Microsoft fixes 974 flaws, including two zero-days
Microsoft’s September 2026 Patch Tuesday fixed 974 vulnerabilities, including two actively exploited Windows zero-days.
Microsoft released its September 2026 Patch Tuesday with 974 vulnerabilities fixed, according to counts cited by several firms. Among them are two actively exploited zero-days, CVE-2026-81963 and CVE-2026-85880, both tied to privilege escalation in Windows and already in CISA’s KEV catalog.
Microsoft rolled out its September 2026 Patch Tuesday with 974 vulnerabilities fixed, according to Microsoft’s count cited by SecurityWeek, The Record, CyberScoop and other cycle analyses. Among the flaws are two actively exploited Windows zero-days, tracked as CVE-2026-81963 and CVE-2026-85880, which CISA has already added to its Known Exploited Vulnerabilities catalog.
What did Microsoft fix in this cycle?
Microsoft closed an unusually large batch of flaws that different vendors place between 964 and 974 CVEs, depending on the methodology used by each one. Tenable counted 964 vulnerabilities, including 104 critical and 860 important issues, while Qualys and tbreak.com reported 974. Other outlets, including Cybersecurity News, The Record and SecurityWeek, cited 973 or 974 based on Microsoft release notes and official guidance.
KrebsOnSecurity described the package as Microsoft’s largest patch set to date. Windows Latest said that for Windows 11, the rollout arrived as cumulative update KB5124008, with builds 26200.9445 and 26100.9445, and called it the biggest update of the year by volume of changes and fixes.
Which are the two most sensitive vulnerabilities?
The two most closely watched flaws are CVE-2026-81963 and CVE-2026-85880, both confirmed as actively exploited by Microsoft and CISA. According to SecurityWeek, The Record, The Hacker News, CrowdStrike, WindowsForum and other analyses, they allow local privilege escalation to SYSTEM in Windows Update Stack and Windows ALPC, respectively.
In the case of CVE-2026-81963, NIST’s NVD describes it as an improper link resolution before file access issue in Windows Update Stack that lets an authorized attacker raise privileges locally. NIST says it affects Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025, including Server Core installations. Cisco Talos said the flaw combines incorrect link resolution before file access with weak access controls, allowing update-process writes to be redirected to attacker-controlled paths.
AZ Pentest, Lansweeper and Windows Latest agree that Microsoft confirmed active exploitation and that the redirection can end in SYSTEM privileges. The Hacker News also reported a CVSS score of 7.8 for this CVE, and Zero Day Initiative classified it as Important in its internal technical table.
What is known about CVE-2026-85880?
CVE-2026-85880 appears in NVD as a Microsoft Windows Heap-Based Buffer Overflow Vulnerability and, according to ThreatClaw.ai, Feedly CVE Tracker, Cisco Talos, CrowdStrike and The Hacker News, affects the Windows ALPC messaging layer. The official source described by The Hacker News says that an attacker running code inside a low-privilege AppContainer can use it to escape the sandbox and elevate privileges on the affected system.
CrowdStrike added that the heap overflow in ALPC can lead to code execution with elevated privileges, while Cisco Talos linked it to use of uninitialized resources. Feedly CVE Tracker noted that no functional public exploits were found among the analyzed URLs, but exploitation in the wild was confirmed by official sources, which raises its operational risk.
What did CISA and response teams say?
CISA added CVE-2026-81963 and CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog and set Sept. 22, 2026, as the deadline for U.S. federal agencies to apply patches, according to Qualys and The Record. WindowsForum added that the warning was also picked up by the Canadian Centre for Cyber Security, aligning its stance with CISA’s.
Splashtop warned that, although both CVEs are listed as Important rather than Critical, real-world exploitation makes them a high patching priority compared with other flaws that may have a higher nominal severity but no known exploitation. S-EDV, for its part, said both issues carry a CVSS score of 7.8 and are the most relevant vulnerabilities in September 2026 Patch Tuesday for Windows administrators.
Sources
- September 2026 Microsoft Patch Tuesday | Tenable®tenable.com· Tenable
- NVD - CVE-2026-81963nvd.nist.gov· NIST NVD
- Microsoft discloses two actively exploited zero-days among 974 vulnerabilitiescyberscoop.com· CyberScoop
- September 2026 Patch Tuesday: Two Exploited Windows Flawswindowsforum.com· WindowsForum
- Microsoft's September 2026 Patch Tuesday: 974 ...ap7i.com· ap7i.com
- NVD - CVE-2026-85880nvd.nist.gov· NIST NVD
- I tested Windows 11 September 2026 update, here's everything new, improved and fixedwindowslatest.com· Windows Latest
- September 2026 Patch Tuesday: Updates and Analysiscrowdstrike.com· CrowdStrike
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewblog.qualys.com· Qualys
- CVE-2026-85880 — HIGH Vulnerability | CISA KEV | CVSS 7.8 ...threatclaw.ai· ThreatClaw.ai
- September 2026 Patch Tuesday fixes 974 Microsoft CVEstbreak.com· tbreak.com
- Microsoft warns: Don’t delay Windows 11’s update released today, confirms record security fixes as AI becomes a threatwindowslatest.com· Windows Latest
- Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Dayscybersecuritynews.com· Cybersecurity News
- CVE-2026-85880 - Exploits & Severityfeedly.com· Feedly CVE Tracker
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Dayssecurityweek.com· SecurityWeek
- September 2026 Patch Tuesday sets a new CVE recordsplashtop.com· Splashtop
- Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedtherecord.media· The Record
- Windows Zero-Day CVE-2026-81963: What to Do Nowazpentest.com· AZ Pentest
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesblog.talosintelligence.com· Cisco Talos Intelligence
- The September 2026 Security Update Reviewzerodayinitiative.com· Zero Day Initiative
- Microsoft Plugs Nearly 1,000 Security Holeskrebsonsecurity.com· KrebsOnSecurity
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Daysthehackernews.com· The Hacker News
- Microsoft Patch Tuesday – September 2026lansweeper.com· Lansweeper
- Microsoft Patchday September 2026: Zero-Days und RCE-Lückens-edv.com· S-EDV



