Microsoft has set a new benchmark in its Patch Tuesday history, addressing an impressive 974 vulnerabilities across its extensive software suite. This month’s updates include critical patches for two vulnerabilities that have been actively exploited in the wild, underlining the urgency of the situation.
Vulnerability Breakdown
The vulnerabilities patched this month are categorized as follows:
- 723 flaws in Windows
- 111 in Office and Office 2016
- 62 in SQL
- 22 in Developer Tools
Among these, more than 110 vulnerabilities have been rated as critical. The predominant types of vulnerabilities include privilege escalation, remote code execution, and information disclosure, which collectively represent nearly 90% of the issues addressed this month. In total, with the inclusion of fixes for 25 non-Microsoft CVEs, the number of vulnerabilities resolved reaches 999.
In comparison, Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May, illustrating a significant uptick in security efforts.
Jack Bicer, director of vulnerability research at Action1, emphasized the challenges posed by such a large volume of updates. “At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first,” he noted. “With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”
Active Exploitation Concerns
The two vulnerabilities currently under active exploitation are:
- CVE-2026-85880 (CVSS score: 7.8) – A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC), enabling an authorized attacker to elevate privileges locally and gain SYSTEM privileges.
- CVE-2026-81963 (CVSS score: 7.8) – An improper link resolution vulnerability in the Windows Update Stack, also allowing an authorized attacker to elevate privileges locally and gain SYSTEM privileges.
Microsoft’s advisory for CVE-2026-85880 warns that an attacker could exploit this vulnerability locally to escape the sandbox and elevate privileges without requiring additional user interaction. Adam Barnett, lead software engineer at Rapid7, confirmed that all supported versions of Windows have received a patch for CVE-2026-81963, enhancing controls to prevent malicious link exploitation.
Cybersecurity firms Volexity and Proofpoint have been credited with reporting CVE-2026-85880, while Romain Deperne from Airbus Helicopters and the Microsoft Threat Intelligence Center (MSTIC) contributed to the identification of CVE-2026-81963.
Despite the detection of zero-day exploitation efforts targeting these vulnerabilities, Microsoft has not disclosed specifics regarding the perpetrators or the scale of the attacks.
Notable Flaws and Trends
Among the other significant vulnerabilities patched this month are:
- CVE-2026-55007 (CVSS score: 8.1) – A double free vulnerability in Microsoft Exchange Server allowing unauthorized code execution over a network.
- CVE-2026-80097 (CVSS score: 8.6) – An improper authentication vulnerability in Microsoft Authenticator enabling local privilege elevation.
- CVE-2026-69465 (CVSS score: 8.8) – A missing authorization vulnerability in Microsoft Office SharePoint allowing code execution over a network.
- CVE-2026-65669 (CVSS score: 9.6) – An injection vulnerability in SQL Server permitting unauthorized privilege elevation over a network.
- CVE-2026-69525 (CVSS score: 9.8) – A use-after-free vulnerability in Windows Remote Desktop Services enabling unauthorized code execution over a network.
- CVE-2026-69595 (CVSS score: 9.8) – A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver allowing unauthorized code execution over a network.
- CVE-2026-69730 (CVSS score: 9.8) – A use-after-free vulnerability in Windows DNS server enabling unauthorized code execution over a network.
- CVE-2026-69829 (CVSS score: 9.8) – A heap-based buffer overflow vulnerability in Windows Shell allowing unauthorized code execution over a network.
- CVE-2026-72979 (CVSS score: 9.8) – A use-after-free vulnerability in Windows DHCP Server enabling unauthorized code execution over a network.
According to TrendAI’s Zero Day Initiative (ZDI), Microsoft has addressed a total of 2,760 security flaws this year, reflecting the ongoing trend of AI-assisted vulnerability discoveries.
Satnam Narang, senior staff research engineer at Tenable, remarked on the significance of this month’s Patch Tuesday, stating, “September’s release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month, setting a new record.” This month’s updates represent a 70% increase over the previous record of 569 in July, bringing this year’s total to over 2,600 vulnerabilities addressed.
Despite the extensive patching, the actual impact on most organizations remains relatively low, with no significant spike in active exploits observed thus far. Narang emphasized the importance for organizations to discern which vulnerabilities are relevant to them and prioritize remediation based on risk context.
Tyler Reguly, associate director of Security R&D at Fortra, commented on the broader implications of the situation, stating, “As long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning.” He noted that this issue is not unique to Microsoft, as similar patterns are observed with other major vendors. Ultimately, he expressed optimism that the proactive approach to addressing vulnerabilities will reduce the attack surface and lead to a return to a more typical patching cadence in the future.