Microsoft Unleashes Record-Breaking 964 Patch Tuesday Fixes Amid Growing Concerns Over Wormable Bugs
Microsoft released almost 1,000 fixes in its September Patch Tuesday release to address nearly 1,000 vulnerabilities in Windows. Among them are two zero-day holes that could lead to local privilege escalation and wormable bugs.
The patches include fixes for 964 vulnerabilities, with 174 third-party/open-source CVEs and 23 Chromium/Edge CVEs excluded from the count. Two critical vulnerabilities stand out: CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, and CVE-2026-81963, an escalation of privilege stemming from an improper link resolution before file access in Windows Update Stack.
Chris Goettl, Ivanti's vice-president of product management, said that CVE-2026-85880 affects the entire Windows fleet. Dustin Childs, head of threat awareness at the Zero Day Initiative, noted that AI-assisted bug discovery has exploded patch counts into a whole new galaxy, and defenders must adapt to this reality.
Researchers warn that about 20 of the vulnerabilities could be wormable bugs. They also point out that successful exploitation of these vulnerabilities could lead to high-impact consequences for confidentiality, integrity, and availability.