Microsoft Tackles Record 900+ Vulnerabilities in Largest Patch Tuesday Update
Microsoft has released its largest Patch Tuesday security update to date, addressing over 900 vulnerabilities across Windows and other products. The September 2026 release contains 105 Critical vulnerabilities, including dozens of weaknesses capable of enabling remote code execution.
The two actively exploited zero-days, tracked as CVE-2026-81963 and CVE-2026-85880, affect fundamental Windows components and could allow attackers who already have some access to a device to obtain SYSTEM-level privileges. SYSTEM is one of the most powerful security contexts in Windows and can give an attacker extensive control over the operating system.
The September update surpasses Microsoft's previous record-breaking Patch Tuesday releases in June, July, and August, highlighting how the rapid adoption of artificial intelligence-assisted vulnerability research is changing both software security and enterprise patch management. Organizations should not assume that exploitation has been limited to narrowly targeted operations, as the absence of details about threat actors and malware associated with campaigns suggests a broader impact.