New Record in Microsoft Patches
Microsoft fixes 974 flaws, including two exploited zero-days, but only a few matter to most orgs.
Microsoft's September 2026 Patch Tuesday set a new company benchmark: 974 vulnerabilities resolved at once, among them two flaws already under active exploitation as zero-days. The volume eclipses any prior monthly release, yet security professionals caution that the raw count can mislead organizations about actual risk.
Two Zero-Days Exploited in the Wild
The first exploited issue, tracked as CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component. Microsoft's advisory states that an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required.
Microsoft had not patched an ALPC flaw since April 2023, and this is only the second zero-day in the component resolved in nearly four years. The earlier one, CVE-2023-21674, was addressed in January 2023. Tenable senior staff research engineer Satnam Narang highlighted that distinction.
The second zero-day, CVE-2026-81963, is an improper link resolution before file access ('link following') defect in Windows Update Stack, the components responsible for installing Windows updates. This vulnerability also permits local attackers to elevate privileges to System. Narang noted that this marks the first Update Stack security weakness flagged as a zero-day among the seven flaws resolved in that component over the past five years.
“An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory.
The quoted advisory text reflects the criticality of the ALPC flaw, emphasizing sandbox escape and privilege escalation without any user action.
The Scope of This Month's Fixes
Beyond the zero-days, Microsoft addressed a broad swath of product lines. Windows received patches for 723 flaws, and the Office suite saw 222 security bugs resolved, including 111 specifically in Office 2016. Other components were not immune: SQL Server had 62 fixes, Developer Tools 22, SharePoint Server 16, Azure 12, Skype for Business 10, and Exchange Server 9.
- 974 total CVEs patched—a new record for a single Patch Tuesday
- 723 Windows flaws resolved
- 222 Office security bugs fixed, including 111 in Office 2016
- 20 vulnerabilities considered wormable, enabling RCE without authentication or user interaction
The breadth reflects ongoing investment in security, but also complicates prioritization for IT teams.
Servicing Stack Updates and Other Releases
In addition to the security fixes, Microsoft rolled out fresh Servicing Stack Updates (SSU), classified as critical updates. These apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016. Servicing Stack Updates are designed to improve the reliability of the update installation process itself.
Other Notable Vulnerabilities
ZDI's Dustin Childs highlighted several issues deserving special attention: CVE-2026-55007 (remote code execution in Exchange Server), CVE-2026-80097 (elevation of privilege in Authenticator), CVE-2026-69465 (RCE in SharePoint), CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services). Childs also noted that 20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction.
Vendors' Growing Patch Volumes
The massive release is not exclusive to Microsoft. Fortra associate director Tyler Reguly observed that the large number of newly released patches, which he described as not a Microsoft-specific trend, shows that proactive vendors are keen on reducing the attack surface. Reguly expects that eventually, long-standing vulnerabilities will be fixed, and Patch Tuesday will return to its typical cadence.
Prioritization Amidst Rising Counts
Satnam Narang offered perspective on the rising numbers. He said that while the number of vulnerabilities being patched is rising, the number that can and will affect most organizations remains quite low. Narang attributed the growth, in part, to AI-assisted vulnerability discovery in 2026, which he said is creating larger haystacks but not finding more needles.
“One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang said.
He added that it is critical for organizations to understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and to prioritize remediation based on this risk context.
Why It Matters for Your Patch Queue
For security teams, the record-breaking patch count could mean hours of additional triage. Yet the experts' guidance suggests that focusing solely on quantity would be a mistake. The two zero-days—both local privilege escalation flaws—should be at the top of most Windows administrators' lists, especially since no user interaction is required for the ALPC bug. The wormable remote code execution flaws, though not yet exploited, could pose significant risks if left unpatched in internet-facing systems. The rise in patch volumes, driven partly by AI-assisted discovery, may continue to strain resources, but the underlying risk remains concentrated in a small subset. Prioritizing by exploitability and reachability, rather than by sheer count, could help organizations manage the load without losing sight of the threats that actually matter.
Sources
- SecurityWeek Original source
Continue Reading
Windows Server 2016 hit by 0xc0000409 after August updates
Microsoft says August 2026 security updates trigger 0xc0000409 errors on Windows Server 2016 when Compatibility Appraiser is enabled.
Google Warns on AI Coding Tool Threats
Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.
Adobe Commerce bug exploited before hotfix
Sansec reports active attacks on a max-severity Magento flaw, with backdoors and secondary access found.