Microsoft Patches Record 974 CVEs, Two Zero-Days Exploited

Microsoft's historic Patch Tuesday fixes 974 vulnerabilities, including two zero-days exploited in the wild, urging immediate patching.

By Central
Highlights
  • CVE-2026-85880 is an ALPC heap buffer overflow zero-day that allows sandbox escape to System privileges.
  • CVE-2026-81963 is a link following flaw in the Windows Update Stack exploited before a patch existed.
  • AI-assisted vulnerability research is driving a record number of CVEs, demanding continuous patching strategies.

Microsoft made history on Tuesday with its largest-ever Patch Tuesday release, issuing fixes for 974 Common Vulnerabilities and Exposures (CVEs) across its product ecosystem, including two zero-day vulnerabilities that attackers have already exploited in the wild. This record-breaking security update, part of the September 2026 Patch Tuesday cycle, underscores the escalating volume of software flaws discovered and addressed in an era increasingly shaped by AI-assisted vulnerability research. Among the most pressing issues are a privilege escalation flaw in the Windows Advanced Local Procedure Call (ALPC) component and a similar elevation-of-privilege defect in the Windows Update Stack, both of which have been used by attackers before any official patch existed.

CVE-2026-85880: The ALPC Zero-Day That Escalates Privileges

The first exploited zero-day, designated CVE-2026-85880, is a heap buffer overflow vulnerability residing in the Windows Advanced Local Procedure Call (ALPC) component. ALPC is a core mechanism within Windows that facilitates high-performance inter-process communication, making it a critical and sensitive part of the operating system. The flaw allows a local attacker who can execute code within a low-privilege AppContainer environment to escape the sandbox and elevate privileges to the System level. Microsoft’s advisory explicitly states that no additional user interaction is required for exploitation, meaning the attack can unfold silently once a threat actor gains limited access to a system.

This vulnerability represents a significant escalation risk, as it can turn a compromised low-privilege process into a full system takeover. Notably, Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is only the second zero-day in this component to be resolved in nearly four years. The previous instance, CVE-2023-21674, was patched in January 2023 and carried a similar exploitation profile. The reappearance of a zero-day in ALPC after such a gap signals that this attack surface remains a high-value target for threat actors.

The practical implication of CVE-2026-85880 is that it functions as a sandbox escape mechanism. Attackers who have already breached an application or service running in a restricted environment—such as a web browser or a virtualized application—can use this flaw to break free and gain unrestricted access to the underlying operating system. Once elevated to System privileges, an attacker can install programs, modify data, create new accounts, and take full control of the affected machine. Organizations using Windows environments should prioritize testing and deploying this patch immediately, particularly for systems exposed to untrusted code or third-party applications.

CVE-2026-81963: The Windows Update Stack Zero-Day

The second exploited zero-day, CVE-2026-81963, is an improper link resolution before file access vulnerability—commonly referred to as a “link following” flaw—in the Windows Update Stack. The Windows Update Stack is the collection of components responsible for downloading and installing Windows updates, making it a foundational part of system maintenance. This defect allows a local attacker to elevate privileges to System level by tricking the Update Stack into following a symbolic link to a file or directory at a higher privilege level.

This is the first time a security weakness in the Windows Update Stack has been flagged as a zero-day. Microsoft has resolved only seven flaws in this component over the past five years, and none previously carried the distinction of being actively exploited before a patch was available. The relative rarity of vulnerabilities in the Update Stack makes this one particularly notable. Because the Update Stack operates at a high privilege level and is trusted by the operating system, any flaw that grants a local attacker System access through this vector is especially dangerous.

Organizations should be aware that this vulnerability does not require user interaction and can be exploited by an attacker who already has local access to a machine. In practice, this could be combined with a remote code execution vulnerability—such as one delivered through a phishing email or a malicious website—to achieve a full compromise. Security teams should treat this patch as critical and ensure it is applied to all Windows devices in their environment.

What Is the Scope of Microsoft’s September 2026 Patch Tuesday?

Beyond the two zero-days, the sheer volume of patches in September 2026 is unprecedented. Microsoft fixed 723 flaws in Windows alone, covering everything from kernel vulnerabilities to networking stack issues. The Office suite received 222 security fixes, with 111 of those addressing bugs in Office 2016, an application still widely used in enterprise and small business environments. These figures represent a dramatic increase over typical monthly releases, which have averaged around 100 to 150 CVEs in recent years.

The breakdown of other affected products reveals the breadth of Microsoft’s ecosystem:

  • SQL Server: 62 vulnerabilities resolved
  • Developer Tools: 22 security issues addressed
  • SharePoint Server: 16 patches released
  • Azure: 12 flaws fixed
  • Skype for Business: 10 vulnerabilities patched
  • Exchange Server: 9 security updates applied

Microsoft also released new Servicing Stack Updates (SSUs) classified as critical. These apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607 along with its corresponding Server 2016 edition. Servicing Stack Updates are fundamental because they ensure the update mechanism itself is reliable and secure, making them a prerequisite for future patch installations.

Which Vulnerabilities Demand Immediate Attention?

While every patch in a record-breaking release warrants attention, several vulnerabilities stand out due to their severity, attack vector, or the value of the affected component. Security researchers from Trend Micro’s Zero Day Initiative (ZDI) have highlighted five CVEs that deserve special priority:

  • CVE-2026-55007: A remote code execution (RCE) vulnerability in Exchange Server. This is especially concerning because Exchange Server has been a prime target for ransomware groups and nation-state actors in recent years. An RCE in this product can allow an attacker to take full control of email infrastructure without authentication in some cases.
  • CVE-2026-80097: An elevation of privilege (EoP) vulnerability in Microsoft Authenticator. Given that Authenticator is used for two-factor authentication across enterprise environments, a flaw that allows privilege escalation could undermine multi-factor authentication effectiveness and enable account takeover.
  • CVE-2026-69465: A remote code execution flaw in SharePoint Server. SharePoint is deeply integrated into many organizations’ document management and collaboration workflows, making an RCE particularly damaging for data integrity and internal communications.
  • CVE-2026-65669: An elevation of privilege vulnerability in SQL Server. This could allow an attacker with database access to escalate their permissions within the SQL Server instance, potentially gaining control over all stored data and associated applications.
  • CVE-2026-69525: A remote code execution vulnerability in Remote Desktop Services. This is a classic attack vector that, when wormable—meaning no authentication or user interaction required—can spread rapidly across networks, as seen with the BlueKeep vulnerability in years past.

According to analysis from ZDI, 20 of the vulnerabilities patched this month are considered wormable, meaning they enable remote code execution without any authentication or user interaction. In practical terms, a wormable vulnerability can spread from computer to computer automatically, making it a prime candidate for large-scale attacks like ransomware outbreaks. Organizations should identify which of these 20 wormable flaws apply to their specific environment and prioritize those patches above all else.

The Growing Haystack: AI-Assisted Vulnerability Discovery

The record number of patches in September 2026 raises an important question: why are we seeing so many vulnerabilities being fixed now? The answer lies partly in the increasing use of artificial intelligence to assist in vulnerability discovery. AI tools can analyze source code, fuzz test binaries, and identify potential weaknesses at a scale and speed far exceeding human researchers. Microsoft, along with many vendors, has invested heavily in AI-driven security research, and this month’s patch count is a direct reflection of those efforts.

However, size does not always correlate with practical risk. Observers of the security landscape have noted that while the total number of CVEs is rising dramatically, the number of vulnerabilities that actually affect most organizations in a meaningful way remains relatively low. This creates a new challenge for security teams: filtering the signal from the noise. With hundreds of patches to evaluate each month, organizations cannot simply apply every update blindly. They must assess which vulnerabilities are actually present in their environment, whether those vulnerabilities are reachable by an attacker, and whether exploitation is feasible given their network architecture and defenses.

The concept of “risk context” has never been more critical. A vulnerability in a component that an organization does not use poses no threat. A flaw in a service that is isolated behind multiple firewalls and not accessible from the internet is far less urgent than one in an internet-facing application. Security teams need accurate asset inventory, vulnerability scanning, and threat intelligence to prioritize remediation effectively. Simply counting CVEs is no longer a useful metric for organizational security posture.

Industry commentary suggests that this trend is not unique to Microsoft. Proactive vendors across the software industry are investing in more aggressive vulnerability discovery and remediation programs. The result is a temporary spike in patching volume as long-standing, hard-to-find vulnerabilities are finally uncovered and fixed. Over time, as the backlog of undiscovered flaws diminishes, Patch Tuesday releases may return to a more typical cadence. Until that normalization occurs, prioritization remains the primary survival skill for IT and security administrators.

Practical Guidance for Security Teams

With such a massive update cycle, practical steps become essential. Security teams should adopt a risk-based approach to patch prioritization:

  • Identify the two zero-days first: CVE-2026-85880 and CVE-2026-81963 are actively exploited. Confirm whether your systems are affected and deploy these patches immediately, especially on internet-facing servers and endpoints with high-value data.
  • Scan for wormable vulnerabilities: The 20 wormable flaws identified by ZDI should be treated as emergency patches. Any system that can be reached over the network without authentication is at risk. Segmenting networks and disabling unnecessary services can provide immediate mitigation while patches are tested.
  • Inventory your software: Many of the vulnerabilities affect specific products like Exchange Server, SharePoint, SQL Server, or certain versions of Office. If you do not use a particular product, you can deprioritize related patches. Conversely, if you rely heavily on these products, they become critical.
  • Test before deploying: While speed is important, stability remains vital. Deploy patches to a test environment first to ensure no compatibility issues exist with your line-of-business applications. Pay special attention to the Servicing Stack Updates, which can affect the update process itself.
  • Update your asset management data: The scale of this release underscores how quickly the threat landscape changes. Ensure your asset inventory is accurate and up to date so you can quickly determine which machines and applications are affected by which vulnerabilities.

As the volume of patches continues to grow, the human element of security administration becomes more strained. One pragmatic suggestion gaining traction in the industry is to acknowledge the increased workload on IT administrators. Providing additional resources, temporary staffing, or even modest incentives for the teams handling these updates can be a meaningful investment in the organization’s security resilience. The administrative burden of managing patch cycles of this magnitude should not be underestimated.

The Strategic Significance of the September 2026 Update

This month’s Patch Tuesday marks a turning point in how the industry perceives vulnerability management. The integration of AI into vulnerability discovery is changing the cadence and volume of security updates, and organizations must adapt their processes accordingly. Static patching schedules and manual prioritization are no longer adequate. Automated vulnerability assessment tools, continuous monitoring, and dynamic risk scoring are becoming necessities rather than luxuries.

For Microsoft, the record number of patches also represents a strategic bet on transparency and proactive security. By aggressively identifying and fixing vulnerabilities—even those that are not yet exploited—Microsoft aims to reduce the overall attack surface of its products. This approach has trade-offs, including increased operational overhead for customers, but it aligns with broader industry shifts toward security-by-design and vulnerability disclosure as a competitive differentiator.

The two zero-days exploited before patches were available serve as a reminder that no amount of proactive patching can eliminate all risk. Attackers continue to discover and weaponize vulnerabilities faster than vendors can respond, and the gap between public disclosure and exploitation remains narrow. Organizations that treat patching as a periodic task rather than a continuous process will find themselves increasingly exposed as the volume of CVEs continues to climb.

As the dust settles on September 2026’s historic Patch Tuesday, the cybersecurity community will watch closely to see whether this month represents a peak or a new baseline. The data suggests that AI-assisted discovery is unlikely to slow down, meaning future updates may continue to push boundaries. For now, the message is clear: patch fast, prioritize intelligently, and prepare for a new era of vulnerability management where the haystack grows larger every month, even if the needles remain relatively scarce.

Share This Article