Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2721+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
NEWS

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

September's Patch Tuesday breaks records with 974 CVEs fixed, including two actively exploited Windows zero-days now on CISA's KEV catalog.

Dylan H.

Security Engineer

September 9, 2026
3 min read

Microsoft's Biggest Patch Tuesday on Record

Microsoft's September 2026 Patch Tuesday broke its own record, addressing 974 vulnerabilities across its product line — including two zero-days actively exploited in the wild. The release covers 723 flaws in Windows, 222 in the Office suite (111 of those in Office 2016), and dozens more spanning SQL Server and developer tools. More than 110 issues are rated critical, and 20 are considered wormable due to unauthenticated remote-code-execution potential.


The Two Exploited Zero-Days

CVE-2026-85880 — Windows ALPC Heap Buffer Overflow

A heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component allows a local attacker to elevate to SYSTEM privileges. Microsoft notes an attacker who can already execute code inside a low-privilege AppContainer could use this flaw to escape the sandbox with no additional user interaction. This is only the second ALPC zero-day patched since 2023's CVE-2023-21674, and the first since April 2023. Volexity and Proofpoint are credited with the discovery.

CVE-2026-81963 — Windows Update Stack Link-Following Flaw

An improper link resolution before file access ("link following") vulnerability in the Windows Update Stack also allows local privilege escalation to SYSTEM. It's the first Update Stack zero-day among the seven flaws resolved in that component over the past five years.

Both zero-days carry a CVSS score of 7.8. CISA has added both to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22, 2026 to apply the fixes.

Other Notable Fixes

  • A remote-code-execution flaw in Exchange Server
  • A privilege-escalation bug in Microsoft Authenticator
  • An authorization issue in SharePoint
  • High-severity defects in Remote Desktop Services, DNS, DHCP, Shell, and the NFS ONCRPC XDR driver

The Bigger Picture

This month's release pushes Microsoft's 2026 total past 2,600 vulnerabilities disclosed — more than double the previous full-year record set in 2020 — with three months still remaining in the year. Tenable's Satnam Narang cautions against reading the raw count as a proxy for risk: AI-assisted vulnerability discovery is creating larger haystacks, not necessarily more needles that actually affect most organizations. Action1's Jack Bicer echoes that the real challenge for IT and security teams at this scale isn't working through the patch list — it's triaging which fixes need immediate action versus which can follow a normal deployment cadence.

Recommendations

  • Prioritize CVE-2026-85880 and CVE-2026-81963 given active exploitation and the September 22 federal KEV deadline
  • Triage the 110+ critical-rated flaws and the 20 wormable RCE issues ahead of routine patching cycles
  • Patch internet-facing Exchange and SharePoint systems on an accelerated schedule
  • Don't let volume alone dictate priority — focus scarce patching cycles on exploited and wormable flaws first

Sources

  • The Hacker News — Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
  • SecurityWeek — Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
  • CyberScoop — Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
#Microsoft#Patch Tuesday#Zero-Day#Windows#CISA KEV

Related Articles

Microsoft January 2026 Patch Tuesday: 114 Flaws Fixed, One

Microsoft's first security update of 2026 addresses 114 vulnerabilities including three zero-days. One flaw is actively exploited in the wild with CISA...

3 min read

Microsoft Patch Tuesday February 2026: 6 Actively Exploited

Microsoft's February 2026 Patch Tuesday addresses 60 vulnerabilities including 6 actively exploited zero-days and 3 publicly disclosed issues, with...

8 min read

Microsoft Warns of New Defender Zero-Days Exploited in Attacks

Microsoft has issued emergency patches for two Windows Defender vulnerabilities that were actively exploited as zero-days before fixes were available....

5 min read
Back to all News