Particle.news

Microsoft Issues Record 974-Vulnerability September Patch

Rising AI-driven vulnerability discovery plus two confirmed actively exploited zero‑days are forcing Microsoft to push rapid deployment and change how organizations prioritize fixes.

Overview

  • Microsoft released its September 2026 Patch Tuesday updates on Tuesday, delivering cumulative Windows 11 packages (KB5124008 and KB5122880) that together fix 974 CVEs across the company’s products, including 723 in the Windows family.
  • The bundle includes two confirmed actively exploited privilege‑escalation zero‑days — CVE-2026-81963 in the Windows Update stack and CVE-2026-85880 in Advanced Local Procedure Call — that Microsoft says have been seen in real-world exploitation.
  • The Windows 11 cumulative updates also add nonsecurity changes that require testing, such as a movable taskbar, Start menu and Search updates, Administrator Protection, MXC process isolation for containers, and preview agentic-process tagging.
  • Microsoft updated deployment guidance to urge faster installation of quality updates, recommending most organizations deploy critical fixes within three days and use short grace periods for urgent deadlines.
  • Security teams warn the patch volume will strain testing and rollout capacity, and advise exploit-aware, risk‑based triage that focuses on reachable, likely‑exploitable flaws while investing in automated, tested deployment pipelines and backups to limit disruption.