Microsoft Ships Record September 2026 Patch Tuesday, Fixing 964 Flaws Including Two Exploited Zero-Days

Microsoft shipped its largest Patch Tuesday on record this week, fixing 964 vulnerabilities across its product line — more than double August’s release and a new monthly high for the company. The September 2026 update includes patches for two zero-day flaws already being exploited in the wild, along with 113 vulnerabilities rated Critical.

Two Exploited Zero-Days Among 964 Fixes

The two actively exploited flaws include CVE-2026-81963, an elevation-of-privilege vulnerability in the Windows Update Stack that stems from improper link resolution before file access, commonly known as link following. Security researchers note the bug is most relevant to post-compromise activity, letting an attacker who already has a foothold on a system escalate to greater control. Cybersecurity companies Volexity and Proofpoint were credited with reporting one of the exploited flaws, while a researcher at Airbus Helicopters and Microsoft’s own threat intelligence team were credited with the second. The U.S. Cybersecurity and Infrastructure Security Agency has added both to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22, 2026 to apply the fixes.

A Record Critical Count Across Windows Components

Among the 113 Critical-rated bugs, several affect core Windows security components, including CVE-2026-83939 in Windows Secure Kernel Mode and CVE-2026-83498 in Virtualization-Based Security enclave privileges. Microsoft also patched a string of remote-code-execution flaws carrying CVSS scores of 9.8, including issues in Skype for Business, the Windows Routing and Remote Access Service, the Windows HTTP Print Provider, Windows Shell and the Windows Imaging Component. None of the RCE flaws are confirmed to require no user interaction, but their severity ratings and broad footprint across widely deployed Windows components make rapid patch validation and deployment a priority for enterprise IT and security teams this month.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *