Patch Tuesday used to feel like a chore. This month it feels like a natural disaster with a changelog. Microsoft just shipped the largest single batch of security fixes in its history, and two of them were already being exploited before the ink dried.
964 Fixes, Two Active Zero-Days
Microsoft's September 2026 Patch Tuesday addressed 964 CVEs — a record for the company — split into 104 rated Critical and 860 rated Important. Nearly half were elevation-of-privilege flaws, with remote code execution issues making up another sizable chunk of the pile.
Two vulnerabilities were confirmed under active attack: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, both letting a local attacker escalate to full SYSTEM privileges. Also in the mix is CVE-2026-69730, a critical 9.8-severity remote code execution bug in Windows DNS Server that Microsoft itself flags as "Exploitation More Likely" — the kind of wormable flaw that tends to keep security teams up past midnight.
The Number Itself Is the Warning
A record-setting 964-CVE month doesn't happen because Microsoft got sloppier overnight — it happens because the attack surface of modern Windows, Office, and cloud services keeps expanding faster than anyone can audit it. Every new feature, integration, and AI-assisted tool is also a new place for a bug to hide.
The detail most headlines skip past: a DNS Server RCE with a near-max severity score isn't a "patch when convenient" item. DNS sits underneath everything, and a flaw like that is the kind of thing ransomware crews build entire campaigns around once proof-of-concept code leaks.
If your patch management process still involves someone remembering to check Windows Update, this is the month that punishes procrastination.
Keeping up with a flood of CVEs like this is exactly why "we'll get to it eventually" isn't a security strategy — our free guide walks through building a real patching and supply-chain defense process: grab the checklist here.
Source: Tenable