Microsoft patches a record 972 vulnerabilities, 112 of them critical
Microsoft's September Patch Tuesday fixes a record 972 vulnerabilities, 112 rated critical, including two zero-days in Windows components.
Microsoft's September 2026 release patched roughly 972 vulnerabilities (997 including ported Chromium fixes for Edge), a record, with 112 rated critical. Notable flaws include two zero-days: CVE-2026-81963 in the Windows update service and CVE-2026-85880 in the Windows Advanced Local Procedure, with no public information on exploitation breadth. Microsoft has fixed 2,760 vulnerabilities in 2026, more than double last year's total, which ZDI's Dustin Childs attributes to AI-assisted discovery becoming the 'new normal'.
- 112 of the 972 patched vulnerabilities are rated critical; the rest are rated important.
- Two zero-days: CVE-2026-81963 (Windows update service) and CVE-2026-85880 (Windows Advanced Local Procedure).
- No public information yet on who is exploiting the zero-days or how widely.
- 2026 total of 2,760 fixes exceeds last year by more than 2x; record volume called the 'new normal'.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81963 +1 in the same advisory: …85880 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 |
Full article350 words · extracted from arstechnica.com · click to collapse
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.
Welcome to the new normal
Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial.
“On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,” Childs wrote Tuesday. “On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits—yet.”
Counting the precise number of vulnerabilities fixed in a monthly patch release for Microsoft is never an exact science. In some cases, the bugs were previously addressed or affected non-Microsoft products. By Childs’ count, Tuesday’s release patches 972 vulnerabilities, and 997 when counting the porting of fixes for the Chromium browser incorporated into Edge. Of the new vulnerabilities, 112 of them are rated critical, with the remainder carrying the important designation. Already this year, Microsoft has fixed 2,760 vulnerabilities, more than double the number from last year. At this rate, Microsoft will complete the year having fixed more bugs than all of 2023, 2024, and 2025 combined.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/