Cybersecurity

Microsoft Patches 966 Security Flaws and 2 Exploited Windows Zero-Days — Update Now

By Nino Ray Yeh · September 8, 2026 · 7:53 pm AEST · 3 min read
Windows 11 computer representing Microsoft's September 2026 security update and Patch Tuesday fixes

Microsoft has released its September 2026 security updates, addressing a record 966 vulnerabilities including two Windows zero-days that were already being exploited in attacks. For Windows users and IT teams, this is a Patch Tuesday worth treating as a priority.

What happened

The September 2026 Patch Tuesday fixes 966 security flaws across Microsoft products, according to BleepingComputer’s count of vulnerabilities released by Microsoft on Patch Tuesday itself. The release includes 105 vulnerabilities rated Critical, with 81 involving remote code execution.

The two actively exploited Windows zero-days are CVE-2026-81963 and CVE-2026-85880. Both are elevation-of-privilege vulnerabilities that can allow an attacker who already has local access to gain SYSTEM-level privileges.

The two exploited Windows zero-days

CVE-2026-81963 affects the Windows Update Stack. Microsoft says improper link resolution before file access can allow an authorized local attacker to elevate privileges. The vulnerability was credited to Romain Deperne and the Microsoft Threat Intelligence Centre.

CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC. Microsoft describes it as a heap-based buffer overflow that can allow an authorized local attacker to elevate privileges. Researchers from Volexity and Proofpoint were credited with discovering the flaw.

Microsoft has not publicly detailed how either vulnerability has been used in attacks, making prompt patching the safer option for affected systems.

Why this Patch Tuesday matters

The sheer size of this release makes it unusual. The 966 vulnerabilities make September Microsoft’s largest Patch Tuesday security release to date, following already large updates earlier in 2026.

The numbers also illustrate how quickly vulnerability discovery is changing. AI-assisted security research is helping uncover weaknesses at greater scale, contributing to a faster pace of vulnerability identification and remediation.

For organizations, more vulnerabilities being discovered also increases the workload involved in testing and deploying security updates. Actively exploited vulnerabilities should generally receive the highest priority.

What Windows users should do now

For most home users, the simplest action is to open Settings > Windows Update, check for updates and install the latest security update offered for the device. Microsoft says security updates distributed through Windows Update are generally downloaded and installed automatically, but users should still verify their device has successfully updated.

Windows 11 versions 25H2 and 24H2 are receiving September cumulative update KB5124008, while Windows 11 23H2 is receiving KB5122880. Supported Windows 10 systems and devices enrolled in applicable Extended Security Updates also have September security releases available.

Business and enterprise administrators should consult Microsoft’s Security Update Guide to identify affected products and prioritize deployments according to exploit status, severity and organizational exposure.

What it means for readers

The important number is not simply 966. The bigger concern is that two vulnerabilities were already being exploited before Microsoft’s fixes arrived.

That makes delaying this month’s Windows security updates harder to justify. Keeping Windows updated remains one of the simplest ways to close vulnerabilities that attackers are known to be targeting.

Sources

Microsoft Security Response Center – Security Update Guide

Microsoft – Windows September 2026 client images

BleepingComputer – September 2026 Patch Tuesday

Share this story

More From The Tech Boom

View all

Share with