Skip to content
Patch Tuesday: Microsoft updates address almost 1,000 flaws

Patch Tuesday: Microsoft updates address almost 1,000 flaws

Computerweekly September 8, 2026

As record numbers of software vulnerabilities continue to surface, Microsoft has once again smashed its record to smithereens, issuing just short of 1,000 bug fixes in its September 2026 Patch Tuesday update.

With over 100 critical flaws to address, the capacity of human security teams to keep up with the new normal of AI-assisted vulnerability discovery is now falling rapidly away, leaving organisations around the world painfully exposed.

“Looking at nearly 1,000 vulnerabilities in a single month, all I can think is: 'My God, it’s full of stars.' AI-assisted bug discovery has exploded patch counts into a whole new galaxy, and defenders simply have to embrace the suck,” Dustin Childs, head of threat awareness at the Zero Day Initiative (ZDI), told Computer Weekly via email.

Jack Bicer, director of vulnerability research at patch management firm Action1 , added: “At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”

Childs, whose monthly Patch Tuesday blog update has become essential reading for cyber pros, noted one small mercy in that – while Redmond has published more CVEs this year so far than it did in 2024 and 2025 put together – there does not appear to have been a corresponding surge in active exploitation activity.

Nevertheless, two elevation of privilege (EoP) flaws, CVE-2026-81963 in Windows Update Stack and CVE-2026-69380 in Microsoft Exchange Server, should be prioritised, he said.

The Action1 team also flagged CVE-2026-85880 , another EoP arising from a heap-based buffer overflow issue in Windows Advanced Local Procedure Call (ALPC) that is being actively exploited in the wild.

But of more concern this month, said ZDI’s Childs, is a 20-strong cluster of wormable flaws.

“We haven’t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed , that reality could change fast,” he said.

The DNS Server flaw – CVE-2026-69730 – allows an unauthenticated attacker to execute code over the network and could present a severe risk across wider enterprise networks, explained Childs.

Historically, wormable flaws such as SigRed, which was unearthed in the summer of 2020, have proved particularly dangerous because they don’t require user interaction, spread automatically, and since they target core network infrastructure – like DNS Server – can cause serious system crashes, topple networks by overloading them, and serve as a vector for malicious payloads such as ransomware.

Changing times, new approaches

With record breaking updates effectively rendering the whole concept of a monthly maintenance window obsolete, security teams must adopt new approaches to vulnerability management, said Nick Carroll of Nightwing’s ShadowScout team.

He outlined four practical steps that defenders can take right now:

Shrink your exposed perimeter by pulling admin interfaces, legacy appliances and unpatched on-prem Exchange servers off the public internet and hiding them behind authenticated access;

Start to automate automated, phased rollout rings for operating systems and endpoints to deploy large volume releases without needing to manually test each patch;

Focus resources on vulnerabilities that are confirmed exploited instead of wasting time remediating every low-context alert at once;

If an e-commerce, payment, or ERP platform is exposed to an edge vulnerability, don’t just patch it, rotate credentials, tokens, and downstream integration keys too.

“Patch management is no longer a checklist item for the IT department; it is an active operational defence discipline that requires continuous, intelligence-led exposure management,” said Carroll.

August 2026: Microsoft's Patch Tuesday deluge continues with August updates (Dark Reading).

July 2026: Another mammoth Patch Tuesday update, likely topping 600 flaws in total, sends defenders into the weeds .

June 2026: Microsoft has obliterated the record for the largest ever Patch Tuesday drop, with its June 2026 update addressing approximately 200 flaws and three zero-days .

May 2026: No zero-day flaws were addressed in May’s Patch Tuesday update but as usual there is much for admins to chew over in the coming days .

April 2026: Microsoft’s latest Patch Tuesday update may be one of the largest in history, with more than 160 issues in scope .

March 2026: Zero-days in .NET and SQL Server, and a handful of critical RCE bugs, form the nucleus of Microsoft’s March Patch Tuesday update .

February 2026: Microsoft releases patches for six zero-day flaws in its latest monthly update, many of them related to security feature bypass issues .

January 2026: January brings a larger-than-of-late Patch Tuesday update out of Redmond, but an uptick in disclosures is often expected at this time of year .

December 2025: The final Patch Tuesday update of the year brings 56 new CVEs, bringing the year-end total to more than 1,100 .

November 2025: An elevation of privilege vulnerability in Windows Kernel tops the list of issues to address in the latest monthly Patch Tuesday update .

October 2025: Windows 10 is no longer supported, but that does not mean it is not impacted by the latest Patch Tuesday update .

September 2025: Nearly half the CVEs Microsoft disclosed in its September security update, including one publicly known bug, enable escalation of privileges (Dark Reading).

Chaotic July Patch Tuesday threatens to overwhelm defenders By: Alex Scroxton

US cyber agency warns over forgotten SharePoint flaw By: Alex Scroxton

Microsoft smashes record for biggest ever Patch Tuesday update By: Alex Scroxton

Microsoft hits out over irresponsible vulnerability disclosure By: Alex Scroxton