Particle.news

Microsoft Issues Record Patch Tuesday With 974 CVEs and Two Zero‑Days

AI-driven discovery has swollen the update list, prompting faster risk-based patching and a CISA-mandated September 22 federal remediation deadline.

Overview

  • Microsoft published the September Patch Tuesday on Tuesday, Sept. 8, releasing fixes for 974 Microsoft CVEs, the largest single monthly bundle the company has issued.
  • Two flaws—CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC—are confirmed zero-days exploited in the wild and allow local privilege escalation.
  • CISA added those two zero-days to its Known Exploited Vulnerabilities list and set a remediation deadline of September 22 for federal civilian agencies.
  • The release addresses 723 Windows bugs and scores of high-severity issues, including roughly 20 wormable vulnerabilities and multiple remote code execution flaws that affect Exchange, DNS, RDS and other services.
  • Microsoft is urging rapid deployment with a three-day guidance, while vendors and researchers say AI-assisted discovery is increasing volume and forcing teams to use risk-based triage, tested update pipelines, and backups to manage the operational strain.