Microsoft Tackles Record-Breaking Patch Tuesday with Fixes for Two Zero-Day Flaws
Microsoft shipped its September 2026 Patch Tuesday on September 8, addressing a record-breaking 973 vulnerabilities, according to figures compiled by Cisco Talos and Cybersecurity News. The release is one of the largest single-month patch batches Microsoft has issued this year, with 113 critical-rated bugs, including remote code execution flaws that let an attacker run arbitrary code without user interaction.
The two zero-day vulnerabilities being actively exploited in the wild are elevation-of-privilege bugs, which require some existing foothold on a machine before they become useful. CVE-2026-81963 affects the Windows Update Stack and stems from improper link resolution before file access, while CVE-2026-85880 hits Windows Advanced Local Procedure Call.
The Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its Known Exploited Vulnerabilities catalog on September 8, signaling direct evidence of active exploitation. This triggers a binding remediation deadline for U.S. federal civilian agencies under Binding Operational Directive 22-01, although private-sector organizations are not legally bound by this deadline.