Microsoft's September 2026 Patch Tuesday Fixes Nearly 1,000 Flaws, Including Two Zero-Days Under Active Attack
Microsoft's September 2026 Patch Tuesday has arrived as what appears to be the company's largest security update to date. Depending on the source, the count lands at either 964 or 966 total vulnerabilities addressed, a discrepancy likely tied to differences in counting methodology or timing of publication rather than any substantive disagreement. Either figure represents a sharp jump from July's 570 fixes and August's 400, and many observers note that the trend line has been climbing steadily over recent months.
Two Zero-Days Already Under Active Attack
Among the flaws patched this month are two zero-day vulnerabilities that were reportedly being exploited in the wild before fixes became available. CVE-2026-81963 affects the Windows Update Stack and is an elevation-of-privilege flaw carrying a CVSSv3 score of 7.8. CVE-2026-85880, also scoring 7.8, affects Windows Advanced Local Procedure Call (ALPC) and is notable as the first ALPC-related CVE addressed in a Patch Tuesday release since April 2023.
Microsoft has not disclosed detailed technical specifics on how either vulnerability was exploited in the wild, and a recurring concern among consumers and enterprises alike is the lack of clarity around attacker methods. Security teams are encouraged to treat both as high-priority patches given the confirmed active exploitation, even without full visibility into the exploitation chain.
Severity Breakdown and Vulnerability Categories
Of the total vulnerabilities patched, roughly 104 to 105 are rated Critical, with the remaining majority classified as Important. Elevation-of-privilege bugs make up the largest single category, accounting for approximately 44.7% of the total, followed by remote code execution vulnerabilities at around 26.8%. Some analysts suggest this distribution reflects where attackers are currently concentrating their efforts: gaining footholds through low-privilege access and then escalating, rather than relying solely on remote exploitation from the outset.
Notable Exchange Server Flaw: CVE-2026-69380
A separate vulnerability drawing particular attention from enterprise IT teams is CVE-2026-69380, affecting Microsoft Exchange Server. The flaw stems from a missing authorization check that could allow a low-privilege authenticated user to escalate their access. With a CVSSv3 score of 8.1, the bug is considered high severity, largely because it doesn't require an attacker to already hold elevated credentials, only a foothold as an authenticated user. Exchange vulnerabilities of this type have historically drawn fast attention from threat actors, making timely patching a priority for organizations running on-premises Exchange environments.
What's Driving the Surge: AI-Assisted Vulnerability Discovery
Microsoft has reportedly attributed part of this month's unusually high vulnerability count to an internal, AI-powered vulnerability discovery system. This claim originates from Microsoft itself and has not been independently verified by third-party researchers. If accurate, it could signal a structural shift in how vulnerabilities are surfaced and disclosed going forward, potentially making months with hundreds of fixes the new normal rather than an anomaly. Many observers note that this trend is worth watching closely in subsequent Patch Tuesday cycles to see whether the elevated volume persists.
Unconfirmed Side Effects and Broader Patch Landscape
Some reports have surfaced describing disruptions to Remote Desktop Services functionality on Windows Server following this month's updates. These reports remain unconfirmed by Microsoft at the time of writing, and readers should treat them as a possibility rather than an established fact until official acknowledgment or documentation appears. A recurring theme in the broader patch landscape this cycle is that Microsoft was not alone: Adobe, SonicWall, and Cisco each released their own critical or zero-day patches in the same general window, underscoring a busy period across the security ecosystem.
What IT Teams and Users Should Do Now
Given the confirmed active exploitation of the two Windows zero-days, prioritizing those patches is the most immediate action for IT teams. Organizations running Windows Server should consider testing updates in staging environments first, given the unconfirmed reports of Remote Desktop Services disruption. Exchange Server administrators should review their environments specifically for exposure related to CVE-2026-69380. As always, official channels such as the Microsoft Security Response Center and the National Vulnerability Database remain the authoritative sources for technical details, advisory updates, and confirmation of any side effects as they are validated.