www.securityweek.com 8 Sept 2026, 19:20 UTC

Microsoft Fixes 974 Flaws in Record Patch Tuesday Update

Microsoft Fixes 974 Flaws in Record Patch Tuesday Update

MICROSOFT has issued a record September Patch Tuesday, fixing 974 CVEs across its product range, including two zero-days that have seen exploitation in the wild. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow in the Windows ALPC component that could allow a local attacker to escape the sandbox and elevate privileges from a low-privilege AppContainer, with no user interaction required.

Microsoft notes that this is the first ALPC flaw exploited since April 2023, and that CVE-2026-85880 marks the second zero-day in ALPC in around four years (the previous being CVE-2023-21674).

The second zero-day, CVE-2026-81963, concerns an improper link resolution before file access (link following) in Windows Update Stack, similarly enabling local privilege escalation to System. Security researchers highlighted that this Update Stack weakness is the first zero-day among seven flaws resolved in that component over recent years.

In total, Microsoft released patches for 723 Windows flaws and 222 Office security issues, with notable updates across SQL, Developer Tools, SharePoint Server, Azure, Skype for Business, and Exchange Server. Some advisories identify wormable risk, with 20 newly fixed vulnerabilities capable of RCE without authentication or user interaction.

Industry commentary emphasised prioritisation: while vulnerability counts are rising, the number actually affecting most organisations remains relatively low, and effective risk-context prioritisation will be essential. The patches include Servicing Stack Updates for older Windows versions, underscoring the breadth of the update effort.

CVEs to watch include RCE in Exchange (CVE-2026-55007), EoP in Authenticator (CVE-2026-80097), RCE in SharePoint (CVE-2026-69465), EoP in SQL Server (CVE-2026-65669), and RCE in Remote Desktop Services (CVE-2026-69525).

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline