Skip to content
Patch Tuesday Sets Another Record With 974 CVEs

Patch Tuesday Sets Another Record With 974 CVEs

Darkreading Jai Vijayan September 8, 2026

Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.

Microsoft released fixes for 974 unique vulnerabilities in its scheduled security update for September, which until recently would have represented a full year’s worth of CVEs.

Of these, the highest-priority vulnerabilities include two that are already under active exploitation. Additionally, Microsoft rated 13 flaws as "Critical" and 58 it deemed as bugs that attackers are more likely to exploit for different reasons, including low attack complexity and high impact.

Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each. The remaining vulnerabilities were spread across other Microsoft technologies, including 62 in SQL, 22 in Developer Tools, 16 in SharePoint Server, and 12 in Azure. This month's release follows a recent trend of increasingly large and record-setting volumes of CVEs for the software giant's Patch Tuesday.

An Overabundance of Elevation of Privilege Flaws

As has been the pattern in recent months, a plurality of the bugs — 45%, or 438 — were elevation-of-privilege (EoP) vulnerabilities that can, in many cases, enable attackers to gain administrator- or system-level access to compromised systems. Another 25%, or 260, were remote code execution (RCE) flaws, while 18%, or 175, involved information disclosure.

Related: AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are CVE-2026-85880 (CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963 (CVSS 7.8), another EoP flaw this time in Windows Update Stack. Both vulnerabilities allow an attacker who already has gained access to a vulnerable system to achieve SYSTEM-level privileges.

Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, pointed to CVE-2026-69380 (CVSS:8.1), a Microsoft Exchange Server EoP, as another vulnerability that organizations should patch immediately, because it "allows low-privileged attackers to impersonate any user and hijack every mailbox in the organization."

A Cluster of Wormable CVEs

Also of high priority in Microsoft's September Patch Tuesday are a cluster of 20 wormable CVEs, Childs warned in an emailed statement. The bugs enable an unauthenticated remote attacker to execute arbitrary code on vulnerable systems. The "zero-click RCE bugs — headlined by a Windows DNS Server flaw ( CVE-2026-69730 CVSS:9.8) acting as SigRed’s spiritual successor — creates severe, self-propagating contagion risk across enterprise networks," he wrote.

Related: SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

SigRed ( CVE-2020-1350 ) was a maximum severity RCE flaw in DNS servers from 2020 that allowed an unauthenticated attacker to gain Local System/Domain Administrator-level control and potentially spread across a network without user interaction.

"Reaching nearly 1,000 monthly CVEs confirms that AI-assisted vulnerability discovery is the industry's new normal, completely outstripping human patching capacities," Childs noted. "Coupled with an extraordinary cluster of 20 wormable bugs, defenders face a higher risk of automated network contagion than they have in years."

Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set: CVE-2026-69829 , an RCE in Windows Shell; CVE-2026-69595 , an RCE in Windows Services for NFS ONCRPC XDR Driver; and CVE-2026-78510 , a Microsoft Word RCE. In emailed statement, Action1 researchers described the bugs as posing a high-risk because of their potential impact on confidentiality, integrity, and availability.

Amol Sarwate, head of security research and REDLab at Cohesity, advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane this month. Attackers could exploit these flaws by sending unauthenticated packets to DNS, DHCP, RDS, and Netlogon listeners on domain controllers and Microsoft Exchange, he said in a statement.

Related: Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

"On the endpoint front, security teams should prioritize the Office stack, as attackers can exploit a condition in the SMB client and create a malicious Word RTF or a malicious message in the Outlook Reading Pane that can lead to code execution," he cautioned. "A single or phishing mail can own the workstation without the user choosing to open anything."

Massive Updates are the New Normal — For Now

This is the fourth month in a row that Microsoft has released a substantially larger Patch Tuesday update than usual, reflecting the company's increasing use of AI to hunt for vulnerabilities across its technology portfolio. While the numbers might appear staggering in scale, they are not entirely unexpected and do not necessarily translate into a corresponding increase in risk for organizations, as numerous security experts have stressed in recent months. The key lies in prioritizing actively exploited bugs and the relatively smaller subset of critical flaws that attackers are more likely to exploit.

"One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low," noted Satnam Narang, senior staff research engineer at Tenable, in a statement. "AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles."

Security teams should focus on understanding the vulnerabilities that actually apply to their organizations, figure out if the flaws are reachable and exploitable in their specific environments, and prioritize based on risk context, Narang said.

It's also important to keep in mind that the massive surge in vulnerability discovery and disclosure is likely temporary, noted Tyler Reguly, associate director of security R&D at Fortra, in a statement. "We need to remember that these large CVE counts are a good thing, as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence," Reguly predicted.

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

Want more Dark Reading stories in your Google results?

The State of Cloud Security: The Latest Challenges

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Essential News & Insights from Black Hat USA 2025

Benchmark Scores Are a False Flag

Benchmark Scores Are a False Flag

Threat Exposure Analytics: Measuring and Communicating Security Risk

Threat Exposure Analytics: Measuring and Communicating Security Risk

Building an Effective Red Team: Beyond Penetration Testing

Building an Effective Red Team: Beyond Penetration Testing

How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach

How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach

Cloud Incident Response: Forensics in Distributed Environments

Cloud Incident Response: Forensics in Distributed Environments