← Back to Daily Briefing (#ZeroDay)

Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation

Published September 11, 2026

The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.

  • Vulnerability Volume and Severity Distribution

    • Unprecedented scale: 974 total CVEs identified within the September 2026 release cycle.
    • Criticality breakdown: 104–110 critical flaws and approximately 860 important-severity vulnerabilities.
    • Remediation mandate: 964 specific vulnerabilities require direct customer action to mitigate security risks.
  • Critical RCE and Wormable Threats

    • Windows DNS Server RCE (CVSS 9.8): High-risk vulnerability capable of wormable, automated exploitation across enterprise infrastructure.
    • SigRed Successor: Vulnerability researchers have identified this DNS flaw as a potential successor to the SigRed vulnerability due to its impact profile.
    • Remote Desktop Services (RDS): High-severity RCE targeting remote access protocols, posing significant risks to perimeter defense and entry vectors.
  • Active Zero-Day Exploitation Details

    • CVE-2026-81963: Windows Update Stack elevation-of-privilege (EoP) via improper link resolution (CVSS 7.8).
    • CVE-2026-85880: Windows ALPC heap-based buffer overflow facilitating sandbox escape and local privilege escalation (CVSS 7.8).
    • Threat Actor Activity: Confirmed active exploitation is being used by actors to facilitate post-exploitation persistence and lateral movement.
  • Attack Surface and Product Distribution

    • Windows Core: 723 vulnerabilities impacting operating system components, core services, and system architecture.
    • Enterprise Infrastructure: 111 vulnerabilities in Office/Office 2016 and 62 vulnerabilities in SQL Server.
    • Development Environments: 22 vulnerabilities affecting specialized developer-centric software and tools.
  • Defensive Strategy and Mitigation

    • Priority Patching: Prioritize Windows DNS Server updates to disrupt potential wormable, automated attack vectors.
    • Endpoint Hardening: Remediate zero-day EoP flaws immediately to prevent attackers from gaining elevated system persistence.
    • Perimeter Audit: Conduct comprehensive audits of Remote Desktop Services (RDS) and Exchange Server instances to mitigate high-severity RCE risks.

Related posts

  1. arcticwolf.com — Microsoft Patch Tuesday Security Recap: September 2026 Edition
  2. The Record by Recorded Future — Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
  3. thecyberexpress.com — Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited
  4. esecurityplanet.com — Microsoft’s September Patch Tuesday Fixes Nearly 1,000 Flaws, Including 2 Exploited Zero-Days
  5. techjacksolutions.com — SCC Executive Brief - 2026-09-09
  6. computerweekly.com — Patch Tuesday: Microsoft updates address almost 1,000 flaws
  7. cybersecurity.fullcoll.edu — Microsoft Plugs Nearly 1,000 Security Holes
  8. Malware News — Microsoft fixes record 964 flaws, including 2 exploited zero-days
  9. falconinternet.net — Record Patch Tuesday: 974 CVEs, Two Active Zero-Days, a Wormable DNS RCE
  10. it.slashdot.org — Microsoft Breaks Another Patch Tuesday Record
  11. socprime.com — CVE-2026-85880 and CVE-2026-81963: Microsoft Patches Two Actively Exploited Windows Zero-Days
  12. bleepingcomputer.com — Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
  13. cyberscoop.com — Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
  14. thehackernews.com — Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
  15. Securityaffairs
  16. Securitybrief
  17. Helpnetsecurity
  18. cybersecuritydive.com — New FBI cyber strategy promises increase in adversary disruptions
  19. Youtube
  20. Krebsonsecurity
  21. Petri
  22. Senserva
  23. Hackread
  24. Crowdstrike
  25. Windows
  26. Cybersecurity-insiders
  27. Markets
  28. Zvelo
  29. Mbtmag
  30. Thecipherbrief
  31. Techradar
  32. Redmondmag
  33. Malwarebytes
  34. Lifehacker
  35. Windowslatest
  36. Techpowerup
  37. Thezdi
  38. SecurityWeek — Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
  39. Dark Reading — Patch Tuesday Sets Another Record With 974 CVEs
  40. Dark Reading — Identity-Based AI Attack Threatens Security of Enterprise Data

LINK COPIED TO CLIPBOARD