Microsoft Fixes Record 964 Flaws in Massive Patch Tuesday Release
Microsoft's September Patch Tuesday has set a record for the largest release of security fixes in its history, with an astonishing 964 vulnerabilities addressed. This includes 104 rated Critical and 860 rated Important CVEs.
The update also patches two zero-day vulnerabilities that were actively exploited by attackers before a fix was available. These vulnerabilities allowed an attacker to gain SYSTEM privileges locally, which can be used to disable defenses, access protected data, or establish persistence on the system.
The first zero-day vulnerability is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a CVSS score of 7.8 out of 10, tracked as CVE-2026-81963. The second is a heap-based buffer overflow in Windows ALPC, also with a CVSS score of 7.8 out of 10 and tracked as CVE-2026-85880.