Skip to main content
CybersecurityVulnerability Management

Microsoft Unveils Record 974 CVE Fixes in September Patch Tuesday Release

A cluttered tech workspace with a central computer, papers, and security tools.

“At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first,” Jack Bicer wrote. “With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”

Microsoft’s September 2026 Patch Tuesday: a record 974 CVEs

On September 8, Microsoft released fixes for 974 Common Vulnerabilities and Exposures (CVEs), the largest single Patch Tuesday roll‑out in the company’s history. The September total more than doubles the previous record of 570 CVEs published in July 2026 and continues a marked upward trend over recent months: 164 CVEs in April, 120 in May, 200 in June, 570 in July and 400 in August, followed by this month’s 974.

Microsoft had warned customers in July to expect a surge in updates as a consequence of its use of agentic AI tools to discover zero‑day vulnerabilities; the September total is the clearest manifestation of that forecast so far.

Windows, Office, and product breakdown

The fixes span Microsoft’s product portfolio, with Windows affected most heavily: 723 of the September CVEs are tied to Windows products. Office accounted for 111 CVEs. Across the release, Microsoft identified 119 critical vulnerabilities.

The sheer scale of the list stretches patch and change windows for enterprises that manage large installed bases of Windows and Office, and it concentrates risk-management decisions into a very short operational timeframe.

Two actively exploited zero‑days highlighted by Microsoft

Microsoft called out two zero‑day flaws in the September update that were being actively exploited by threat actors.

  • CVE-2026-85880 — assigned a high severity rating of 7.8. Microsoft described this as a heap‑based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that can enable an attacker who can execute code in a low‑privilege AppContainer to elevate privileges locally.
  • CVE-2026-81963 — described as an improper link resolution before file access in Windows Update Stack, which allows an authorized attacker to elevate privileges locally.

Both were elevated by Microsoft in the September advisory as active threats that merit immediate attention during patch planning.

Action1’s prioritized list and guidance from Jack Bicer

Jack Bicer, director of vulnerability research at Action1, both warned of the triage challenge and published a short prioritized list of flaws he recommended security teams address first. His list includes four high‑impact remote code execution vulnerabilities in Windows server components, two rated critical at 9.8 and two rated high or critical in the 8.1–8.8 range:

  • CVE-2026-62878 — remote code execution in Windows DNS Server caused by a stack‑based buffer overflow; critical rating 9.8.
  • CVE-2026-62823 — remote code execution in Windows DHCP Server caused by a heap‑based buffer overflow; high severity 8.8.
  • CVE-2026-62893 — remote code execution in Windows Deployment Services caused by a use‑after‑free condition; critical rating 9.8.
  • CVE-2026-65789 — remote code execution in Windows DNS caused by a use‑after‑free condition; high severity 8.1.
  • CVE-2026-58231 — listed as three critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform.

Bicer’s central point: with hundreds of updates arriving simultaneously, vulnerability managers must first separate truly urgent flaws from those that can proceed through normal deployment cycles.

What this means for security teams, procurement leaders, and end users

Security teams and technologists: The record volume makes a risk‑based approach essential. Microsoft’s identification of two actively exploited zero‑days and the presence of 119 critical CVEs mean teams must triage by exploitability and business impact rather than simply applying every patch immediately.

Enterprises and procurement leaders: The spike in updates — tied by Microsoft to its use of agentic AI to find vulnerabilities — will affect budgetary planning, patch management windows and vendor support conversations, particularly for organizations that run large Windows estates and multiple Office deployments.

End users and administrators: Two zero‑days that allow local privilege elevation and multiple critical remote code execution bugs in Windows server components increase the urgency for administrators to test and deploy remedial updates for exposed systems promptly.

For organizations that already operate tight change-control processes, the September surge presents a difficult balancing act: failing to patch quickly risks exploitation, while wholesale, rapid deployment risks operational disruption. Microsoft’s July warning that its agentic AI tools would surface more zero‑days has moved from forecast to operating reality; the practical question now is whether teams and tooling can keep pace.

https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/