Microsoft Patches Record-Breaking 966 Vulnerabilities, Two Zero-Days Confirmed Exploited
Microsoft released its September Patch Tuesday updates on September 8, 2026, which fixed a total of 966 security vulnerabilities. Among these, 105 were classified as critical, and two Windows zero-days had already been actively exploited in attacks before the patches were released.
The two actively exploited vulnerabilities are CVE-2026-81963, found in the Windows Update Stack, and CVE-2026-85880, which affects Windows Advanced Local Procedure Call (ALPC). Both allow an authorized local attacker to elevate their privileges to SYSTEM, one of the highest privilege contexts in Windows.
Microsoft has not yet disclosed any information about the campaigns or targets that used these vulnerabilities. However, it is recommended that supported Windows systems receive the September updates promptly, particularly because the two actively exploited privilege escalations may already have been part of real-world attack chains.