MICROSOFT’S September 2026 Patch Tuesday set a record, with Microsoft fixed between 966 and 997 CVEs depending on counting method, and a further 204 vulnerabilities addressed earlier in September across Azure, Entra ID, Edge and other services. The publication notes that despite AI-assisted vulnerability discovery driving the large monthly tally, there has not yet been a corresponding spike in active exploits, though 58 of the fixes are rated as more likely to be exploited.
The update slate includes two zero-days under active exploitation and a large set of wormable flaws, underscoring the breadth of risk across endpoints and services.
Key items highlighted by the report include CVE-2026-85880, a heap buffer overflow in the Windows ALPC component that could let a local attacker obtain SYSTEM privileges, and CVE-2026-81963 in the Windows Update Stack, which could be exploited via a malicious link to escalate privileges.
In Exchange Server, CVE-2026-55007 is a remote code execution flaw exploitable through a specially crafted Visio attachment, while CVE-2026-69380 could allow a low-privileged authenticated attacker to impersonate any user and hijack mailboxes. CVE-2026-69525 in Remote Desktop Services is a use-after-free flaw allowing unauthenticated code execution in-network.
The release also fixes 20 wormable vulnerabilities across components such as DHCP Server, Active Directory, Windows DNS Server, SMB Client, and Netlogon (notably CVE-2026-69730, a DNS flaw rated 9.8). The guidance emphasises patching these critical surfaces promptly, alongside the extensive fixes across SharePoint, SQL Server, and Android Authenticator components.