azure.microsoft.com
Microsoft Patch Tuesday September 2026 Fixes Record 974 Vulnerabilities
Article Content
On September 8, 2026, Microsoft released its largest Patch Tuesday update, addressing 974 vulnerabilities, including two actively exploited zero-day flaws: CVE-2026-81963 and CVE-2026-85880. The vulnerabilities allow attackers to elevate privileges on Windows systems, potentially leading to full system control. Among the 113 critical vulnerabilities, many are remote code execution (RCE) flaws, posing significant risks to organizations. The update reflects a trend of increasing vulnerability disclosures, attributed to AI-assisted research. Security teams are urged to prioritize patching the critical vulnerabilities, especially those under active exploitation. This release surpasses previous records set in July and August of 2026, highlighting the growing challenge of managing software vulnerabilities. Organizations must quickly assess and apply the necessary patches to mitigate risks.
Key Points: • Microsoft patched a record 974 vulnerabilities, including two zero-days. • CVE-2026-81963 and CVE-2026-85880 are actively exploited elevation of privilege vulnerabilities. • 113 vulnerabilities were rated critical, with many allowing remote code execution.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.