Microsoft Releases Record 974 Patches, Including 2 Zero-Days
Microsoft released a record 974 patches across its products, including two previously exploited zero-day vulnerabilities. The first, CVE-2026-85880, allows local attackers to escalate privileges on Windows systems. The second, CVE-2026-81963, enables local attackers to elevate privileges in Windows Update components. Microsoft has not patched these vulnerabilities in four years. Additionally, 20…
Key points
- Microsoft released 974 security patches
- Two zero-day vulnerabilities were exploited
- 20 vulnerabilities are considered potentially wormable
Microsoft's monthly patch has 974 security fixes, including 2 exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities - almost all of them found by AI systems
securityweek.com · 10 September 2026
Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days.
The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges.
“An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory.
Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out.
The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in Windows Update Stack, the components used for Windows update installation. The vulnerability also allows local attackers to elevate their privileges to System.
As Narang notes, this is the first Update Stack security weakness to be flagged as a zero-day of the seven flaws resolved in the component over the past five years.
Overall, Microsoft rolled out patches for 723 flaws in Windows and fixed 222 security bugs in its Office suite, including 111 in Office 2016 for this month’s Patch Tuesday. Multiple security issues were also addressed in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9).
Also as part of its September 2026 Patch Tuesday updates, Microsoft rolled out fresh Servicing Stack Updates (SSU), which are classified as critical updates. They apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.
Some of the issues that deserve special attention include CVE-2026-55007 (remote code execution (RCE) in Exchange Server), CVE-2026-80097 (elevation of privilege (EoP) in Authenticator), CVE-2026-69465 (RCE in SharePoint, CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), ZDI’s Dustin Childs says.
According to Childs, 20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction.
“One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang said.
“AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context,” he added.
According to Fortra associate director Tyler Reguly, the large number of newly released patches, which is not a Microsoft-specific trend, shows that proactive vendors are keen on reducing the attack surface.
“Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated,” Reguly said.
This text was published by securityweek.com and written by Ionut Arghire. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
Coverage and discussion
2 sources- Reddit discussion reddit.com
- Why this month's Microsoft patch release is a doozy Press · Ars Technica AI ·
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
Comments
via GitHub Discussions