Microsoft has released its September 2026 Patch Tuesday security updates, fixing a record 966 vulnerabilities across its products.

The update includes two zero-day flaws that are already being exploited in attacks.

Of the 966 vulnerabilities addressed this month, 105 are rated critical. These include 81 remote code execution flaws, 20 elevation of privilege vulnerabilities, two information disclosure bugs, and one security feature bypass vulnerability.

Overall, the fixes cover 438 elevation of privilege vulnerabilities, 258 remote code execution flaws, 173 information disclosure vulnerabilities, 56 denial-of-service bugs, 19 security feature bypass vulnerabilities, and 16 spoofing vulnerabilities.

The total only counts vulnerabilities released by Microsoft as part of the September Patch Tuesday updates. It does not include 204 additional flaws that Microsoft fixed earlier this month in products and services including Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Microsoft Edge, Microsoft Fabric, and Power Automate.

This month’s release is Microsoft’s largest Patch Tuesday security update to date. It is significantly larger than the 570 vulnerabilities fixed in July and the 400 addressed in August.

The increase comes after Microsoft began using an AI-powered vulnerability discovery system to identify security flaws across its software products.

The September update also fixes two actively exploited zero-day vulnerabilities. The first, tracked as CVE-2026-81963, is an elevation of privilege flaw in the Windows Update Stack. An authorized attacker could exploit improper link resolution before file access to gain SYSTEM privileges locally. Microsoft has not disclosed how the vulnerability was used in attacks.


Buy ExpressVPN with PayPal or Credit Card
READ
Microsoft Defender Mistakenly Blocks Legitimate Google Search Links

The second zero-day, CVE-2026-85880, affects Windows Advanced Local Procedure Call, or ALPC. The heap-based buffer overflow allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges. Microsoft also has not provided details about how the flaw was exploited. The vulnerability was discovered by Volexity and researchers Mark Kelly, David Galazin and Jeremy Hedges with Proofpoint.

Advertisement