Overview
- Microsoft published the September Patch Tuesday on Tuesday, Sept. 8, releasing fixes for 974 Microsoft CVEs, the largest single monthly bundle the company has issued.
- Two flaws—CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC—are confirmed zero-days exploited in the wild and allow local privilege escalation.
- CISA added those two zero-days to its Known Exploited Vulnerabilities list and set a remediation deadline of September 22 for federal civilian agencies.
- The release addresses 723 Windows bugs and scores of high-severity issues, including roughly 20 wormable vulnerabilities and multiple remote code execution flaws that affect Exchange, DNS, RDS and other services.
- Microsoft is urging rapid deployment with a three-day guidance, while vendors and researchers say AI-assisted discovery is increasing volume and forcing teams to use risk-based triage, tested update pipelines, and backups to manage the operational strain.