September 2026 Patch Tuesday Shatters Microsoft’s Record With 966 Security Fixes
Microsoft’s September 2026 Patch Tuesday fixes a record 966 security vulnerabilities, including two zero-days that attackers are actively exploiting.
Microsoft has released Patch Tuesday updates for Windows 11 alongside Windows 10 KB5122878, delivering what appears to be the company’s largest Patch Tuesday security release to date.
Microsoft has patched a record-breaking number of security vulnerabilities
According to BleepingComputer, Microsoft addressed 966 vulnerabilities in the September release, with 105 classified as Critical.
The Critical vulnerabilities include:
- 81 remote code execution vulnerabilities
- 20 elevation of privilege vulnerabilities
- 2 information disclosure vulnerabilities
- 1 security feature bypass vulnerability
Across all severity levels, Microsoft addressed approximately:
- 438 Elevation of Privilege vulnerabilities
- 258 Remote Code Execution vulnerabilities
- 173 Information Disclosure vulnerabilities
- 56 Denial of Service vulnerabilities
- 19 Security Feature Bypass vulnerabilities
- 16 Spoofing vulnerabilities
The 966 total doesn’t include another 204 fixes
The already massive 966-vulnerability figure only counts security flaws Microsoft addressed as part of Patch Tuesday itself.
It does not include another 204 vulnerabilities that Microsoft fixed earlier in September across products and services including Azure, Copilot Studio, Entra ID, Edge, Microsoft Fabric, and Power Automate.
That means Microsoft’s actual number of security fixes released during September is already considerably higher than the headline Patch Tuesday figure.
Windows Update Stack zero-day gives attackers SYSTEM privileges
One of the most important fixes covers CVE-2026-81963, an actively exploited elevation of privilege vulnerability affecting the Windows Update Stack.
The vulnerability involves improper link resolution before Windows accesses a file, a weakness also known as link following.
An authorized attacker with local access can exploit the vulnerability to elevate privileges and gain SYSTEM-level permissions.
Microsoft has confirmed that attackers exploited the vulnerability in real-world attacks, but the company has not disclosed how those attacks worked.
Microsoft also fixes an actively exploited Windows ALPC flaw
The second zero-day, CVE-2026-85880, affects Windows Advanced Local Procedure Call, or ALPC.
Microsoft describes the vulnerability as a heap-based buffer overflow that allows an authorized local attacker to elevate privileges.
A successful attack can give the attacker SYSTEM privileges, providing extensive control over the affected Windows system.
Microsoft has also confirmed active exploitation of this flaw but has not released details explaining how attackers used it in attacks.
The September release significantly exceeds Microsoft’s other recent record-sized Patch Tuesday updates.
Microsoft previously fixed 570 security vulnerabilities in July 2026, which was itself an unusually large security release.
That was followed by around 400 vulnerabilities addressed in August. September’s 966 fixes therefore represent a major increase even compared with those releases.
The rise also comes after Microsoft began using an AI-powered vulnerability discovery system to find security weaknesses across its software products.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages