Skip to content

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

Infosecurity-Magazine September 9, 2026

Microsoft has announced fixes for a record 974 CVEs in its September 2026 Patch Tuesday release.

The number of flaws included in this month’s update shatters the record for Patch Tuesday, which was 570 CVEs in July 2026.

The September CVE list spans Microsoft’s product portfolio, with Windows affected by most, at 723, followed by Office at 111.

The past three months have seen a substantial rise in the number of CVEs patched by the tech giant – 570 in July, 400 in August and 974 in September. Prior to that, 200 CVEs were included in June’s Patch Tuesday, 120 in May and 164 in April .

The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in the number of security updates they will need to apply to Windows products as a result of its use of agentic AI tools to discover zero-day vulnerabilities.

Given this new reality, it is more important than ever for security teams to deploy a risk-based approach to vulnerability management, ensuring they are prioritizing the flaws that pose the biggest risks to their business.

Responding to the latest Patch Tuesday announcement, Jack Bicer, director of vulnerability research at Action1, wrote : “At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”

Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows

Microsoft Warns of Two Actively Exploited Flaws

As part of its update on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.

The first of these is CVE-2026-85880 , assigned a high severity rating of 7.8. This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.

The other flaw, CVE-2026-81963 , is an improper link resolution before file access in Windows Update Stack, which allows an authorized attacker to elevate privileges locally.

The update contains 119 critical vulnerabilities. In Action1’s Bicer’s blog, he recommended that security teams prioritize the following flaws:

CVE-2026-62878 . A remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow, given a critical rating of 9.8

CVE-2026-62823 . A remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow, given a high severity rating of 8.8

CVE-2026-62893 . A remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition, given a critical rating of 9.8

CVE-2026-65789 . A remote code execution vulnerability in Windows DNS caused by a use-after-free condition, given a high severity rating of 8.1

CVE-2026-58231 . three Critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform

Image credit: tomeqs / Shutterstock.com

Microsoft Patches 570 CVEs in Record Patch Tuesday News 15 July 2026

Microsoft Patches 570 CVEs in Record Patch Tuesday

Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft News 13 June 2025

Microsoft 365 Copilot: New Zero-Click AI Vulnerability Allows Corporate Data Theft

Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities News 8 April 2026

Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities

Over 100 CVEs Addressed in First Patch Tuesday of 2023 News 11 January 2023

Over 100 CVEs Addressed in First Patch Tuesday of 2023

Microsoft Patches 120 CVEs Including Two Zero Days News 12 August 2020

Microsoft Patches 120 CVEs Including Two Zero Days

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

NCSC Warns Shadow AI Creates New Security Risks

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

Multiple Class Action Lawsuits Filed Against IDScan

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

NCSC Warns Shadow AI Creates New Security Risks

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

How to Manage Enterprise Cyber Resilience in the Age of AI

How to Harness Advanced Intelligence Capabilities to Strengthen Cyber Defence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust