Microsoft has released its September 2026 security updates, addressing a record 966 vulnerabilities including two Windows zero-days that were already being exploited in attacks. For Windows users and IT teams, this is a Patch Tuesday worth treating as a priority.
What happened
The September 2026 Patch Tuesday fixes 966 security flaws across Microsoft products, according to BleepingComputer’s count of vulnerabilities released by Microsoft on Patch Tuesday itself. The release includes 105 vulnerabilities rated Critical, with 81 involving remote code execution.
The two actively exploited Windows zero-days are CVE-2026-81963 and CVE-2026-85880. Both are elevation-of-privilege vulnerabilities that can allow an attacker who already has local access to gain SYSTEM-level privileges.
The two exploited Windows zero-days
CVE-2026-81963 affects the Windows Update Stack. Microsoft says improper link resolution before file access can allow an authorized local attacker to elevate privileges. The vulnerability was credited to Romain Deperne and the Microsoft Threat Intelligence Centre.
CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC. Microsoft describes it as a heap-based buffer overflow that can allow an authorized local attacker to elevate privileges. Researchers from Volexity and Proofpoint were credited with discovering the flaw.
Microsoft has not publicly detailed how either vulnerability has been used in attacks, making prompt patching the safer option for affected systems.
Why this Patch Tuesday matters
The sheer size of this release makes it unusual. The 966 vulnerabilities make September Microsoft’s largest Patch Tuesday security release to date, following already large updates earlier in 2026.
The numbers also illustrate how quickly vulnerability discovery is changing. AI-assisted security research is helping uncover weaknesses at greater scale, contributing to a faster pace of vulnerability identification and remediation.
For organizations, more vulnerabilities being discovered also increases the workload involved in testing and deploying security updates. Actively exploited vulnerabilities should generally receive the highest priority.
What Windows users should do now
For most home users, the simplest action is to open Settings > Windows Update, check for updates and install the latest security update offered for the device. Microsoft says security updates distributed through Windows Update are generally downloaded and installed automatically, but users should still verify their device has successfully updated.
Windows 11 versions 25H2 and 24H2 are receiving September cumulative update KB5124008, while Windows 11 23H2 is receiving KB5122880. Supported Windows 10 systems and devices enrolled in applicable Extended Security Updates also have September security releases available.
Business and enterprise administrators should consult Microsoft’s Security Update Guide to identify affected products and prioritize deployments according to exploit status, severity and organizational exposure.
What it means for readers
The important number is not simply 966. The bigger concern is that two vulnerabilities were already being exploited before Microsoft’s fixes arrived.
That makes delaying this month’s Windows security updates harder to justify. Keeping Windows updated remains one of the simplest ways to close vulnerabilities that attackers are known to be targeting.
Sources
Microsoft Security Response Center – Security Update Guide




