Microsoft’s September 2026 Patch Tuesday update set a new record, addressing 973 vulnerabilities across its products—a stark increase from the 600 disclosed in July 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that two of these flaws, CVE-2026-81963 and CVE-2026-85880, are already being exploited by hackers, prompting federal agencies to prioritize remediation by September 22.
The update surpassed previous records, with Microsoft fixing 723 flaws in Windows, 222 in Office, and additional vulnerabilities in SQL, Azure, and Exchange Server. Tenable’s Satnam Narang noted that the 973 vulnerabilities pushed the year’s total over 2,600, more than double the 2020 record.
CVE-2026-85880, a heap buffer overflow in Windows’ Advanced Local Procedure Call (ALPC) component, allows local attackers to escalate privileges without additional user interaction. Microsoft’s advisory emphasized that this is the second ALPC-related zero-day patched since April 2023. CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack, enables attackers to bypass security measures and gain System-level access. Tenable’s Narang warned that these vulnerabilities are critical for ransomware chains, as they provide initial footholds for broader attacks.
Microsoft posts a record number of bugs for Patch Tuesday as
According to Nightwing cybersecurity expert Nick Carroll, over 22,000 corporate Exchange servers remain unpatched against weaponized exploit code. Nightwing’s analysis highlighted that flaws like CVE-2026-81963 are often the first step in ransomware campaigns, where hackers use phishing to gain initial access and then leverage privileged elevation to spread across networks. Microsoft’s advisory for CVE-2026-85880 noted that an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required.
Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out. The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in Windows Update Stack, the components used for Windows update installation. The vulnerability also allows local attackers to elevate their privileges to System. As Narang notes, this is the first Update Stack security weakness to be flagged as a zero-day of the seven flaws resolved in the component over the past five years.
The update included Servicing Stack Updates (SSUs), which are classified as critical updates. They apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016. SecurityWeek highlighted specific flaws like CVE-2026-55007 (remote code execution (RCE) in Exchange Server), CVE-2026-80097 (elevation of privilege (EoP) in Authenticator), CVE-2026-69465 (RCE in SharePoint), CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), ZDI’s Dustin Childs says. Childs noted that 20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction.
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Adobe also addressed over 170 vulnerabilities, including a critical zero-day in Adobe Commerce, as part of the broader patching cycle. The surge in vulnerabilities has sparked debate about the role of AI in cybersecurity. Tenable’s Narang noted that AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. He urged organizations to focus on risk context, asking: Which vulnerabilities actually apply to you? Are they reachable and exploitable?
Fortra associate director Tyler Reguly attributed the patch volume to proactive vendor efforts to reduce attack surfaces. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence,
Reguly said. However, he emphasized that prioritization remains critical, suggesting that gift cards for extra coffee for admins might be more effective than generic advice. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context,
Narang added.

CISA’s warning underscores the urgency for organizations to address these flaws. The agency’s directive to patch by September 22 aligns with Microsoft’s advisory, which stresses that if you can’t say when the update stack last ran, you can’t say whether it's patched.
The immediate focus is on meeting the September 22 deadline for critical patches. However, experts warn that the trend of increasing vulnerability disclosures—driven by AI tools and expanding software ecosystems—will likely continue. Narang noted that while the number of patched flaws is rising, the number of vulnerabilities that can and will affect most organizations remains quite low.
Microsoft’s update included 111 security bugs in Office 2016 for this month’s Patch Tuesday. Multiple security issues were also addressed in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9). The company set a previous record in July with fixes for more than 600 security vulnerabilities—which itself was triple the size of the previous record set the month before. The year’s total bugs disclosed now exceed 2,600, surpassing the 2020 record.
