The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.
-
Vulnerability Volume and Severity Distribution
- Unprecedented scale: 974 total CVEs identified within the September 2026 release cycle.
- Criticality breakdown: 104–110 critical flaws and approximately 860 important-severity vulnerabilities.
- Remediation mandate: 964 specific vulnerabilities require direct customer action to mitigate security risks.
-
Critical RCE and Wormable Threats
- Windows DNS Server RCE (CVSS 9.8): High-risk vulnerability capable of wormable, automated exploitation across enterprise infrastructure.
- SigRed Successor: Vulnerability researchers have identified this DNS flaw as a potential successor to the SigRed vulnerability due to its impact profile.
- Remote Desktop Services (RDS): High-severity RCE targeting remote access protocols, posing significant risks to perimeter defense and entry vectors.
-
Active Zero-Day Exploitation Details
- CVE-2026-81963: Windows Update Stack elevation-of-privilege (EoP) via improper link resolution (CVSS 7.8).
- CVE-2026-85880: Windows ALPC heap-based buffer overflow facilitating sandbox escape and local privilege escalation (CVSS 7.8).
- Threat Actor Activity: Confirmed active exploitation is being used by actors to facilitate post-exploitation persistence and lateral movement.
-
Attack Surface and Product Distribution
- Windows Core: 723 vulnerabilities impacting operating system components, core services, and system architecture.
- Enterprise Infrastructure: 111 vulnerabilities in Office/Office 2016 and 62 vulnerabilities in SQL Server.
- Development Environments: 22 vulnerabilities affecting specialized developer-centric software and tools.
-
Defensive Strategy and Mitigation
- Priority Patching: Prioritize Windows DNS Server updates to disrupt potential wormable, automated attack vectors.
- Endpoint Hardening: Remediate zero-day EoP flaws immediately to prevent attackers from gaining elevated system persistence.
- Perimeter Audit: Conduct comprehensive audits of Remote Desktop Services (RDS) and Exchange Server instances to mitigate high-severity RCE risks.
Related posts
- The Record by Recorded Future — Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
- computerweekly.com — Patch Tuesday: Microsoft updates address almost 1,000 flaws
- cybersecurity.fullcoll.edu — Microsoft Plugs Nearly 1,000 Security Holes
- Malware News — Microsoft fixes record 964 flaws, including 2 exploited zero-days
- falconinternet.net — Record Patch Tuesday: 974 CVEs, Two Active Zero-Days, a Wormable DNS RCE
- bleepingcomputer.com — Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
- thehackernews.com — Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
- Youtube
- Krebsonsecurity
- Petri
- Senserva
- Hackread
- Crowdstrike
- Windows
- SecurityWeek — Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
- Dark Reading — Patch Tuesday Sets Another Record With 974 CVEs