Patch Tuesday Fixes 973 Flaws, 2 Zero-Days Exploited [2026]

Microsoft shipped its September 2026 Patch Tuesday on September 8, closing out roughly 973 vulnerabilities in a single release, according to figures compiled by Cisco Talos and Cybersecurity News. Two of those flaws were already being used in live attacks before the patches landed, and the Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog the same day. For IT teams already stretched thin by a summer of zero-days at SonicWall, N-able, and Adobe Commerce, September’s release lands as one of the largest single-month patch batches Microsoft has issued this year.

The headline number itself is a moving target, and the range has only widened as more trackers have weighed in. Microsoft’s own release notes tally 974 vulnerabilities, a figure both The Hacker News and The Register echoed in their September 9 write-ups, with The Register additionally flagging the 2 actively exploited flaws. BleepingComputer counted 966, the Zero Day Initiative logged 972 new CVEs, and Tenable put the figure at 964. SANS ISC’s Internet Storm Center counted 973 on September 8, the same day Arctic Wolf tallied 974 Microsoft CVEs plus another 25 non-Microsoft CVEs, while Computerworld’s September 14 review put the total at 963. The discrepancy comes down to how each organization counts advisories that cover multiple products or get revised after initial publication. Most security teams are treating 973 as the working number, per Cisco Talos’s monthly breakdown and a separate tally from Cybersecurity News.

Google ยท Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What Shipped in the September 2026 Patch Tuesday

Talos reported that the September batch includes 113 vulnerabilities Microsoft marked as “critical,” a critical-severity count SANS ISC’s Internet Storm Center independently arrived at in its own September 8 tally, and that 82 of those critical-rated bugs are remote code execution flaws, the category security teams treat as highest priority because they let an attacker run arbitrary code without any user interaction. Other trackers landed on somewhat lower critical counts tied to their own overall totals: Tenable counted 104 critical bugs, BleepingComputer put the figure at 105, and Computerworld’s September 14 review counted 106. That is a notably heavy critical load compared to a typical Patch Tuesday, where critical-severity bugs usually make up a much smaller share of the total.

Coverage spans the traditional on-premises Windows stack rather than cloud-first services. Yahoo Tech’s rundown of the release describes it as focused on “the traditional on-premises stack,” pointing to bugs in Windows Secure Kernel Mode (CVE-2026-83939) and the Windows Virtualization-Based Security Enclave (CVE-2026-83498 and CVE-2026-83501). A Critical-rated Windows DNS Server remote code execution bug, CVE-2026-69730, also made the list, carrying a CVSS score of 9.8 out of 10, the near-maximum severity rating reserved for flaws that are both easy to exploit and catastrophic in impact.

No vulnerabilities in this batch were publicly disclosed ahead of the patch release, meaning attackers did not have advance warning through leaked proof-of-concept code or premature disclosure, a scenario that has complicated past Patch Tuesdays. The entire urgency of September’s release centers on two bugs that were already being exploited quietly, in the wild, before Microsoft or anyone else knew about them.

The Two Zero-Days Under Active Attack

Both actively exploited flaws are elevation-of-privilege bugs, not remote entry points, a characterization CyberScoop’s September 8 coverage of the two zero-days also confirmed. That distinction matters: an attacker needs some existing foothold on a machine, whether through phishing, a compromised credential, or another vulnerability, before either of these bugs becomes useful. Once they have that foothold, both flaws let them escalate to SYSTEM-level privileges, the highest access tier on a Windows machine.

CVE-2026-81963 affects the Windows Update Stack and stems from what Microsoft classifies as improper link resolution before file access, commonly called a “link following” flaw. Qualys flagged the bug the same day Microsoft published it, September 8, 2026, and Tenable’s advisory describes it plainly: “CVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege,” per Tenable’s September Patch Tuesday post. The bug lets an authorized local attacker manipulate how a privileged update component resolves a file-system link, tricking it into acting on the wrong file with elevated permissions.

CVE-2026-85880 hits Windows Advanced Local Procedure Call, or ALPC, a core inter-process communication mechanism baked into every supported version of Windows. Talos attributes the bug to a heap-based buffer overflow combined with use of an uninitialized resource, and both carry a CVSS base score of 7.8, rated “Important” rather than “Critical” under Microsoft’s own severity scale despite the active exploitation. That gap between severity label and real-world urgency is a recurring theme in vulnerability management: a 7.8 score sounds moderate, but a bug attackers are already using outranks a theoretical 9+ score sitting unexploited.

The Record’s coverage of the release frames the stakes directly, noting that the September update “deserves urgent attention less because of any single headline CVE total than because it fixes two Windows elevation-of-privilege vulnerabilities already exploited in the wild,” a framing echoed across multiple security outlets tracking the release, per The Record’s Patch Tuesday writeup.

CISA’s Same-Day KEV Listing

CISA added both CVE-2026-81963 and CVE-2026-85880 to its Known Exploited Vulnerabilities catalog on September 8, 2026, the same day Microsoft published the fixes and posted advisories through its Microsoft Security Response Center. KEV inclusion is not a routine bureaucratic step. It signals that the agency has direct evidence of active exploitation rather than a theoretical risk assessment, and it triggers a binding remediation deadline for U.S. federal civilian agencies under Binding Operational Directive 22-01. Private-sector organizations are not legally bound by that deadline, but security teams widely treat KEV entries as a de facto patch-immediately signal regardless of sector.

This is a pattern security teams have seen play out repeatedly through 2026. This site’s earlier coverage of an actively exploited Chrome V8 zero-day tracked a nearly identical sequence: quiet in-the-wild exploitation, an emergency vendor patch, then same-week KEV addition. The CISA KEV patch workflow that many enterprise teams have already built around 24-hour internal SLAs for KEV-listed bugs is about to get another real-world stress test.

How September Compares to August’s Patch Volume

August 2026’s Patch Tuesday closed out roughly 751 CVEs, meaning September’s release, at somewhere between 963 and 974 depending on the counting method, represents an increase of more than 200 vulnerabilities month over month, or roughly 28 to 30 percent, a jump CrowdStrike’s own September 17 review put even more starkly, counting 972 vulnerabilities and describing the total as more than double August’s count. BleepingComputer’s own headline called the release “record-breaking,” describing “966 flaws, including two actively exploited zero-day vulnerabilities.”

Whether September 2026 sets an all-time record for a single Patch Tuesday is harder to verify with precision, since public trackers do not agree on a single historical baseline and Microsoft’s advisory counting methodology has shifted over the years as the company consolidated more products under one release cycle. What is clear is that the trajectory across 2026 points upward, with each of the past two months landing well above what used to be considered a typical 100-to-150-CVE release just a few years earlier.

Key Vulnerabilities in the September 2026 Release

CVE IDAffected ComponentCVSS ScoreVulnerability TypeExploitation Status
CVE-2026-81963Windows Update Stack7.8 (Important)Elevation of privilege, link followingActively exploited, in CISA KEV
CVE-2026-85880Windows ALPC7.8 (Important)Elevation of privilege, heap overflowActively exploited, in CISA KEV
CVE-2026-69730Windows DNS Server9.8 (Critical)Remote code executionNot confirmed exploited
CVE-2026-83939Windows Secure Kernel ModeNot disclosed publiclyPrivilege escalationNot confirmed exploited
CVE-2026-83498Windows VBS EnclaveNot disclosed publiclySecurity feature bypassNot confirmed exploited
CVE-2026-83501Windows VBS EnclaveNot disclosed publiclySecurity feature bypassNot confirmed exploited

Why Windows Update Stack and ALPC Keep Coming Back

Neither of this month’s zero-days is a flashy remote exploit, and that is precisely the point. Advanced Local Procedure Call has existed in Windows since the NT kernel was first built, handling communication between low-privilege processes and privileged system services. Because it sits underneath almost every other Windows subsystem, a single well-placed heap overflow in ALPC has a blast radius that touches every supported Windows client and server release, not just one product line.

The Windows Update Stack tells a similar story from a different angle. It is one of the few Windows components that runs with elevated privileges essentially by design, since it needs system-level access to install patches in the first place. That makes any flaw in how it resolves file paths or validates the source of an update package unusually dangerous, because the entire threat model of the update mechanism assumes it can be trusted to run with maximum privilege. Attackers who understand that structural trust relationship have increasingly targeted update-adjacent components rather than trying to break through more heavily scrutinized network-facing services.

The Broader September 2026 Zero-Day Landscape

Microsoft’s two zero-days did not land in isolation. The same week produced a cluster of actively exploited or high-severity disclosures across other major vendors, underscoring how compressed the September 2026 vulnerability disclosure calendar has become. Google patched an actively exploited Chrome V8 engine flaw, CVE-2026-85046, rated CVSS 8.8, on September 4. Adobe Commerce and Magento merchants faced CVE-2026-75650, dubbed StyleSmuggler, an unauthenticated remote code execution bug carrying the maximum CVSS 10.0 score, with exploitation beginning around September 4 to 5. Managed service providers running N-able’s N-central platform had to respond to a critical pre-authentication remote code execution zero-day, tracked as CVE-2026-86218, disclosed September 7 alongside an emergency hotfix.

Vendor / ProductCVE IDCVSS ScoreStatusDate Disclosed
Microsoft Windows Update StackCVE-2026-819637.8Actively exploited, in CISA KEVSept. 8, 2026
Microsoft Windows ALPCCVE-2026-858807.8Actively exploited, in CISA KEVSept. 8, 2026
N-able N-centralCVE-2026-86218Critical (pre-auth RCE)Emergency hotfix issuedSept. 7, 2026
Adobe Commerce / MagentoCVE-2026-75650 (StyleSmuggler)10.0Actively exploited, unauthenticated RCESept. 4-5, 2026
Google Chrome (V8 engine)CVE-2026-850468.8Actively exploited before patchSept. 4, 2026
Koha library systemCVE-2026-197808.8Disclosed via ZDI, not confirmed exploitedSept. 8, 2026

Six significant vulnerability disclosures across five vendors inside a single week is a heavier load than IT and security operations teams typically plan for, and it illustrates a competitive reality that rarely gets discussed directly: patch prioritization is now a scarce resource that vendors are effectively competing for. A security team that spends Monday and Tuesday triaging the Adobe Commerce and N-able emergencies has less bandwidth left for a careful review of Microsoft’s 973-CVE Wednesday release, even when two of those CVEs are already being exploited.

Microsoft’s Patch Cadence Versus Its Peers

Microsoft’s monthly, scheduled Patch Tuesday cadence, running uninterrupted since it was introduced in October 2003, remains the industry’s most predictable disclosure rhythm, and that predictability is itself a double-edged asset. Enterprise IT teams can plan maintenance windows around a known date, but attackers can just as easily plan reconnaissance and exploit development around that same calendar, timing their own zero-day use to land right before or during the patch window to maximize the exploitation runway.

Google and Adobe, by contrast, patch on an as-needed basis for actively exploited bugs, pushing emergency updates like the Chrome V8 fix or the Magento StyleSmuggler patch outside any fixed schedule. That approach can close exploitation windows faster for single critical bugs, but it also means security teams juggling multiple vendors face a constant, unpredictable drip of urgent patches rather than one batched monthly event. N-able’s MSP-focused platform sits somewhere in between, issuing emergency hotfixes for critical RCE bugs as they surface, a pattern this site has tracked across multiple N-able zero-days disclosed within a six-week span earlier this year. Neither model has proven clearly superior at reducing real-world exploitation, and the September 2026 cluster of disclosures suggests both scheduled and emergency patching are running at capacity simultaneously.

Historical Context: How Patch Volumes Have Climbed

Patch Tuesday began in October 2003 as Microsoft’s attempt to consolidate what had been an unpredictable, near-daily stream of individual security bulletins into a single, plannable monthly release. In its early years, a typical Patch Tuesday addressed a handful of bulletins covering a dozen or so vulnerabilities. That number has grown by roughly two orders of magnitude over two decades, driven by an expanding product surface, the incorporation of open-source and third-party components into Windows and Azure, and steadily improving vulnerability research tooling on both the offensive and defensive sides.

September 2026’s roughly 973-CVE release, following August’s 751, continues a trend that has made 700-plus-CVE months a regular occurrence rather than an outlier. Security researchers attribute part of that growth to Microsoft’s own expanded bug bounty and internal fuzzing programs surfacing more issues before they reach production, alongside a genuine increase in the complexity of the codebase itself as Windows, Azure, and Microsoft 365 have become more deeply interconnected.

Enterprise and MSP Impact

For managed service providers already dealing with N-able’s N-central RCE zero-day, September’s Microsoft release compounds an already difficult week. Both incidents point at the same underlying weakness: privileged management infrastructure, whether it is an MSP’s remote monitoring platform or Windows’s own update mechanism, is an increasingly attractive target precisely because compromising it grants broad downstream access. An attacker who pops an ALPC-based elevation bug on one endpoint, or who compromises an N-central instance managing hundreds of client networks, gets outsized returns compared to attacking a single application vulnerability.

Enterprise patch management teams face a practical sequencing problem this month. With 973 total CVEs to review, 113 of them critical, and only two confirmed under active exploitation, the temptation is to spend days triaging the full list before deploying anything. Security teams that follow a KEV-first patching discipline, pushing fixes for actively exploited CVEs within 24 to 48 hours regardless of how much of the broader batch has been reviewed, are best positioned to close the exploitation window on CVE-2026-81963 and CVE-2026-85880 without waiting for a full regression-tested rollout of the entire September release.

What Comes Next: Predictions for the Rest of 2026

  • Monthly Patch Tuesday volumes are likely to stay above the 700-CVE mark through the remainder of 2026, given the trajectory from August’s 751 to September’s roughly 973, rather than reverting to earlier, smaller monthly batches.
  • Elevation-of-privilege bugs in core Windows plumbing components like ALPC and the Update Stack will keep appearing in KEV listings, since they offer attackers a reliable path from an initial low-privilege foothold to full system control without needing a separate remote entry vulnerability.
  • CISA’s same-day KEV additions, now a consistent pattern for Microsoft’s actively exploited bugs, will likely extend to more vendors’ emergency patches, including the kind of MSP-platform and e-commerce zero-days seen this month from N-able and Adobe Commerce.
  • Enterprises will increasingly adopt KEV-first, risk-based patch prioritization over full-batch patch-and-test cycles, since the gap between total CVE counts and actually-exploited CVE counts keeps widening month over month.
  • Expect continued clustering of major vendor disclosures within the same calendar week, since attackers appear to be probing multiple widely deployed platforms in parallel rather than focusing exclusively on any single vendor’s release cycle.

How to Prioritize Patching This Month

Security teams working through the September 2026 release should treat CVE-2026-81963 and CVE-2026-85880 as immediate, same-week priorities across every supported Windows client and server build, given confirmed active exploitation and CISA KEV inclusion. The Critical-rated Windows DNS Server bug, CVE-2026-69730, deserves the next tier of urgency for any organization running Windows DNS Server in a domain controller role, since a CVSS 9.8 remote code execution flaw in core network infrastructure represents catastrophic potential impact even without confirmed in-the-wild exploitation yet.

The remaining critical-rated RCE bugs, roughly 80 of them by Talos’s count, should follow standard risk-based triage: internet-facing and high-value servers first, followed by general endpoint deployment on a normal patch cycle. Organizations already running hardened infrastructure practices or a documented vulnerability management workflow will find this month’s volume manageable if they resist the urge to review all 973 advisories line by line before deploying the two that matter most today.

Frequently Asked Questions

How many vulnerabilities did Microsoft fix in the September 2026 Patch Tuesday?
Counts vary by tracker: Microsoft’s own release notes list 974, Cisco Talos and Cybersecurity News report 973, the Zero Day Initiative counted 972 new CVEs, BleepingComputer reported 966, and Tenable counted 964. Most security teams use 973 as the working figure.

What are the two actively exploited zero-days in September’s release?
CVE-2026-81963, a Windows Update Stack elevation-of-privilege flaw, and CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw. Both carry a CVSS score of 7.8 and were added to CISA’s Known Exploited Vulnerabilities catalog on September 8, 2026.

Do I need to worry about CVE-2026-81963 and CVE-2026-85880 if I have good endpoint protection?
Yes. Both are local elevation-of-privilege bugs, meaning an attacker needs an initial foothold, such as a phishing-delivered credential or another exploited vulnerability, before using them to reach SYSTEM-level privileges. Endpoint protection reduces the odds of that initial foothold but does not eliminate the risk once an attacker is already on a machine.

How does September 2026 compare to August 2026’s Patch Tuesday?
August 2026 closed with roughly 751 CVEs. September’s release, at 966 to 974 depending on the count, represents an increase of more than 200 vulnerabilities, or roughly 28 to 30 percent month over month.

Is the Windows DNS Server bug, CVE-2026-69730, being actively exploited?
As of the September 8 release, there is no confirmed active exploitation of CVE-2026-69730. It carries a CVSS score of 9.8 and is rated Critical because of its remote code execution potential, but it has not been added to CISA’s KEV catalog.

Were any of September’s vulnerabilities publicly disclosed before Microsoft patched them?
No. Security researchers tracking the release found no vulnerabilities in this batch that were publicly disclosed ahead of the patch. The two zero-days were being quietly exploited in the wild before discovery, rather than disclosed through a public proof-of-concept.

What is CISA’s Known Exploited Vulnerabilities catalog and why does it matter?
The KEV catalog is a running list maintained by the Cybersecurity and Infrastructure Security Agency of vulnerabilities with confirmed real-world exploitation. Listing triggers a binding remediation deadline for U.S. federal civilian agencies and is widely used by private-sector security teams as a signal to prioritize patching regardless of a bug’s raw CVSS score.

Should MSPs treat this month’s Microsoft release differently given the N-able N-central zero-day the same week?
Yes. MSPs managing both Windows endpoints and N-able’s N-central platform face compounding risk this week, since both a management platform and core Windows privilege-escalation paths are under active or near-active exploitation simultaneously. Prioritizing the N-central hotfix and the two Microsoft KEV entries ahead of the broader 973-CVE review is the more defensible sequencing.

Related Coverage

Elias Virtanen

Elias Virtanen

Cybersecurity Analyst

Elias Virtanen is the Cybersecurity Analyst at Tech Insider, bringing hands-on expertise from his background in penetration testing and security consulting. He previously worked as a security researcher at F-Secure in Helsinki, where he focused on threat intelligence and vulnerability disclosure. Elias covers ransomware trends, zero-trust architecture, and the evolving regulatory landscape including NIS2 and the EU Cyber Resilience Act. He holds a CISSP certification and an MSc in Information Security from Aalto University.

View all articles