Microsoft Addresses Record 974 Vulnerabilities, Including Two Exploited Windows Zero-Days
Microsoft has released a record-breaking Patch Tuesday update, fixing 974 vulnerabilities across its software, including two actively exploited zero-day flaws in Windows.

Microsoft on Tuesday issued an unprecedented Patch Tuesday update, resolving a record 974 vulnerabilities across its software ecosystem. Among the massive batch of fixes are two zero-day flaws in Windows that had already been actively exploited by attackers in the wild. The company reported 723 vulnerabilities in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Over 110 of these flaws were classified as critical severity. Privilege escalation, remote code execution, and information disclosure vulnerabilities accounted for nearly 90% of the issues addressed.
The two zero-day vulnerabilities requiring immediate attention are CVE-2026-85880 and CVE-2026-81963. CVE-2026-85880, rated with a CVSS score of 7.8, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that allows a local attacker with privileges to gain SYSTEM access. Microsoft stated in an advisory that an attacker in a low-privilege AppContainer could exploit this flaw to escape the sandbox and elevate their privileges without requiring user interaction. The second zero-day, CVE-2026-81963, also with a CVSS score of 7.8, involves an improper link resolution in the Windows Update Stack, enabling a local attacker to escalate privileges. Rapid7's Adam Barnett noted that patching this vulnerability presumably strengthens controls to prevent the Windows Update Stack from being tricked into overwriting system components with malicious files.
These zero-day exploits were reported by cybersecurity firms Volexity and Proofpoint (CVE-2026-85880), and by Romain Deperne, an offensive security researcher at Airbus Helicopters, and the Microsoft Threat Intelligence Center (MSTIC) (CVE-2026-81963). Microsoft confirmed detection of exploitation attempts but did not provide details on the attackers, their methods, or the extent of any breaches. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by September 22, 2026.
Record-Setting Pace for Vulnerabilities
The sheer volume of patches this month shatters previous records, highlighting an escalating trend in vulnerability discovery and disclosure. According to Tenable, Microsoft has now addressed a total of 2,760 security flaws in 2026 alone. Satnam Narang, senior staff research engineer at Tenable, commented that September's release marks another milestone, with nearly 1,000 CVEs patched, setting a new record for 2026. Narang stated, "September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026." He added that this month's total represents a nearly 70% increase over the previous record of 569 set in July, pushing the year-to-date total to over 2,600, which is more than double the record-setting year of 2020, with three months remaining in 2026.
The increasing number of vulnerabilities patched monthly presents significant challenges for IT and security teams. Jack Bicer, director of vulnerability research at Action1, noted, "At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first." He emphasized the need for rapid prioritization to distinguish critical patches from those that can follow standard deployment schedules. Despite the high volume, the actual number of vulnerabilities expected to impact most organizations remains relatively low, and there hasn't been a corresponding surge in active exploits reported for the majority of these flaws.
Tyler Reguly, associate director of Security R&D at Fortra, suggested that large CVE counts might indicate a vendor playing catch-up, but also acknowledged that these extensive patching efforts are beneficial for reducing the overall attack surface. "I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning," Reguly said. "This is not a Microsoft specific problem. We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we're reducing the attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence."
Among other notable patches are fixes for a double free vulnerability in Microsoft Exchange Server (CVE-2026-55007), an improper authentication flaw in Microsoft Authenticator (CVE-2026-80097), and a missing authorization vulnerability in Microsoft Office SharePoint (CVE-2026-69465). Critical issues also include vulnerabilities in SQL Server (CVE-2026-65669), Windows Remote Desktop Services (CVE-2026-69525), Windows Services for NFS ONCRPC XDR Driver (CVE-2026-69595), Windows DNS server (CVE-2026-69730), Windows Shell (CVE-2026-69829), and Windows DHCP Server (CVE-2026-72979), many carrying a CVSS score of 9.6 or higher.
