Microsoft's Record-Breaking September Patch Tuesday Tackles 974 Security Flaws
Microsoft's September Patch Tuesday update addressed an unprecedented 974 security flaws across its products. This record-breaking number far surpasses previous months, with July's update fixing roughly 570 flaws and August's tackling about 620.
Two of these vulnerabilities were already being exploited by attackers before the patches were released. Both zero-days allowed an attacker who had already gained access to a Windows machine to escalate their privileges. One flaw was located in the Windows Update Stack (CVE-2026-81963), while the other resided in the Advanced Local Procedure Call component (CVE-2026-85880).
Dustin Childs, of the Zero Day Initiative, reviewed this month's release and noted that it is unlikely attackers have hijacked the update mechanism itself. Instead, he suspects they are pairing the Update Stack bug with a code execution flaw to spread malware or ransomware.
The total number of vulnerabilities has been rising rapidly, with more than 110 rated as critical by Microsoft. Childs counted 972 new flaws, with the addition of fixes for Chromium bringing this number to 997. This represents a significant surge in the number of bugs being addressed each month, with Microsoft having fixed over 2,760 vulnerabilities so far this year.