Startups

Microsoft Patch Tuesday September 2026 Fixes 974 CVEs

's rollout has broken previous records, with the company addressing 974 across its product lineup in a single release. Two of these vulnerabilities were already being exploited in the wild before fixes became available, prompting quick action from federal cybersecurity authorities. 

The sheer volume of this month's Patch Tuesday September 2026 release dwarfs recent months. Windows accounted for 723 of the fixed flaws, while the Office suite received patches for 222 issues, 111 of which affected Office 2016 specifically.  

Scale of Patch Tuesday September 2026 

SQL Server products saw 62 CVEs resolved, Developer Tools had 22, SharePoint Server received 16 fixes, Azure had 12, Skype for Business had 10, and Exchange Server accounted for 9. More than 110 of the vulnerabilities patched carry a critical severity rating, and nearly 90% of the total fall into three categories: privilege escalation, remote code execution, and information disclosure.  

Factoring in fixes for 25 non-Microsoft CVEs, the combined total for this Patch Tuesday September 2026 cycle reaches 999 resolved vulnerabilities. 

This release continues a pattern of escalating patch volumes from Microsoft in recent months — 457 CVEs were addressed in August, 663 in July, 220 in June, and 161 in May, making September's numbers a significant jump even against that backdrop. 

The Two Exploited Zero-Days 

Central to this month's Patch Tuesday September 2026 update are two CVEs that Microsoft confirmed had been exploited before patches were issued. 

The first, CVE-2026-85880 (CVSS 7.8), is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component. It allows an attacker with local access to escalate privileges and obtain SYSTEM-level control. Microsoft's advisory states that an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system, with no additional user interaction required. 

The second actively exploited flaw, CVE-2026-81963 (CVSS 7.8), stems from improper link resolution within the Windows Update Stack. Like the ALPC bug, it enables a local, authorized attacker to escalate privileges and gain SYSTEM access. 

Both CVEs have since been added to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Federal Civilian Executive Branch agencies now face a September 22, 2026 deadline to apply the relevant patches. 

Other Notable CVEs Worth Tracking 

Beyond the zero-days, several other CVEs patched in this Patch Tuesday September 2026 batch carry high severity scores and warrant prompt attention from Microsoft administrators: 

  • CVE-2026-55007 (CVSS 8.1) — a double-free flaw in Microsoft Exchange Server enabling remote code execution 
  • CVE-2026-80097 (CVSS 8.6) — improper authentication in Microsoft Authenticator allowing local privilege escalation 
  • CVE-2026-69465 (CVSS 8.8) — missing authorization in Microsoft Office SharePoint permitting remote code execution 
  • CVE-2026-65669 (CVSS 9.6) — an injection flaw in SQL Server enabling remote privilege escalation 
  • CVE-2026-69525 (CVSS 9.8) — use-after-free in Windows Remote Desktop Services allowing remote code execution 
  • CVE-2026-69595 (CVSS 9.8) — use-after-free in the Windows Services for NFS ONCRPC XDR Driver 
  • CVE-2026-69730 (CVSS 9.8) — use-after-free in the Windows DNS server 
  • CVE-2026-69829 (CVSS 9.8) — heap-based buffer overflow in Windows Shell 
  • CVE-2026-72979 (CVSS 9.8) — use-after-free in the Windows DHCP Server 

Alongside the CVE fixes, Microsoft's Patch Tuesday September 2026 release also included new Servicing Stack Updates (SSUs), classified as critical, covering Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016. 

Given the number of critical-severity CVEs and the confirmed exploitation of two privilege-escalation bugs, security teams are expected to prioritize this Patch Tuesday September 2026 rollout above routine monthly cycles, particularly for internet-facing Windows and Exchange deployments. 

Source

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button