← All security news

Patch Tuesday Fixes 966 Flaws, 2 Zero-Days

A shield icon being patched with a wrench while a small crack glows amber under attack, next to a panel listing Microsoft's September 2026 Patch Tuesday: 966 flaws fixed, over 105 rated critical, and two zero-days already being exploited before the update shipped

Microsoft's September update rolled out fixes for 966 vulnerabilities — the largest single Patch Tuesday the company has ever shipped, ahead of July's 570 and August's 400. Independent counts vary slightly (The Hacker News puts the figure at 974, plus 25 non-Microsoft CVEs bundled into the same release; researchers at Tenable counted around 964) but the discrepancy is just different methods of counting bundled versus individually-listed flaws, not disagreement on the substance. More than 105 of the fixes are rated Critical, including 81 remote-code-execution bugs across Windows, Office, and core graphics and media components.

Two of the flaws were already being used in real attacks before the patch existed. CVE-2026-81963 is a privilege-escalation bug in the Windows Update Stack caused by improper link resolution, and CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC — both let an attacker who already has a foothold on a machine escalate to full SYSTEM privileges. Microsoft confirmed it detected exploitation attempts for both but has not disclosed who is behind them or how widely they were used. Separately, several of this month's Critical-rated RCE bugs — including a 9.8-severity flaw in Windows Shell and another in Windows DHCP Server — don't require any prior access at all, which is what makes the sheer size of this release matter as much as the two zero-days.

What this means for your business

Neither zero-day is a way in on its own — both need an attacker to already be on the machine, typically via a phishing email or a malicious download. That makes this a two-front problem: patch Windows promptly, and keep phishing defences (email filtering, staff awareness, least-privilege accounts) in good shape so attackers can't get the foothold these bugs then escalate from. Given the record scale of this release, don't assume a routine "Windows Update ran fine" is enough proof it applied cleanly — if you manage your own fleet, check that critical machines actually installed this month's update rather than silently failing partway through, and prioritise the Windows Update Stack, ALPC, and Windows Shell/DHCP Server fixes first if you have to stagger rollout across a larger office. If an IT provider handles your patching, ask them to confirm this specific month's update landed everywhere — a release this size is exactly when a few machines quietly fall behind.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Hacker News