Security News

Microsoft's September Patch Tuesday Sets Record With 974 Security Fixes

Infosecurity Magazine · 9 Sept 2026
Key Takeaway Small businesses should prioritise patching the two actively exploited Windows vulnerabilities immediately, rather than trying to apply all 974 fixes at once.

Microsoft has released fixes for 974 CVEs in its September 2026 Patch Tuesday update, smashing the previous record of 570 set just two months earlier. Windows accounts for the bulk of the flaws at 723, followed by Office with 111. The number of patched vulnerabilities has climbed sharply over recent months: from 164 in April and 120 in May, to 200 in June, 570 in July, 400 in August, and now 974 in September. Microsoft had previously warned customers to expect more frequent large-scale updates as it uses AI tools to discover zero-day vulnerabilities faster.

Among the fixes are two zero-day vulnerabilities already being actively exploited. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call system that could let an attacker with low-level code execution rights escalate their privileges. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, which could also allow privilege escalation by an authorised attacker. The release includes 119 critical-rated vulnerabilities in total.

Security experts note that the sheer volume of patches makes prioritisation essential. As one vulnerability researcher put it, the challenge for IT teams is no longer just applying updates, but quickly identifying which ones require urgent action versus those that can follow a normal patching schedule.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.