Skip to main content
CybersecurityVulnerability Management

Microsoft Patches 974 Flaws, Including Two Actively Exploited Windows Zero-Days

Rows of computer workstations in a brightly-lit software development room with personnel working and large windows in the…

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.

Scope of the September release: numbers and types

The company fixed 974 Microsoft-specific flaws across products this month: 723 in Windows, 111 in Office and Office 2016, 62 in SQL Server, and 22 in Developer Tools. Over 110 of the shortcomings received a critical severity rating, and three vulnerability types — privilege escalation, remote code execution, and information disclosure — account for nearly 90% of the fixes. Including Microsoft's updates for 25 non‑Microsoft CVEs, the update brings the total number of vulnerabilities resolved in this release to 999.

The torrent of patches follows a steady increase through 2026: 457 vulnerabilities were patched in August, 663 in July, 220 in June, and 161 in May. TrendAI's Zero Day Initiative (ZDI) reported that Microsoft has patched a total of 2,760 security flaws this year.

Two actively exploited Windows zero-days

Microsoft identified two Windows vulnerabilities as being actively exploited and assigned both CVSS scores of 7.8.

  • CVE-2026-85880 — A heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges. Microsoft warned: "An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required." Volexity and Proofpoint were acknowledged for reporting this issue.
  • CVE-2026-81963 — An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges. Adam Barnett of Rapid7 noted that patches for "all supported versions of Windows" appear to "presumably tighten up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter." Romain Deperne of Airbus Helicopters and the Microsoft Threat Intelligence Center were credited with reporting this bug.

Microsoft said it has detected zero-day exploitation efforts targeting the two flaws but did not disclose who is behind them, the scale of those efforts, or whether any attacks have successfully breached victims.

CISA response and compliance deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both CVE-2026-85880 and CVE-2026-81963 to its Known Exploited Vulnerabilities (KEV) catalog, creating a binding timeline for Federal Civilian Executive Branch (FCEB) agencies. The KEV listing requires FCEB agencies to apply the fixes by September 22, 2026.

Notable high-severity flaws addressed

Beyond the two zero-days, Microsoft patched numerous high-severity, network-reachable issues that could lead to remote code execution or privilege elevation. Selected entries reported in the release include:

  • CVE-2026-55007 (CVSS 8.1) — a double free in Microsoft Exchange Server allowing an unauthorized attacker to execute code over a network.
  • CVE-2026-80097 (CVSS 8.6) — an improper authentication issue in Microsoft Authenticator permitting local privilege elevation by an unauthorized attacker.
  • CVE-2026-69465 (CVSS 8.8) — a missing authorization flaw in Microsoft Office SharePoint enabling an authorized attacker to execute code over a network.
  • CVE-2026-65669 (CVSS 9.6) — an injection vulnerability in SQL Server that allows an unauthorized attacker to elevate privileges over a network.
  • Multiple Windows use-after-free and buffer-overflow bugs with CVSS scores of 9.8 impacting Remote Desktop Services, NFS ONCRPC XDR Driver, DNS server, Shell, and DHCP Server (CVE-2026-69525, CVE-2026-69595, CVE-2026-69730, CVE-2026-69829, CVE-2026-72979).

Patch volume in context: expert voices

Experts emphasized triage and prioritization. Jack Bicer, director of vulnerability research at Action1, said: "At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first." Satnam Narang of Tenable placed the release in historical context, saying: "September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026," and noting the month's release is "nearly a 70% increase over the previous record (569) in July" and pushes the year's total to over 2,600.

Tyler Reguly of Fortra observed a different perspective: "I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning." Others urged focus on which vulnerabilities actually apply to a given environment and which are reachable and exploitable over the internet.

What this means for IT teams, FCEB agencies, and end users

  • IT and security teams — face a high-volume triage problem: prioritize fixes that are internet-reachable, rated critical, or listed on CISA's KEV and apply mitigations accordingly, per expert guidance in the reporting.
  • FCEB agencies — must meet the CISA deadline to remediate CVE-2026-85880 and CVE-2026-81963 by September 22, 2026, as required by the KEV listing.
  • End users — should be aware that Microsoft has detected active exploitation of two Windows flaws but did not disclose details about affected victims or threat actors; patch deployment by organizations will be the primary defense identified in the advisory.

Microsoft's largest-ever Patch Tuesday raises as many operational questions as it resolves technical ones: with nearly a thousand fixes, agencies and enterprises are now racing to parse what actually matters to their networks before CISA's remediation deadline arrives. Microsoft confirmed zero-day exploitation but left the scale and attribution unspecified — a gap that will determine how urgently some of these fixes are prioritized.

Original story at The Hacker News