Microsoft's September Patch Tuesday Brings Record Number of CVEs
Microsoft's September Patch Tuesday has brought in the largest release of the year so far, with 963 CVEs requiring customer action. Among them, 106 are rated critical. Two vulnerabilities have already been exploited by attackers: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call.
The Readiness team recommends a Patch Now scheduling for Windows, Office, SQL Server, and developer tooling, while standard patch releases are advised for Exchange. Microsoft has published an infographic summarizing deployment risks by product family.
The update resolves three client issues that originated in August: the failure of Microsoft Teams and Outlook to launch on ARM devices, desktop backgrounds reverting to solid black, and mouse cursor customization resetting on non-English installations. However, a defect with Microsoft Defender Antivirus notifications has been left open.