Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Microsoft has announced fixes for a record 974 CVEs in its September 2026 Patch Tuesday release.
The number of flaws included in this month’s update shatters the record for Patch Tuesday, which was 570 CVEs in July 2026.
The September CVE list spans Microsoft’s product portfolio, with Windows affected by most, at 723, followed by Office at 111.
The past three months have seen a substantial rise in the number of CVEs patched by the tech giant – 570 in July, 400 in August and 974 in September. Prior to that, 200 CVEs were included in June’s Patch Tuesday, 120 in May and 164 in April .
The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in the number of security updates they will need to apply to Windows products as a result of its use of agentic AI tools to discover zero-day vulnerabilities.
Given this new reality, it is more important than ever for security teams to deploy a risk-based approach to vulnerability management, ensuring they are prioritizing the flaws that pose the biggest risks to their business.
Responding to the latest Patch Tuesday announcement, Jack Bicer, director of vulnerability research at Action1, wrote : “At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its update on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
The first of these is CVE-2026-85880 , assigned a high severity rating of 7.8. This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.
The other flaw, CVE-2026-81963 , is an improper link resolution before file access in Windows Update Stack, which allows an authorized attacker to elevate privileges locally.
The update contains 119 critical vulnerabilities. In Action1’s Bicer’s blog, he recommended that security teams prioritize the following flaws:
CVE-2026-62878 . A remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow, given a critical rating of 9.8
CVE-2026-62823 . A remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow, given a high severity rating of 8.8
CVE-2026-62893 . A remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition, given a critical rating of 9.8
CVE-2026-65789 . A remote code execution vulnerability in Windows DNS caused by a use-after-free condition, given a high severity rating of 8.1
CVE-2026-58231 . three Critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform
Image credit: tomeqs / Shutterstock.com
Microsoft Patches 570 CVEs in Record Patch Tuesday News 15 July 2026
Microsoft Patches 570 CVEs in Record Patch Tuesday
Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft News 13 June 2025
Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft
Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities News 8 April 2026
Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities
Over 100 CVEs Addressed in First Patch Tuesday of 2023 News 11 January 2023
Over 100 CVEs Addressed in First Patch Tuesday of 2023
Microsoft Patches 120 CVEs Including Two Zero Days News 12 August 2020
Microsoft Patches 120 CVEs Including Two Zero Days
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
NCSC Warns Shadow AI Creates New Security Risks
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Multiple Class Action Lawsuits Filed Against IDScan
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
NCSC Warns Shadow AI Creates New Security Risks
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How to Manage Enterprise Cyber Resilience in the Age of AI
How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
