Microsoft Shatters Record with 974 CVE Fixes in September Patch Tuesday
Microsoft's September Patch Tuesday update has set a new record for the highest number of CVE fixes, with 974 vulnerabilities addressed. This surpasses the previous record of 570 CVEs in July 2026.
The majority of the affected products are Windows and Office, with 723 and 111 vulnerabilities respectively.
This surge in CVEs is attributed to Microsoft's use of agentic AI tools to discover zero-day vulnerabilities, which it warned customers about in July. As a result, security teams must adopt a risk-based approach to vulnerability management to prioritize the most critical flaws.
Microsoft highlighted two actively exploited zero-day flaws: CVE-2026-85880 and CVE-2026-81963. The former is a heap-based buffer overflow in Windows ALPC that can elevate privileges locally, while the latter is an improper link resolution before file access in Windows Update Stack.