Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft released a record-breaking 974 security updates this month, including two zero-day vulnerabilities that have been actively exploited in the wild. These updates address a wide range of flaws across its Windows, Office, SQL Server, and Developer Tools products. While the sheer volume of patches is significant, current exploit activity remains relatively low, highlighting the importance of organizations prioritizing remediation based on actual risk and reachability.
Microsoft released a record-breaking 974 security updates this month, including two zero-day vulnerabilities that have been actively exploited in the wild. These updates address a wide range of flaws across its Windows, Office, SQL Server, and Developer Tools products. September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026.
CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges, and has been weaponized as a zero-day since CVE-2023-21674. CVE-2026-81963, an improper link resolution vulnerability in the Windows Update Stack, similarly allows privilege escalation and SYSTEM privilege gain locally.
Cybersecurity companies Volexity and Proofpoint were acknowledged for reporting CVE-2026-85880, while Romain Deperne, an offensive security researcher at Airbus Helicopters, and the Microsoft Threat Intelligence Center (MSTIC) were credited with the second bug. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
Despite the massive batch of patches, current exploit activity remains relatively low, suggesting that organizations should focus on identifying and addressing vulnerabilities that are actually reachable and exploitable. According to TrendAI's Zero Day Initiative (ZDI), Microsoft has patched a total of 2,760 security flaws this year alone, indicating how artificial intelligence (AI)-assisted vulnerability discoveries are unlikely to slow down any time soon. Satnam Narang, senior staff research engineer at Tenable, noted that this month's Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and pushes this year’s total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months to go. Tyler Reguly, associate director of Security R&D at Fortra, emphasized that this is not a Microsoft-specific problem, and that large vendors like Oracle are also proactively addressing vulnerabilities, highlighting the ongoing need to reduce the attack surface before attackers can exploit them.
