securityaffairs.com 9 Sept 2026, 07:03 UTC

Microsoft Fixes Nearly 1,000 Flaws in Record Patch Tuesday Update

Microsoft Fixes Nearly 1,000 Flaws in Record Patch Tuesday Update
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT’S September 2026 Patch Tuesday set a record, with Microsoft fixed between 966 and 997 CVEs depending on counting method, and a further 204 vulnerabilities addressed earlier in September across Azure, Entra ID, Edge and other services. The publication notes that despite AI-assisted vulnerability discovery driving the large monthly tally, there has not yet been a corresponding spike in active exploits, though 58 of the fixes are rated as more likely to be exploited.

The update slate includes two zero-days under active exploitation and a large set of wormable flaws, underscoring the breadth of risk across endpoints and services.

Key items highlighted by the report include CVE-2026-85880, a heap buffer overflow in the Windows ALPC component that could let a local attacker obtain SYSTEM privileges, and CVE-2026-81963 in the Windows Update Stack, which could be exploited via a malicious link to escalate privileges.

In Exchange Server, CVE-2026-55007 is a remote code execution flaw exploitable through a specially crafted Visio attachment, while CVE-2026-69380 could allow a low-privileged authenticated attacker to impersonate any user and hijack mailboxes. CVE-2026-69525 in Remote Desktop Services is a use-after-free flaw allowing unauthenticated code execution in-network.

The release also fixes 20 wormable vulnerabilities across components such as DHCP Server, Active Directory, Windows DNS Server, SMB Client, and Netlogon (notably CVE-2026-69730, a DNS flaw rated 9.8). The guidance emphasises patching these critical surfaces promptly, alongside the extensive fixes across SharePoint, SQL Server, and Android Authenticator components.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline