Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due to the company's use of agentic AI tools for discovering zero-day vulnerabilities.
The September update, released on September 8, addressed a wide array of products, with Windows accounting for the majority of fixes at 723 CVEs, followed by Office with 111. The past three months have shown a clear upward trend in the number of CVEs patched, with 570 in July, 400 in August, and the current 974 in September. This contrasts with earlier figures for the year, which included 200 CVEs in June, 120 in May, and 164 in April.
Among the 974 CVEs, 119 were rated as critical. Microsoft specifically highlighted two zero-day flaws that were confirmed to be actively exploited by threat actors at the time of the update. The first, CVE-2026-85880, is a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC). Rated with a high severity score of 7.8, this flaw could allow an attacker with low-privilege AppContainer code execution to achieve local privilege escalation. The second actively exploited flaw, CVE-2026-81963, involves improper link resolution before file access in the Windows Update Stack, enabling an authorized attacker to elevate privileges locally.
Given the unprecedented scale of the September update, security experts emphasized the need for a risk-based approach to vulnerability management. The challenge for IT and security teams is to quickly identify and prioritize vulnerabilities that demand immediate attention from those that can follow a standard deployment cycle.
Several other vulnerabilities were identified as high-priority for patching. These include CVE-2026-62878, a critical remote code execution (RCE) vulnerability in Windows DNS Server stemming from a stack-based buffer overflow, with a severity rating of 9.8. Another critical RCE, CVE-2026-62893, affects Windows Deployment Services due to a use-after-free condition, also rated 9.8.
Additional high-severity RCE vulnerabilities include CVE-2026-62823 in Windows DHCP Server, caused by a heap-based buffer overflow and rated 8.8, and CVE-2026-65789 in Windows DNS, resulting from a use-after-free condition and rated 8.1. The update also addressed three critical vulnerabilities, CVE-2026-58231, spanning Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform.






