Back to Feed
VulnerabilitiesSep 8, 2026

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft patches 974 vulnerabilities, including two zero-days exploited in the wild.

Summary

Microsoft's September Patch Tuesday addresses a record-breaking 974 vulnerabilities, including two zero-days that were actively exploited. One zero-day, CVE-2026-85880, is a heap buffer overflow in Windows ALPC allowing privilege escalation, and the other, CVE-2026-81963, is an update stack flaw also enabling privilege escalation. The update also includes fixes for 20 potentially wormable vulnerabilities.

Full text

Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory. Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out. The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in Windows Update Stack, the components used for Windows update installation. The vulnerability also allows local attackers to elevate their privileges to System. As Narang notes, this is the first Update Stack security weakness to be flagged as a zero-day of the seven flaws resolved in the component over the past five years.Advertisement. Scroll to continue reading. Overall, Microsoft rolled out patches for 723 flaws in Windows and fixed 222 security bugs in its Office suite, including 111 in Office 2016 for this month’s Patch Tuesday. Multiple security issues were also addressed in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9). Also as part of its September 2026 Patch Tuesday updates, Microsoft rolled out fresh Servicing Stack Updates (SSU), which are classified as critical updates. They apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016. Some of the issues that deserve special attention include CVE-2026-55007 (remote code execution (RCE) in Exchange Server), CVE-2026-80097 (elevation of privilege (EoP) in Authenticator), CVE-2026-69465 (RCE in SharePoint, CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), ZDI’s Dustin Childs says. According to Childs, 20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction. “One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang said. “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context,” he added. According to Fortra associate director Tyler Reguly, the large number of newly released patches, which is not a Microsoft-specific trend, shows that proactive vendors are keen on reducing the attack surface. “Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated,” Reguly said. Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Related: The Hidden Instructions That Can Hijack AI Agents Related: SAP Patches Critical Extended Passport Processing Vulnerability Related: MikroTik Patches Critical Flaws Chained to Hack Routers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire N-able Patches Critical Zero-Day in N-centralNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitAdobe Commerce Zero-Day Exploited to Backdoor Online StoresModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesHPE Patches Critical RCE Vulnerabilities in AOS-CXSangoma Switchvox Vulnerability Exploited in the Wild Latest News Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayThe Hidden Instructions That Can Hijack AI AgentsHackers Return $263 Million Stolen From Liquid NetworkCylake Raises $245 Million Ahead of Cybersecurity Platform BetaSAP Patches Critical Extended Passport Processing VulnerabilityParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftMikroTik Patches Critical Flaws Chained to Hack RoutersMathspace Data Breach Exposes Over 1 Million People Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-85880
  • cve — CVE-2023-21674
  • cve — CVE-2026-81963
  • cve — CVE-2026-55007
  • cve — CVE-2026-80097
  • cve — CVE-2026-69465
  • cve — CVE-2026-65669
  • cve — CVE-2026-69525

Entities

Microsoft (vendor)Windows (product)Exchange Server (product)SharePoint Server (product)SQL Server (product)Remote Desktop Services (product)