Microsoft's Biggest Patch Tuesday on Record
Microsoft's September 2026 Patch Tuesday broke its own record, addressing 974 vulnerabilities across its product line — including two zero-days actively exploited in the wild. The release covers 723 flaws in Windows, 222 in the Office suite (111 of those in Office 2016), and dozens more spanning SQL Server and developer tools. More than 110 issues are rated critical, and 20 are considered wormable due to unauthenticated remote-code-execution potential.
The Two Exploited Zero-Days
CVE-2026-85880 — Windows ALPC Heap Buffer Overflow
A heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component allows a local attacker to elevate to SYSTEM privileges. Microsoft notes an attacker who can already execute code inside a low-privilege AppContainer could use this flaw to escape the sandbox with no additional user interaction. This is only the second ALPC zero-day patched since 2023's CVE-2023-21674, and the first since April 2023. Volexity and Proofpoint are credited with the discovery.
CVE-2026-81963 — Windows Update Stack Link-Following Flaw
An improper link resolution before file access ("link following") vulnerability in the Windows Update Stack also allows local privilege escalation to SYSTEM. It's the first Update Stack zero-day among the seven flaws resolved in that component over the past five years.
Both zero-days carry a CVSS score of 7.8. CISA has added both to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22, 2026 to apply the fixes.
Other Notable Fixes
- A remote-code-execution flaw in Exchange Server
- A privilege-escalation bug in Microsoft Authenticator
- An authorization issue in SharePoint
- High-severity defects in Remote Desktop Services, DNS, DHCP, Shell, and the NFS ONCRPC XDR driver
The Bigger Picture
This month's release pushes Microsoft's 2026 total past 2,600 vulnerabilities disclosed — more than double the previous full-year record set in 2020 — with three months still remaining in the year. Tenable's Satnam Narang cautions against reading the raw count as a proxy for risk: AI-assisted vulnerability discovery is creating larger haystacks, not necessarily more needles that actually affect most organizations. Action1's Jack Bicer echoes that the real challenge for IT and security teams at this scale isn't working through the patch list — it's triaging which fixes need immediate action versus which can follow a normal deployment cadence.
Recommendations
- Prioritize CVE-2026-85880 and CVE-2026-81963 given active exploitation and the September 22 federal KEV deadline
- Triage the 110+ critical-rated flaws and the 20 wormable RCE issues ahead of routine patching cycles
- Patch internet-facing Exchange and SharePoint systems on an accelerated schedule
- Don't let volume alone dictate priority — focus scarce patching cycles on exploited and wormable flaws first