September 2026 Patch Tuesday: 966 Flaws, 2 Zero-Days
The September Patch Tuesday became the largest security update release in Microsoft’s history. The company closed 966 vulnerabilities, two of which attackers had already wielded in real-world attacks. Previous records proved short-lived: in July, Microsoft mended 570 flaws, and in August a further 400.
A Record-Breaking Breakdown
Among the September vulnerabilities, 105 earned critical status. This tally included 81 remote code execution flaws, 20 privilege escalation bugs, two information disclosures, and one security feature bypass.
Counting every severity level paints a fuller picture. In total, 438 vulnerabilities permit privilege elevation, 258 involve remote code execution, and 173 expose data. Furthermore, 56 trigger denial of service, 19 bypass protections, and 16 allow the spoofing of data or identity.
Two Actively Exploited Zero-Days
Particular attention fell upon two zero-days already deployed to breach Windows. The first, CVE-2026-81963, resides in the Windows Update Stack. A flaw in resolving links before file access lets an authorized attacker locally elevate privileges to SYSTEM. Microsoft has yet to reveal who exploited the vulnerability or in which attacks.
The second zero-day, CVE-2026-85880, affects the Windows Advanced Local Procedure Call (ALPC) mechanism, through which processes communicate within the system. A heap-based buffer overflow allows an attacker who has already gained local access to likewise reach SYSTEM privileges. Specialists at Volexity uncovered the vulnerability, alongside Mark Kelly, David Galazin, and Jeremy Hedges of Proofpoint. Details of the real-world attacks remain unpublished. Microsoft’s advisory listing appears in the official Microsoft Security Update Guide vulnerability catalog.
Why Local Privilege Escalation Matters
Both problems concern local privilege escalation, so on their own they cannot compromise a computer over the internet. Yet after an initial intrusion, this class of flaw grows especially prized among attackers. An ordinary account transforms into SYSTEM-level access, whereupon malicious software gains nearly maximal rights in Windows.
An Even Larger Picture
The scale of the September release looms larger still if one counts the vulnerabilities Microsoft patched early in the month, separately from Patch Tuesday. Such problems numbered another 204 across Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Edge, Microsoft Fabric, Power Automate, and other products. Consequently, during the first days of September the number of closed vulnerabilities surpassed 1,100.
Microsoft attributes this rapid surge in fixes partly to automated bug hunting and the application of AI. Back in May, the company explained that its engineers and independent specialists were discovering ever more defects thanks to new analysis tools. The trend shows clearly in recent releases: the July Patch Tuesday closed 570 vulnerabilities, while the August release delivered fixes for another 400.
How to Get the Updates
The September updates arrive through Windows Update and Microsoft’s other standard channels. For Windows 11 versions 24H2 and 25H2, update KB5124008 was released. In September, even devices tied to the hotpatch mechanism must reboot, since some changes touch components that cannot be updated without restarting the system.
The full list of vulnerabilities reveals how unusual the present Patch Tuesday has become. Merely two months ago, 570 fixed problems ranked as Microsoft’s absolute record. Now the September release has approached a thousand within a single day of updates alone.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.