Microsoft September 2026 Patch Tuesday Addresses Nearly 1,000 Flaws Including Two Exploited Zero‑Days
In September 2026 Microsoft released a Patch Tuesday update addressing 964 distinct vulnerabilities across Windows client/server OS, Office suites, Azure services, Exchange Server, and .NET Framework. Two of the flaws were zero‑day vulnerabilities already observed in active exploitation: CVE‑2026‑XXXXX (Print Spooler elevation‑of‑privilege) and CVE‑2026‑YYYYY (Office VBA remote code execution). The remaining vulnerabilities spanned critical to low severity, with 112 rated Critical. Immediate deployment is required to mitigate ongoing attacks targeting government, finance, and healthcare sectors.
Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation
The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.