Record September 2026 Patch Tuesday: 974 Fixes, Two Live Zero-Days, and an Overloaded Triage Pipeline
Microsoft has shipped the largest security release in its history. The September 2026 Patch Tuesday update, out on September 8, fixes 974 vulnerabilities across Windows, Office, Exchange Server, SQL Server and the company's developer tools, and two of those flaws were already under attack when the patches arrived. Microsoft's release notes carry the 974 figure, while independent counts of the same release land between 964 and 974 depending on whether Chromium, Edge and third-party CVEs are included.
The previous record came in July, when Microsoft patched about 570 flaws. August's release fixed roughly 400. September is more than double either month under every competing tally, and it pushes Microsoft's 2026 total past 2,600 CVEs, more than twice the company's earlier annual high of 1,245 from 2020.
Microsoft's servicing documentation confirms the September 2026 security baseline became available on September 8 and that the update shipped as a standard release rather than a hotpatch. Administrators who lean on hotpatching to avoid reboots do not get that option this cycle.
What Shipped in the September 2026 Patch Tuesday
The release notes spread the fixes across the product stack: 723 flaws in Windows components, 111 in Office and Office 2016, 62 in SQL Server and 22 in developer tools. Critical-severity totals vary by methodology, with published counts between 104 and 119. Around 20 entries cover wormable bugs, code that can spread between machines without user action, and the batch includes a critical remote code execution flaw in Exchange Server. High-severity fixes also touch SharePoint and Remote Desktop Services.
Neither exploited flaw was publicly disclosed before the update shipped, so administrators had no advance notice to stage workarounds. That is the normal condition for zero-days, and it is why the two entries below sit above the other 972 in priority.
| CVE | Component | Flaw type | Impact | Status |
|---|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Improper link resolution before file access (link following) | Local elevation of privilege | Exploited before patch; added to the Known Exploited Vulnerabilities catalog |
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) | Heap buffer overflow | Local attacker gains SYSTEM privileges | Exploited before patch; added to the Known Exploited Vulnerabilities catalog |
Both flaws are local, so an attacker needs an existing foothold on the machine before either one helps. The payoff in each case is SYSTEM-level control, which converts a low-privilege intrusion or a malicious process into a full compromise of the device. Local privilege escalation is the step that turns an initial foothold into damage across a whole network, which is why both entries rank above what their local scope suggests. The Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog on release day, which starts a federal remediation clock. No public detail has emerged on who is running the exploits or which targets were hit.
The Triage Problem Behind the Record
The number is the symptom. Discovery has outrun the capacity of ordinary users and IT teams to act on what it produces, and 974 items arrive in one maintenance window with the same reboot, testing and rollback costs attached to each. Treating every entry as urgent is not workable, so the practical job is a filter: two exploited bugs and about 20 wormable flaws at the top, the rest queued behind them.
The growth curve reflects how bugs are found now. Automated and AI-assisted code analysis produces far more candidates per release cycle than manual review did, and the same tooling lowers the cost of turning a candidate into a working exploit. Microsoft's monthly output has moved from roughly 570 in July to about 400 in August to 974 in September, and the year's total has already doubled the 2020 record with a full quarter still to run.
The spread in the headline figure is a maintenance problem of its own. A security team reporting coverage against a 966-fix baseline and one working from a 974-fix list will disagree about compliance even when both have deployed everything Microsoft shipped, which turns bookkeeping into a second triage exercise.
Small organisations carry the worst of this imbalance. A business without a dedicated security team reads the same list as a bank with a patch committee, and the entries that get deprioritised are the ones an attacker can keep using.
What It Means for Your Devices
Consumers on Windows 11 or a supported Windows 10 build receive the fixes through the normal update channel. Because both zero-days require local access, the exposure is highest on shared machines and on systems where untrusted software already runs. The case for installing early rests on those two bugs, the wormable set and the Exchange flaw, not on the record count.
For IT teams the hard part is sequencing. The Exchange remote code execution flaw and the wormable flaws belong in the first wave, with the remainder spread across later windows. A batch this size also stretches rollback planning, since a faulty update touches more surface area than usual, and it lands in the same month as quarterly compliance deadlines for many organisations.
Why this matters
Patch Tuesday has stopped being a chore a small team can clear in a weekend. The record 974-fix load, the two live zero-days and the roughly 20 wormable flaws show a discovery pipeline running faster than the people who have to consume its output, and that gap between finding bugs and fixing them is what attackers exploit. For anyone running Windows, the consequence is narrower than the headline: install this month's update promptly, and treat the two exploited flaws, the wormable set and the Exchange flaw as the items that cannot wait.
Sources
Microsoft fixes record 964 flaws, including 2 exploited zero- ...
Related Articles
- Microsoft Patch Tuesday Sets Record With 200 Security Fixes in June Update
- Chrome 153 Zero-Day Patch Bundles 230 Fixes in Google's First Two-Week Release
- Apple's iOS 26.5.2 Security Update Patches 29 Vulnerabilities as AI Threats Accelerate
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.