Microsoft has released its September 2026 security updates, addressing a staggering 974 Common Vulnerabilities and Exposures (CVEs) across its product portfolio, with 723 of those flaws affecting Windows alone. Among the most critical patches are two Windows elevation-of-privilege vulnerabilities — CVE-2026-85880 and CVE-2026-81963 — which attackers are already exploiting in the wild. This Patch Tuesday is not merely a routine cumulative update; it represents one of the largest single-month security fixes in Microsoft’s history, underscoring the escalating threat landscape and the urgent need for organizations and individual users to prioritize deployment.
September 2026 Patch Tuesday: A Record 974 CVEs Fixed
Microsoft’s September 2026 Patch Tuesday release marks a significant milestone in the company’s vulnerability management efforts. The update addresses 974 CVEs across Windows, Office, SQL Server, SharePoint, Azure, Exchange, and developer tools. Of these, 723 vulnerabilities are classified as Windows-specific, spanning kernel, Win32k, Windows Update Stack, and Advanced Local Procedure Call (ALPC) components. The sheer volume of fixes reflects the growing complexity of the Windows attack surface, as well as Microsoft’s aggressive internal discovery and third-party researcher collaboration.
This is not the first time Microsoft has released a patch batch exceeding 900 CVEs, but the concentration of privilege-escalation bugs and the inclusion of two actively exploited zero-days makes this month particularly noteworthy. The company’s Threat Intelligence Center (MSTIC) and external researchers from Volexity and Proofpoint contributed to identifying the most critical issues.
Two Zero-Days Under Active Exploitation: What Are the Vulnerabilities?
What are the two actively exploited vulnerabilities in Microsoft’s September 2026 update? The two vulnerabilities are CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) combined with an uninitialized resource, and CVE-2026-81963, an improper link resolution and access control flaw in the Windows Update Stack. Both allow a low-privileged attacker to escalate to SYSTEM privileges locally, and both have been detected in active exploitation before patches were released on September 8, 2026.
CVE-2026-85880: ALPC Sandbox Escape
CVE-2026-85880 resides in the Windows Advanced Local Procedure Call (ALPC) facility, a high-performance interprocess communication mechanism used by numerous system components. The vulnerability is a combination of a heap-based buffer overflow and the use of an uninitialized resource. An attacker who can execute code inside an AppContainer — a lightweight sandbox typically used by Microsoft Store apps, browsers, and other restricted environments — can exploit the flaw locally to escape the sandbox and obtain full SYSTEM privileges. The attack requires no user interaction, making it a potent weapon for malware that gains initial code execution via a separate vector.
Microsoft credited researchers at Volexity and Proofpoint for reporting this flaw. The fact that exploitation was already detected in the wild suggests that threat actors are actively chaining this privilege-escalation bug with initial access exploits, such as phishing or drive-by downloads, to achieve complete system compromise. Local privilege-escalation weaknesses are a staple of advanced persistent threat (APT) toolkits, and this ALPC vulnerability is particularly dangerous because it bypasses AppContainer restrictions, which are designed to contain malicious code.
CVE-2026-81963: Windows Update Stack Elevation
The second exploited zero-day, CVE-2026-81963, affects the Windows Update Stack. This component handles the download, installation, and verification of system updates. The vulnerability stems from improper link resolution and access controls, allowing an attacker with low-level privileges to elevate to SYSTEM. Microsoft’s Threat Intelligence Center (MSTIC) discovered the issue internally. While the Windows Update Stack is not typically exposed to user interaction, the fact that an attacker can exploit it locally means that once a foothold is established, they can move laterally or escalate privileges without triggering typical security alerts.
Both vulnerabilities underscore a recurring theme: privilege escalation remains the most common path to full system compromise. Microsoft has been investing heavily in reducing the attack surface of ALPC and the update stack, but these bugs demonstrate that even well-audited components can harbor subtle flaws.
Beyond Windows: A Broad Ecosystem of Fixes
September’s release extends far beyond the Windows kernel. Microsoft Office receives 111 fixes, addressing vulnerabilities in Excel, Word, PowerPoint, and the Office suite’s core components. SQL products see 62 patches, covering SQL Server, Azure SQL Database, and SQL Server Management Studio (SSMS). SharePoint Server receives 16 fixes, Azure 12, and Exchange Server 9. Developer tools, including Visual Studio and .NET, account for 22 vulnerabilities. This distribution reflects the interconnected nature of modern enterprise environments, where a single exploit in one product can cascade across multiple systems.
For organizations running Microsoft 365, the Office fixes are particularly critical. Many of the vulnerabilities are memory corruption issues that could be triggered by opening a malicious document. With phishing attacks still the primary vector for initial access, patching Office is as important as patching Windows.
Windows 11 Build Numbers and Secure Boot Certificate Rollout
For Windows 11 users, the cumulative updates are delivered via KB5124008 for versions 24H2 and 25H2, pushing systems to OS builds 26100.9445 and 26200.9445 respectively. Windows 11 26H1 receives KB5124012, updating to build 28000.2954. These updates are cumulative, meaning they include all previous security fixes and additional quality improvements.
An important part of the September update is the continued rollout of replacement Secure Boot certificates. The certificates used by many Windows devices began expiring in June 2026, and Microsoft is gradually deploying new certificates to ensure that systems can boot securely and verify the integrity of the OS. The company states that systems that have not yet received the newer certificates will continue to boot and install normal Windows updates while the rollout progresses. This is a multi-month transition, and users should not expect any immediate disruption, but it is a reminder that Secure Boot, while robust, requires periodic maintenance.
Windows 11 24H2 End of Servicing: A Critical Deadline
Windows 11 24H2 Home and Pro editions reach end of servicing on October 13, 2026. After that date, these editions will no longer receive monthly security updates, leaving users exposed to future vulnerabilities. The September 2026 update is one of the last security updates for these versions. Users of Windows 11 24H2 Home or Pro should plan to upgrade to a supported release — such as 25H2 or 26H1 — before the October deadline. Enterprise and Education editions of 24H2 may have longer support timelines, but home users face imminent risk.
Microsoft has historically given ample notice before end-of-service dates, but many users delay upgrades, increasing their exposure. The combination of two actively exploited zero-days and the looming end of support for 24H2 makes this month’s patch cycle a critical moment for system administrators and home users alike.
How to Install the September 2026 Cumulative Update
Users can install the update through the standard Windows Update path: Settings > Windows Update > Download & install all. The update requires a system restart to complete. Microsoft also offers direct download links for the standalone update packages via the Microsoft Update Catalog for offline installation on multiple machines.
Given the active exploitation of CVE-2026-85880 and CVE-2026-81963, it is strongly recommended that administrators expedite deployment. Backing up important data before installation is advisable to mitigate the risk of data loss from installation errors or unexpected power loss during the reboot process. For enterprise environments, testing the update in a staging environment first is prudent, although the severity of the zero-days may warrant a faster rollout.
Strategic Implications and Industry Context
The September 2026 Patch Tuesday is a stark illustration of the evolving threat landscape. The number of CVEs addressed — 974 in a single month — is a record for Microsoft, and it reflects the company’s expanding vulnerability disclosure program, which includes bug bounty rewards, internal fuzzing, and collaboration with security firms. However, the volume also raises questions about the sustainability of patch management. Organizations with limited IT resources may struggle to keep pace with monthly updates that routinely exceed 100 CVEs. The trend toward larger update batches is likely to continue as Microsoft’s codebase grows and as more security researchers focus on the platform.
The two zero-days are particularly concerning because they target core Windows components — ALPC and the Windows Update Stack — that are central to system security. The fact that attackers are already exploiting them suggests that reconnaissance and exploit development are ongoing, and that other zero-days may exist in similar components. The involvement of Volexity and Proofpoint, both known for their incident response expertise, indicates that these vulnerabilities were discovered in real-world attack scenarios, not just through theoretical analysis.
For security teams, the September update reinforces the importance of a layered defense. While patching is the first line of defense, privilege-escalation vulnerabilities can bypass many security controls. Application control, endpoint detection and response (EDR), and least-privilege principles are essential to mitigate the impact of such flaws. The sandbox escape capability of CVE-2026-85880 is a reminder that AppContainer isolation is not impenetrable, and that even sandboxed applications should be treated with caution.
Looking ahead, the Secure Boot certificate rollout and the end of servicing for Windows 11 24H2 are practical milestones that users must address. The certificate migration is a long-term process that will continue for months, but it is vital for maintaining the integrity of the boot chain. The end of support for 24H2 Home and Pro is a concrete deadline that should not be ignored. Upgrading to a supported version is the only way to receive future security updates, and the cost of delaying is exposure to future vulnerabilities.
In summary, the September 2026 Patch Tuesday is a comprehensive but urgent update. The two actively exploited privilege-escalation flaws demand immediate attention, and the broader set of fixes across Office, SQL, SharePoint, and Azure addresses vulnerabilities that could be leveraged in multi-stage attacks. Users should install the update as soon as practical, plan for the Windows 11 24H2 end of service, and ensure that their Secure Boot certificates are up to date. The cybersecurity landscape is unforgiving, and this month’s patches are a reminder that staying current is not optional — it is a necessity.