Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two actively exploited Windows zero-days, CVE-2026-85880 and CVE-2026-81963.
Microsoft fixed a record 974 CVEs in its September 2026 Patch Tuesday, surpassing the previous record of 570 in July 2026, with Windows affected by 723 flaws and Office by 111, including 119 critical vulnerabilities. Two zero-days are actively exploited: CVE-2026-85880, a 7.8 heap-based buffer overflow in Windows ALPC allowing AppContainer privilege escalation, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack enabling local privilege escalation. Microsoft attributed the update surge partly to agentic AI tools used to discover zero-day vulnerabilities, and researchers highlighted critical RCE flaws in Windows DNS, DHCP and Deployment Services as priorities.
- Record 974 CVEs, nearly double the prior 570 record from July
- CVE-2026-85880: exploited ALPC heap overflow enabling privilege escalation
- CVE-2026-81963: exploited Update Stack link resolution local EoP flaw
- Surge linked to agentic AI-based vulnerability discovery at Microsoft
- Priority RCEs in Windows DNS, DHCP Server and Deployment Services
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking s SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. NVD description · AI analysis pending | 10.0 | 2% | — | — | ||
| CVE-2026-62893 | Pre-auth use-after-free RCE in Microsoft Windows Deployment Services (WDS) Microsoft Windows Deployment Services (WDS) contains a use-after-free memory-safety flaw (CWE-416) that an unauthenticated attacker can trigger by sending crafted network traffic to the WDS service, leading to remote code execution on the target system. The vulnerability affects Windows 10 1607 and 1809 and Windows Server 2012, 2016, 2019, 2022, and 2025 on systems where WDS is deployed, a role typically used for network-based (PXE) operating system imaging. A successful exploit grants the attacker code execution with high confidentiality, integrity, and availability impact, reflected in the critical CVSS 3.1 score of 9.8 with network vector, low complexity, and no privileges or user interaction required. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, although EPSS estimates a 2.7% probability of exploitation within 30 days (85th percentile). The flaw was disclosed alongside Microsoft's record September 2026 Patch Tuesday, which shipped nearly 1,000 fixes including two Windows zero-days. Do: Apply Microsoft's September 2026 (or later) security updates for all affected Windows versions listed in the advisory. Because the vulnerable component is an optional role, audit Windows systems for the presence of Windows Deployment Services; disable the role where it is not needed and restrict network access to WDS/PXE endpoints on systems that require it but are not yet patched. Given the moderate EPSS score and lack of public PoC, prioritize patching internet-facing or shared-network WDS servers first and monitor for exploitation activity. | 9.8 group max | 3% |
| largeon the order of tens of thousands of WDS-enabled Windows systems worldwide (exact count and internet-exposed share unknown) | ||
| CVE-2026-81963 +1 in the same advisory: …85880 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 |
Full article498 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft has announced fixes for a record 974 CVEs in its September 2026 Patch Tuesday release.
The number of flaws included in this month’s update shatters the previous record for Patch Tuesday, which was 570 CVEs in July 2026.
The September CVE list spans Microsoft’s product portfolio, with Windows affected by most, at 723, followed by Office at 111.
The past three months have seen a substantial rise in the number of CVEs patched by the tech giant – 570 in July, 400 in August and 974 in September. Prior to that, 200 CVEs were included in June’s Patch Tuesday, 120 in May and 164 in April.
The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in the number of security updates they will need to apply to Windows products as a result of its use of agentic AI tools to discover zero-day vulnerabilities.
Given this new reality, it is more important than ever for security teams to deploy a risk-based approach to vulnerability management, ensuring they are prioritizing the flaws that pose the biggest risks to their business.
Responding to the latest Patch Tuesday announcement, Jack Bicer, director of vulnerability research at Action1, wrote: “At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its update on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
The first of these is CVE-2026-85880, assigned a high severity rating of 7.8. This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.
The other flaw, CVE-2026-81963, is an improper link resolution before file access in Windows Update Stack, which allows an authorized attacker to elevate privileges locally.
The update contains 119 critical vulnerabilities. In Action1’s Bicer’s blog, he recommended that security teams prioritize the following flaws:
- CVE-2026-62878. A remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow, given a critical rating of 9.8
- CVE-2026-62823. A remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow, given a high severity rating of 8.8
- CVE-2026-62893. A remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition, given a critical rating of 9.8
- CVE-2026-65789. A remote code execution vulnerability in Windows DNS caused by a use-after-free condition, given a high severity rating of 8.1
- CVE-2026-58231. three Critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform
Image credit: tomeqs / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/