Full Breakdown
Microsoft’s September 2026 Patch Tuesday Sets Record with 974 Vulnerabilities, Two Actively Exploited Zero-Days
9/9/2026, 5:13:56 PM
Core Event – Record-Breaking Patch Release
On September 8 2026 Microsoft issued its monthly Patch Tuesday updates, addressing a record 974 CVEs. The bulletin includes two privilege-escalation flaws already exploited in the wild: CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC) and CVE-2026-81963 in the Windows Update Stack. Both allow a low-privilege attacker to obtain SYSTEM-level rights. The update also contains 20 wormable bugs and a critical remote-code-execution flaw in Microsoft Exchange (CVE-2026-55007).
Background & Context – Accelerating Vulnerability Discovery
Microsoft’s monthly counts have risen sharply in 2026, driven by AI-assisted code auditing. The company patched 723 Windows flaws, 111 Office issues, 62 SQL Server bugs, and 22 developer-tool vulnerabilities. Prior months recorded 457 fixes in August and 663 in July, showing a sustained upward trend.
Data & Statistics – Scope of the September Bulletin
- Total Microsoft-origin CVEs: 974 (record)
- Windows-specific CVEs: 723
- Critical-severity CVEs: >110
- Exploited zero-days: 2 (both elevation-of-privilege)
- Exchange Server RCE (CVE-2026-55007): remote code execution via malicious Visio attachment
- Non-Microsoft CVEs addressed: 25, bringing the overall September count to 999.
Official Statements & Responses
CISA added the two exploited Windows flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply the patches by September 22 2026 and to address the Adobe Commerce zero-day by September 11 2026. Microsoft confirmed ongoing exploitation but did not disclose attacker identities. Tenable urged organizations to prioritize “exposed remote-code-execution paths” over sheer CVE counts. Rapid7 warned that the lack of a Microsoft advisory for the Chrome-patched V8 engine bug (CVE-2026-85046) could hinder exposure tracking.
Criticism & Opposition – Concerns Over Advisory Gaps and Metric Inflation
Adam Barnett, lead software engineer at Rapid7, argued that missing advisories complicate defensive tracking, suggesting that reliance on advisories alone could cause organizations to overlook zero-day exposure.
Conflicting Reports & Gaps – Discrepancies in Total Counts and Advisory Coverage
Sources differ on the exact number of CVEs released: The Register cites 974 Microsoft-origin CVEs, SecurityAffairs reports a range of 966–997, while The Hacker News and Quasa reference a total of 999 when non-Microsoft fixes are added. Google patched the V8 engine zero-day on September 3 2026, but Microsoft has not issued a corresponding advisory for Edge.
Verbatim Quotes
- “At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first,” — Jack Bicer, director of vulnerability research at Action1
- “September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026,” — Satnam Narang, senior staff research engineer at Tenable
What’s Next – Upcoming Deadlines and Lifecycle Changes
- CISA KEV compliance: Federal agencies must install the Microsoft patches by September 22 2026 and the Adobe Commerce fix by September 11 2026.
- Product support transitions: Windows 11 24H2 Home & Pro and Windows Server 2022 will enter extended-support phases on October 14 2026, while Windows Server 2012/2012 R2 will exit paid Extended Security Updates the same day.
- Advisory monitoring: Security teams should watch for future Microsoft advisories addressing the V8 engine vulnerability and any additional zero-day disclosures.
