MICROSOFT released fixes for 974 unique vulnerabilities in its September Patch Tuesday, a figure that would once have represented a full year’s worth of CVEs. Of these, two zero‑days are already under active exploitation, and 58 further flaws are considered more likely to be exploited. Microsoft also rated 13 flaws as Critical.
The Bulletin shows a heavy concentration of Windows‑based issues (723), with Office and Office 2016 at 111 each, and smaller counts across SQL (62), Developer Tools (22), SharePoint Server (16) and Azure (12). The piece notes this continues a trend of record‑breaking Patch Tuesday volumes, driven in part by AI‑assisted vulnerability discovery.
A notable pattern this month is the prevalence of elevation‑of‑privilege (EoP) bugs, about 45% of the total (roughly 438), with roughly a quarter (260) being remote code execution (RCE) flaws and around 18% (175) involving information disclosure. The two actively exploited flaws are CVE-2026-85880 (ALPC) and CVE-2026-81963 (Windows Update Stack), both enabling an attacker with initial access to achieve SYSTEM‑level privileges. A third high‑priority case cited is CVE-2026-69380 (Exchange Server EoP), which could allow impersonation of any user and mailbox hijack.
The report highlights a cluster of 20 wormable CVEs, including a near‑maximum‑severity RCE in Windows DNS Server (CVE-2026-69730, CVSS 9.8) that pose significant self‑propagation risk. Security teams are urged to prioritise actively exploitable flaws, especially in the Windows identity and infrastructure space, and to apply patches promptly to mitigate potential network contagion.