Microsoft September Patch Tuesday Fixes 973 Vulnerabilities, Including Two Actively Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities, with a focus on two zero-days in Windows that are already being exploited in the wild.

Microsoft has released its September 2026 Patch Tuesday security updates, tackling a significant total of 973 vulnerabilities across its product ecosystem. This month's release is particularly noteworthy for including two zero-day vulnerabilities in Windows that have already been observed being exploited by attackers.
The two zero-days, identified as CVE-2026-85880 and CVE-2026-81963, are both classified as elevation-of-privilege flaws. CVE-2026-85880 affects the Windows Advanced Local Procedure Call (ALPC) interface, while CVE-2026-81963 targets the Windows Update Stack. Although rated as 'Important' by Microsoft, the fact that these vulnerabilities are being actively exploited in the wild makes them a critical priority for patching. This underscores the importance of not solely focusing on 'Critical' severity flaws during patch management cycles.
Beyond the zero-days, the update addresses a broad spectrum of vulnerabilities, with Windows bearing the brunt of the fixes, accounting for 723 vulnerabilities. Other affected products include Microsoft Office (111 vulnerabilities), SQL Server (62), developer tools (22), SharePoint Server (16), and Exchange Server (9). The sheer volume and diversity of these fixes necessitate a coordinated and comprehensive patching strategy for organizations.
Several other critical vulnerabilities demand immediate attention. These include elevation-of-privilege flaws in Windows Secure Kernel Mode (CVE-2026-83939) and Virtualization-Based Security (VBS) Enclave privileges (CVE-2026-83498), as well as an information disclosure vulnerability related to VBS (CVE-2026-83501). Microsoft Office also receives critical remote-code-execution fixes for Excel (CVE-2026-81959, CVE-2026-81953) and Word (CVE-2026-81952).
Additional notable vulnerabilities include remote-code-execution flaws in the Windows Print Spooler (CVE-2026-85877), Windows Message Queuing (CVE-2026-83997), and the Remote Desktop Client (CVE-2026-83998), all rated 'Important'. The update also addresses denial-of-service vulnerabilities in the Windows Key Distribution Center (CVE-2026-84001) and Services for NFS ONCRPC XDR driver (CVE-2026-83989), along with a tampering vulnerability in the Windows Cloud Files Mini Filter Driver (CVE-2026-83991).
Microsoft's release guidance emphasizes that Windows 10 and Windows 11 security updates are cumulative and directs administrators to the Microsoft Update Catalog for deployment. It also highlights the importance of installing the latest servicing stack update and reviewing known issues before implementing changes in production environments. Organizations are advised to use representative test groups for staged rollouts and monitor application health closely.
The breadth of vulnerabilities patched this month, from kernel-level issues to application-specific flaws and developer tools, reinforces the ongoing challenge of maintaining a secure posture in complex IT environments. The active exploitation of zero-days serves as a stark reminder that timely patching remains a cornerstone of cybersecurity defense.
This new report from Tenable details Microsoft's September 2026 Patch Tuesday, which addresses a record-breaking 964 Common Vulnerabilities and Exposures (CVEs). While the previous report noted 973 CVEs, this update provides a more granular breakdown, highlighting 104 critical and 860 important vulnerabilities across a vast array of Microsoft products and services, including .NET, Azure, and Office applications. Notably, it confirms patches for two zero-day vulnerabilities that were actively exploited in the wild, underscoring the ongoing threat landscape.
This month's Patch Tuesday from Microsoft is exceptionally large, addressing a record 973 vulnerabilities, significantly surpassing previous totals. Notably, two vulnerabilities are confirmed to be exploited in the wild: CVE-2026-81963, an elevation of privilege in the Windows Update Stack, and CVE-2026-85880, an ALPC elevation of privilege flaw. Critical remote code execution vulnerabilities in Skype for Business (CVE-2026-66302) and Windows Message Queuing (CVE-2026-69579) are also among the critical fixes.
This new report from SecurityWeek clarifies that Microsoft's September Patch Tuesday addressed a record 974 vulnerabilities, a slight increase from the 973 previously reported. The update specifically includes fixes for two actively exploited zero-day vulnerabilities: CVE-2026-85880, a heap buffer overflow in Windows ALPC allowing privilege escalation, and CVE-2026-81963, a link following defect in the Windows Update Stack also leading to privilege escalation. Additionally, the article highlights that 20 of the resolved flaws are potentially wormable, requiring no authentication or user interaction for exploitation.