
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.
These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month. Along with Microsoft's fixes for 25 non-Microsoft CVEs, the update brings the total number of vulnerabilities resolved to 999.
September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May.
"At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first," Jack Bicer, director of vulnerability research at Action1, said. "With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle."
The two vulnerabilities that have come under active exploitation are listed below -
- CVE-2026-85880 (CVSS score: 7.8) - A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
- CVE-2026-81963 (CVSS score: 7.8) - An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
"An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880. "No additional user interaction is required."
Adam Barnett, lead software engineer at Rapid7, said all supported versions of Windows receive a patch for CVE-2026-81963, a move that "presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter."
Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an offensive security researcher at Airbus Helicopters, and the Microsoft Threat Intelligence Center (MSTIC) have been credited with the second bug.
The Windows maker said it has detected zero-day exploitation efforts targeting the flaws, but did not disclose any specifics as to who is behind them, the scale of such efforts, and if those attacks have successfully breached any victims.
Per exposure management and vulnerability assessment platform Tenable, there have been seven privilege escalation flaws in the Windows Update Stack since 2022. However, CVE-2026-81963 is the first zero-day as well as the first to be exploited in the wild. As for CVE-2026-85880, it's the second to be weaponized as a zero-day since CVE-2023-21674, which was addressed in January 2023.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
Some of the other notable flaws patched by Microsoft are as follows -
- CVE-2026-55007 (CVSS score: 8.1) - A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network
- CVE-2026-80097 (CVSS score: 8.6) - An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally
- CVE-2026-69465 (CVSS score: 8.8) - A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network
- CVE-2026-65669 (CVSS score: 9.6) - An injection vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network
- CVE-2026-69525 (CVSS score: 9.8) - A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network
- CVE-2026-69595 (CVSS score: 9.8) - A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows an unauthorized attacker to execute code over a network
- CVE-2026-69730 (CVSS score: 9.8) - A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network
- CVE-2026-69829 (CVSS score: 9.8) - A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network
- CVE-2026-72979 (CVSS score: 9.8) - A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network
According to TrendAI's Zero Day Initiative (ZDI), Microsoft has patched a total of 2,760 security flaws this year alone, indicating how artificial intelligence (AI)-assisted vulnerability discoveries are unlikely to slow down any time soon.
"September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026," Satnam Narang, senior staff research engineer at Tenable, said in a statement shared with The Hacker News.
"To put it into context, this month's Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year's total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go."
Despite the massive batch of patches, the number of vulnerabilities that are expected to impact most organizations remains quite low, not to mention the absence of a correlating spike in active exploits so far. Narang added that it's critical for organizations to understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable over the internet, and prioritize remediation based on this risk context.
"I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning," Tyler Reguly, associate director of Security R&D at Fortra, said.
"This is not a Microsoft specific problem. We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we're reducing the attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence.