Microsoft Patch Tuesday Updates Fix Record Number of Vulnerabilities in September 2026
Microsoft has released its September 2026 Patch Tuesday updates to address numerous vulnerabilities across various Windows and enterprise products.
The update fixes a total of 974 security flaws, with 114 being rated as critical. This includes high-severity bugs affecting Exchange Server, SharePoint, SQL Server, and Remote Desktop Services.
The most notable vulnerabilities addressed include an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), a privilege escalation vulnerability in the Windows Update Stack, and several remote code execution flaws in Exchange Server and SQL Server.
Microsoft has already fixed 2,760 vulnerabilities this year, which is more than double the number from 2025. The company advises organizations to perform thorough testing to confirm that updates do not compromise the stability of their production systems.