MICROSOFT’S September Patch Tuesday set a new record, with fixes for 974 vulnerabilities across its software stack, including two flaws that were already being exploited in the wild. The breakdown cited by Microsoft shows 723 in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
More than 110 of the patched items carry a critical severity rating, and three classes of vulnerability—privilege escalation, remote code execution and information disclosure—account for almost 90% of the addressed issues. When combined with fixes for 25 non‑Microsoft CVEs, the total tracked vulnerabilities reach 999.
Two of the exploited flaws are CVE-2026-85880, a heap‑based buffer overflow in Windows ALPC that can let an authorised user escalate to SYSTEM privileges, and CVE-2026-81963, an improper link resolution in the Windows Update Stack that enables local privilege elevation. Microsoft’s advisory notes that an attacker could trigger CVE-85880 locally from a low‑privilege AppContainer sandbox without any user interaction.
Observers from Rapid7 and security firms credited for reporting the flaws include Volexity, Proofpoint, and MSTIC, with Tenable noting that CVE-2026-81963 is the first zero‑day in the wild tied to Windows Update, while 85880 is the second such weaponised case since 2023.
Authorities have begun tracking these vulnerabilities, with CISA adding both to its Known Exploited Vulnerabilities catalogue and mandating relevant Federal Civilian Executive Branch agencies apply the patches by 22 September 2026. The broader patch set has prompted calls for prioritisation and risk‑context awareness, as analysts emphasise that not all patched flaws pose equal risk to all organisations.