Microsoft’s September Patch Tuesday Fixes Almost 1000 Vulnerabilities Across Windows, Office, and Azure

windows security2 windows security2

Microsoft’s September 2026 Patch Tuesday is one of the largest security releases in the company’s history, addressing 974 vulnerabilities across its own products. Two Windows privilege-escalation flaws were already being exploited, while the broader release has produced differing headline totals depending on which related CVEs are counted.

Key takeaways

Microsoft’s unusually large release creates an immediate prioritisation challenge for PC users, administrators and security teams. The most important points are:

  • 974 Microsoft product vulnerabilities were fixed, including 723 affecting Windows.
  • Two Windows flaws, CVE-2026-85880 and CVE-2026-81963, were exploited before patches became available.
  • Including 25 non-Microsoft CVEs, the overall tally reaches 999.
  • CISA added both exploited vulnerabilities to its Known Exploited Vulnerabilities catalog.
  • Several Microsoft products face major support-lifecycle changes in October.

A record-sized Microsoft release

Microsoft’s own-product total includes 723 Windows flaws, 111 Office and Office 2016 issues, 62 SQL Server vulnerabilities and 22 affecting Developer Tools. SharePoint Server, Azure, Skype for Business and Exchange Server were also included.

More than 110 vulnerabilities were rated critical, with privilege escalation, remote code execution and information disclosure accounting for nearly 90% of the fixes. The monthly total follows 457 vulnerabilities in August, 663 in July, 220 in June and 161 in May.

The conflicting figures stem from counting methods. Microsoft’s product advisories account for 974 vulnerabilities, while 25 additional non-Microsoft CVEs bring the broader release total to 999. One industry assessment also referenced a 964-CVE figure, illustrating why organisations should validate affected products rather than rely on a single headline number.

Two Windows zero-days require priority attention

CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call, or ALPC. A local attacker running code in a low-privilege AppContainer could escape the sandbox and obtain SYSTEM privileges without further user interaction. Windows Server 2025 and Windows 11 were not listed as receiving patches for this issue.

CVE-2026-81963 affects the Windows Update Stack. Improper link resolution can allow an authorised local attacker to overwrite a system component and escalate to SYSTEM privileges. All supported Windows versions receive a fix for this vulnerability.

Both flaws carry a CVSS score of 7.8, but that rating should not reduce their urgency. Attackers frequently combine an initial foothold with local privilege escalation instead of relying on a more complex remote-code-execution chain. CISA set September 22, 2026, as the remediation deadline for US federal civilian agencies.

Other vulnerabilities and browser visibility

Administrators should also review high-severity fixes in Exchange Server, SharePoint, SQL Server, Remote Desktop Services, DNS Server, DHCP Server and Windows Shell. Several carry CVSS scores of 9.8 and involve remote code execution or use-after-free vulnerabilities.

Rapid7 additionally highlighted a tracking concern involving CVE-2026-85046, an exploited V8 JavaScript flaw patched in Chrome and Edge. Although Edge reportedly received a fix before Chrome, Microsoft had not published a corresponding security advisory at the time of reporting. Organisations that depend solely on advisories could therefore miss browser exposure.

Support deadlines add pressure

October brings further changes for Microsoft customers. Windows 11 24H2 Home and Pro reach end of servicing, Windows Server 2022 enters extended support, and Windows Server 2012 and 2012 R2 leave their final paid Extended Security Updates period. Office 2021 and Exchange Server 2016 and 2019 are also scheduled to move out of support.

For PC enthusiasts and businesses maintaining older systems, the September release reinforces the need to inventory software, patch internet-facing services first and plan migrations before support ends.

Add a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *