---|---|
| Elevation of Privilege | 438 |
| Remote Code Execution | 258 |
| Information Disclosure | 173 |
| Denial of Service | 56 |
| Security Feature Bypass | 19 |
| Spoofing | 16 |
Microsoft Patch Tuesday 2026: Why the Number Is So High
The September release is notable because Microsoft fixed 966 vulnerabilities in a single Patch Tuesday release. This follows other unusually large security updates, including approximately 570 vulnerabilities fixed in July and 400 in August. :contentReference[oaicite:5]{index=5}
The growth in vulnerability discovery is also occurring alongside increased use of automation and AI-assisted security research. Faster discovery can help vendors find and fix vulnerabilities earlier, but it also increases the pressure on organizations to deploy security updates quickly.
What Should Windows Users Do?
Microsoft customers should review and deploy the applicable September 2026 security updates as part of their normal patch-management process.
1. Install the September Security Updates
Windows users and enterprise administrators should install applicable September security updates and verify that the updates have been successfully deployed.
2. Prioritize the Two Zero-Days
Security teams should immediately identify systems affected by:
- CVE-2026-81963 — Windows Update Stack
- CVE-2026-85880 — Windows ALPC
Both vulnerabilities have been reported as actively exploited and therefore deserve accelerated remediation. :contentReference[oaicite:6]{index=6}
3. Prioritize Critical Systems
Organizations should prioritize:
- Internet-facing Windows systems
- Windows servers
- Domain controllers
- Remote access infrastructure
- Privileged administrator workstations
- Business-critical systems
4. Verify Patch Deployment
Installing or approving an update is not enough. Security teams should verify successful deployment across the environment using endpoint-management and vulnerability-management tools.
5. Monitor for Suspicious Activity
Security teams should review:
- EDR alerts
- Windows Event Logs
- Authentication activity
- Unexpected privilege changes
- Suspicious process execution
- PowerShell activity
- Lateral-movement indicators
Patch Management Checklist
| Security Task | Priority |
|---|---|
| Review September 2026 Microsoft Security Updates | 🔴 High |
| Identify affected Windows systems | 🔴 High |
| Patch actively exploited vulnerabilities | 🔴 Critical |
| Prioritize internet-facing systems | 🔴 Critical |
| Verify successful patch installation | 🟠 High |
| Review EDR and SIEM alerts | 🟠 High |
| Review privileged account activity | 🟠 High |
| Document remediation | 🟢 Normal |
What This Means for Businesses
For enterprise security teams, the September Patch Tuesday release demonstrates why vulnerability management and patch management should be treated as core cybersecurity controls.
Organizations should consider:
- Risk-based vulnerability prioritization
- Automated endpoint patching
- Accurate asset inventory
- Vulnerability-management integration
- EDR monitoring
- SIEM correlation
- Emergency change procedures
- Patch deployment validation
Organizations should also have a process for accelerating remediation when a vulnerability is confirmed to be actively exploited.
Organizations should review the September 2026 Microsoft security updates immediately and prioritize the two actively exploited Windows zero-days.
References
