Microsoft September 2026 Patch Tuesday fixes 966 flaws, including two exploited Windows zero-days

Microsoft released its September 2026 Patch Tuesday security updates, fixing a record 966 vulnerabilities across Windows and other products, including two zero-days already used in attacks. The exploited flaws are CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC), both local elevation-of-privilege bugs that can let an attacker who already has access gain SYSTEM rights. Microsoft says 105 of the fixed issues are critical.
Why it matters: This is a broad, urgent patch cycle affecting many Windows and Microsoft environments, and two of the bugs were already being exploited. Organizations and users should prioritize September Microsoft updates immediately, especially for systems where local compromise could be chained into full takeover.

Sources

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
info@thehackernews.com (The Hacker News) 2026.09.09 98% relevant
This is the same September 2026 Patch Tuesday event and appears to be another report on Microsoft's record monthly patch release, framing it as 974 flaws and highlighting the two exploited Windows zero-days.
Microsoft breaks Patch Tuesday record with 974-CVE deluge
2026.09.09 96% relevant
This is a direct update on the same Patch Tuesday event, with a revised total of 974 CVEs instead of 966 and additional details on the two exploited Windows zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack, both allowing SYSTEM privilege escalation, plus CISA KEV additions and a September 22 federal remediation deadline.
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
2026.09.08 96% relevant
This is the same Patch Tuesday event and adds that the final count reached 973 disclosed bugs, identifies the two actively exploited flaws as CVE-2026-81963 and CVE-2026-85880, notes CISA’s September 22 federal patch deadline, and provides context that CVE-2026-81963 affects the Windows update installation component.
Microsoft Plugs Nearly 1,000 Security Holes
BrianKrebs 2026.09.08 97% relevant
This is the same September 2026 Microsoft Patch Tuesday event and adds a fuller tally of 974 flaws, highlights the two exploited zero-days CVE-2026-81963 and CVE-2026-85880, and calls out likely-to-be-exploited critical issues including Windows DNS flaw CVE-2026-69730 and Windows Shell RCE CVE-2026-69829.
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Ionut Arghire 2026.09.08 98% relevant
This source covers the same September 2026 Microsoft Patch Tuesday release and adds specific counts and technical details on the two exploited zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in Windows Update Stack, plus notes on 20 potentially wormable flaws and servicing stack updates.
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Lawrence Abrams 2026.09.08 100% relevant
This article establishes a new monthly Patch Tuesday event for September 2026, centered on a distinct Microsoft release and two newly patched exploited zero-days not covered by the existing tracked Patch Tuesday stories for June, July, or August.
← Back to all stories