Microsoft Patches 966 Vulnerabilities in Record-Breaking Security Update
September 2026 Patch Tuesday addresses 966 security vulnerabilities across its product lineup, including two zero-day flaws already being exploited in attacks. The update surpasses previous records, including the 570 vul…

September 2026 Patch Tuesday addresses 966 security vulnerabilities across its product lineup, including two zero-day flaws already being exploited in attacks. The update surpasses previous records, including the 570 vulnerabilities fixed in July and 400 patched in August. The company has attributed the surge in identified flaws to its deployment of an AI-powered vulnerability discovery system. Among the vulnerabilities addressed, 105 carry Critical severity ratings, with 81 of those enabling remote code execution. Elevation of privilege flaws account for the largest portion of this month’s security holes at 438. Remote code execution vulnerabilities total 258, while information disclosure issues number 173. The remaining vulnerabilities span denial of service (56), spoofing (16), and security feature bypass (19). Microsoft’s count does not include 204 additional flaws patched earlier this month in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge Chromium-based, Microsoft Fabric, and Power Automate.
Zero-Day Vulnerabilities Under Active Exploitation
Two zero-day vulnerabilities require immediate attention. CVE-2026-81963 exists in the Windows Update Stack, where improper link resolution allows an authorized attacker to gain SYSTEM-level access locally. Romain Deperne and Microsoft’s Threat Intelligence Centre discovered this flaw. The second zero-day, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that enables privilege escalation to SYSTEM level. Volexity and Proofpoint researchers Mark Kelly, David Galazin, and Jeremy Hedges reported this vulnerability. Microsoft has not disclosed how either vulnerability was used in attacks.
Other Vendor Security Patches
Beyond Microsoft’s updates, other vendors released security patches during this period. Adobe addressed a max-severity zero-day called StyleSmuggler affecting Adobe Commerce that was used to backdoor websites. Google patched a high-severity V8 zero-day in Chrome along with 11 other vulnerabilities. CrowdStrike advised customers to disable a Windows policy setting after a researcher published a zero-day exploit. HP patched a critical remote code execution flaw in ArubaOS-CX, while Cisco addressed vulnerabilities in IOS XR, Nexus 9000 Series Switches, and Cisco Phones. SonicWall issued fixes for two SMA1000 zero-days being chained together in remote code execution attacks.


