Daily.Dev
Microsoft September 2026 Patch Tuesday Addresses 973 Vulnerabilities, Two Zero-Days Exploited
Article Content
On September 8, 2026, Microsoft released its largest Patch Tuesday update, addressing a record 973 vulnerabilities, including 113 rated critical. Among these, two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, were actively exploited in the wild, allowing attackers to gain SYSTEM privileges. The vulnerabilities primarily affect various Microsoft products, including Windows, Exchange Server, and Microsoft Teams. The update includes critical patches for remote code execution and elevation of privilege vulnerabilities. Security professionals are urged to apply the updates immediately to mitigate potential risks. The vulnerabilities were added to the CISA KEV catalog on the same day as the patch release. No reports of exploitation were noted prior to the patch, but the potential impact is significant given the nature of the vulnerabilities. Microsoft has implemented an AI-powered system for vulnerability discovery, contributing to the increase in flaws addressed this month.
Key Points: • Microsoft patched a record 973 vulnerabilities, including 113 critical. • Two zero-day vulnerabilities exploited in the wild were addressed: CVE-2026-81963 and CVE-2026-85880. • Immediate patching is recommended to mitigate risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.