Software King of the World, Microsoft has unleashed its biggest Patch Tuesday yet, fixing 966 security flaws, including two zero-days already being exploited in attacks.
According to BleepingComputer the September 2026 security dump contains 105 vulnerabilities rated critical, leaving Windows administrators with rather more than the usual Tuesday evening entertainment.
Of those critical flaws, 81 allow remote code execution, 20 involve privilege elevation, two disclose information, and one bypasses a security feature. Across the full haul, Vole fixed 438 elevation-of-privilege vulnerabilities, 258 remote-code-execution bugs and 173 information-disclosure flaws.
Another 56 denial-of-service bugs, 19 security-feature bypasses and 16 spoofing vulnerabilities made it into the pile. The 966 figure covers vulnerabilities Microsoft released on Patch Tuesday. It does not include another 204 flaws fixed earlier in September.
Those earlier fixes affected products including Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Microsoft Fabric, Power Automate and the Chromium-based version of Edge.
September comfortably beats Microsoft’s patching excesses. The company fixed 570 security flaws in July and 400 in August.
The rising numbers come after Microsoft started using an AI-powered vulnerability discovery system to find more holes across its software. Two of this month’s fixes concern zero-days already being exploited.
CVE-2026-81963 is an elevation-of-privilege vulnerability in the Windows Update Stack that can allow an attacker to gain SYSTEM privileges.
Writing in its blog, Microsoft squeaked: “Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorised attacker to elevate privileges locally.
The flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft has not revealed how attackers have been exploiting it. The second exploited bug, CVE-2026-85880, affects Windows Advanced Local Procedure Call, or ALPC. It is another elevation-of-privilege vulnerability that can grant an attacker SYSTEM privileges.
“Heap-based buffer overflow in Windows ALPC allows an authorised attacker to elevate privileges locally,” Vole said.
Volexity and Proofpoint researchers Mark Kelly, David Galazin and Jeremy Hedges discovered the flaw.
Microsoft has not disclosed details attacks using the ALPC vulnerability.
The wider September patch collection reaches deeply into Windows and Microsoft’s application stack, with critical remote-code-execution bugs affecting Office, Windows Graphics Component, DirectWrite, Windows Imaging Component, Windows Media Player and Windows Message Queuing.
Microsoft released the fixes alongside Windows 11 cumulative updates KB5124008 and KB5122880, while Windows 10 users covered by extended security updates received KB5122878.
Tiny RTX 3060 stuffs 12GB into one slot
Microsoft patches a record 966 security holes
Google’s Finn end of the wedge
Qualcomm lands $60 billion Amazon AI chip deal
GEEKOM Air12 Mini PC (2026 Edition)
Pixel Watch 4 45mm A nice evolution
GEEKOM A5 Pro Mini PC is a great budget mini PC
Baseus 65W Charger 2 PRO affordably charges notebook and two more device
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
