Microsoft Fixes Record 964 Flaws Including Two Exploited Zero-Days
Microsoft has released a record September 2026 security update covering 964 vulnerabilities, including two Windows zero-days that were already being exploited in attacks. The vulnerabilities allow local privilege escalation, meaning attackers who already have some level of access to a device can potentially use them to obtain SYSTEM privileges and gain much greater control over the machine.
Microsoft's full September security release contains 974 CVEs, but 10 relate to cloud services or fixes applied directly by Microsoft. For customers, the patch covers 964 vulnerabilities, including 104 rated Critical and 860 rated Important. The scale makes it Microsoft's largest Patch Tuesday release on record.
Two Windows Zero-Days Were Already Exploited
The most urgent fixes address CVE-2026-81963 and CVE-2026-85880, both of which Microsoft says were exploited before the September security updates became available. Both carry a CVSS score of 7.8 and are classified as elevation-of-privilege vulnerabilities.
CVE-2026-81963 affects the Windows Update Stack and involves improper link resolution before file access. CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC) and involves a heap-based buffer overflow. The ALPC flaw can allow an attacker running code inside a low-privilege AppContainer to escape the sandbox and elevate privileges without additional user interaction.
Why Local Privilege Escalation Matters
Neither vulnerability provides remote access by itself. An attacker generally needs an initial foothold on the affected computer before exploiting the flaws. That foothold could come from malware, compromised credentials, phishing or another attack technique.
Once an attacker obtains SYSTEM privileges, however, the situation becomes considerably more serious. SYSTEM is one of the highest levels of access available in Windows, allowing an intruder to interfere with security controls, access protected information, establish persistence and potentially use the compromised machine as a starting point for further attacks.
Patch Covers Windows, Office and Server Products
Beyond the two exploited zero-days, Microsoft's September release addresses vulnerabilities across a broad range of products. Security fixes cover Windows, Office, Exchange Server, SharePoint Server, SQL Server, Azure, Developer Tools and Skype for Business, among other Microsoft technologies.
The release includes high-severity remote-code-execution vulnerabilities affecting components such as Windows DNS Server and Remote Desktop Services. Security researchers also identified a large number of elevation-of-privilege and remote-code-execution flaws within the wider update, increasing the importance of prioritizing patches rather than treating the release as a routine monthly update.
Microsoft's Largest Patch Tuesday Yet
The September release is significantly larger than several recent Patch Tuesday updates. Microsoft addressed 570 vulnerabilities in July and another 400 in August, according to BleepingComputer, before the September release surpassed those figures by a wide margin.
The unusually large volume also comes as Microsoft expands its use of automated and AI-assisted security processes to identify vulnerabilities across its software ecosystem. At the same time, Microsoft has introduced broader machine-readable Vulnerability Exploitability eXchange (VEX) statements for its assigned CVEs, giving security teams more structured information for assessing exposure and prioritizing remediation.
Organisations Urged to Prioritize the Zero-Days
The sheer number of vulnerabilities in the September release means organisations may need to prioritize rather than deploy every fix simultaneously. The two actively exploited Windows flaws should sit near the top of that list because exploitation has already been reported.
NHS England's National Cyber Security Operations Centre has also warned that future exploitation of both vulnerabilities is highly likely and urged affected organisations to apply Microsoft's September updates as soon as possible.
For enterprises, the bigger concern is how these vulnerabilities could fit into existing attack chains. A local privilege-escalation flaw may appear less dangerous than a remote-code-execution bug because it requires an initial foothold, but attackers can use it after compromising a device to move from limited access to much broader control.
Microsoft's September release therefore stands out for two reasons: its unprecedented scale and the fact that two of the vulnerabilities being fixed have already been used in attacks. Organisations running affected Microsoft products should prioritize the two exploited zero-days while working through the remaining security updates according to their risk and patching policies.
