Microsoft Sets Record with 974 Vulnerabilities Fixed in One Patch Tuesday
Microsoft's September Patch Tuesday release has set a new record for vulnerabilities addressed in one update. The company fixed between 966 and 997 Common Vulnerabilities and Exposures (CVEs), depending on how external and Chromium bugs are counted, including two exploited zero-days and 20 wormable bugs.
The number of patched issues skyrocketed due to the increasing use of AI for code auditing in monthly counts. Despite this, researchers from ZDI note that there hasn't been a corresponding spike in active exploits, yet. However, 58 fixes are rated by Microsoft as more likely to be exploited, with two vulnerabilities already under attack allowing attackers to gain higher privileges.
One of these zero-days, CVE-2026-81963, resides in the Windows Update Stack and lets an attacker follow a malicious link and escalate privileges. The other, CVE-2026-85880, is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC) that lets a local attacker gain SYSTEM-level privileges.
The Exchange Server situation this month is pressing, with two critical vulnerabilities: one allowing unauthenticated attackers to send specially crafted Visio attachments and the other letting low-privileged authenticated attackers impersonate any user and hijack every mailbox. Microsoft also fixed 20 wormable bugs, including a critical DNS flaw with a CVSS score of 9.8.