Microsoft Fixes Record-Breaking 966 Vulnerabilities on September 2026 Patch Tuesday
Microsoft released patches for 966 vulnerabilities on September 2026 Patch Tuesday, including two zero-day flaws that have been actively exploited.
The company addressed 105 'Critical' vulnerabilities, with 81 being remote code execution, 20 elevation of privileges, and 2 information disclosure. The other categories included security feature bypass and one 'Important' vulnerability each in .NET, Active Directory Certificate Services (AD CS), and Windows Active Directory Domain Services.
One of the zero-day vulnerabilities was discovered by Romain Deperne and the Microsoft Threat Intelligence Centre (MSTIC) in a flaw within the Windows Update Stack that allowed attackers to gain SYSTEM privileges. The other was found by Volexity, Mark Kelly, David Galazin, and Jeremy Hedges with Proofpoint in an elevation of privilege vulnerability in the Windows Advanced Local Procedure Call (ALPC).