Microsoft September 2026 Patch Tuesday Addresses 973 Vulnerabilities, Two Zero-Days Exploited

Microsoft September 2026 Patch Tuesday Addresses 973 Vulnerabilities, Two Zero-Days Exploited

First seen 8 Sep 2026, 20:13 UTC TenableComputerweeklyCisecurityDaily.DevBleepingcomputer+5 75.6

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Microsoft released its largest Patch Tuesday update, addressing a record 973 vulnerabilities, including 113 rated critical. Among these, two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, were actively exploited in the wild, allowing attackers to gain SYSTEM privileges. The vulnerabilities primarily affect various Microsoft products, including Windows, Exchange Server, and Microsoft Teams. The update includes critical patches for remote code execution and elevation of privilege vulnerabilities. Security professionals are urged to apply the updates immediately to mitigate potential risks. The vulnerabilities were added to the CISA KEV catalog on the same day as the patch release. No reports of exploitation were noted prior to the patch, but the potential impact is significant given the nature of the vulnerabilities. Microsoft has implemented an AI-powered system for vulnerability discovery, contributing to the increase in flaws addressed this month.

Key Points: • Microsoft patched a record 973 vulnerabilities, including 113 critical. • Two zero-day vulnerabilities exploited in the wild were addressed: CVE-2026-81963 and CVE-2026-85880. • Immediate patching is recommended to mitigate risks associated with these vulnerabilities.

Ask AI about this cluster

Timeline

2023-01-10
CVE-2023-21674 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
Microsoft Patch Tuesday release
Microsoft released patches for 973 vulnerabilities, marking the largest Patch Tuesday to date.
Cisecurity
2026-09-08
CVE-2026-81963 added to CISA KEV
The Windows Update Stack elevation of privilege vulnerability was added to the CISA KEV catalog due to active exploitation.
Bleepingcomputer
2026-09-08
CVE-2026-85880 added to CISA KEV
The Windows ALPC elevation of privilege vulnerability was also added to the CISA KEV catalog for active exploitation.
Bleepingcomputer
2026-09-08
CVE-2026-69525 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69730 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69380 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69676 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE