ZeroHour
Story · 1 source · 1 articlefirst updated ()

Microsoft's record September 2026 Patch Tuesday fixes 974 vulnerabilities, including two actively exploited Windows zero-days

highExploit / PoCexploited in the wildimportance 86CVE-2026-81963CVE-2026-85880
What's new: Initial merged summary combining the first two reports (CyberScoop and Malwarebytes Labs). No prior story summary existed. Key reconciliation: CyberScoop's headline count of 974 vulnerabilities matches Malwarebytes' total, which Malwarebytes breaks down as 964 customer-patchable CVEs plus cloud-only fixes; both reports agree on the two exploited zero-days (CVE-2026-81963, CVE-2026-85880) and…
Merged summary · glm-5.3 · rewritten as coverage arrives

Microsoft's largest-ever Patch Tuesday addresses 974 listed vulnerabilities (964 customer-patchable per Malwarebytes), including actively exploited privilege-escalation zero-days CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC), both…

Microsoft's September 2026 Patch Tuesday is the largest release on record. CyberScoop reports 974 vulnerabilities patched, while Malwarebytes specifies 964 customer-patchable CVEs (104 Critical, 860 Important) out of 974 total including cloud-only fixes; CyberScoop states more than 1 in 10 of the 974 defects are rated critical, consistent with Malwarebytes' 104 Critical count. Two zero-days were actively exploited before disclosure: CVE-2026-81963, a link-following elevation-of-privilege flaw in the Windows Update Stack, and CVE-2026-85880, a Windows ALPC heap overflow allowing AppContainer sandbox escape. Both carry CVSS 7.8 and grant SYSTEM-level access after an attacker gains an initial foothold; neither provides remote access on its own. Per CyberScoop, 723 of the flaws affect Windows, 111 affect Office, 62 affect SQL, and 22 affect developer tools. Malwarebytes notes the release also includes high-severity RCE fixes for Windows DNS Server, Remote Desktop Services, Exchange Server, SharePoint, and SQL Server. CyberScoop reports researchers attribute the record volume to AI-assisted vulnerability discovery without a corresponding rise in active exploitation, urging risk-based prioritization.

  • Microsoft's September 2026 Patch Tuesday is its largest ever: 974 total listed vulnerabilities; Malwarebytes specifies 964 customer-patchable CVEs (104 Critical, 860 Important), with the remaining being cloud-only fixes
  • CVE-2026-81963: link-following elevation-of-privilege flaw in the Windows Update Stack, actively exploited before disclosure, CVSS 7.8
  • CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) heap overflow enabling AppContainer sandbox escape, actively exploited before disclosure, CVSS 7.8
  • Both zero-days grant SYSTEM-level access after initial compromise; neither provides remote access alone
  • Per CyberScoop, 723 of the 974 flaws affect Windows, 111 affect Office, 62 affect SQL, and 22 affect developer tools
  • High-severity RCE fixes cover Windows DNS Server, Remote Desktop Services, Exchange Server, SharePoint, and SQL Server
  • CyberScoop reports researchers attribute the record patch volume to AI-assisted vulnerability discovery without a matching rise in active exploitation and urge risk-based prioritization
  • Reported dates: CyberScoop 2026-09-08, Malwarebytes 2026-09-09

Coverage timeline

  1. · 7d ago
    CyberScoop· 78
    Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

    Microsoft patches 974 flaws in record Patch Tuesday, including two actively exploited Windows zero-days enabling privilege escalation.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81963
+1 in the same advisory: …85880
Local Privilege Escalation via Link Following in Windows Update Stack

CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.

Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems.

7.8<1% KEV
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2025
masswell over 1,000,000