Microsoft September 2026 Patch Tuesday Fixes Record Number of Flaws
The latest security update addresses two actively exploited zero-days amid a surge of critical vulnerabilities.
Microsoft has released its September 2026 Patch Tuesday security updates, addressing a record-breaking volume of vulnerabilities. The release is urgent, as it includes fixes for two zero-day vulnerabilities already being exploited in the wild.
Reports on the total number of flaws vary due to differing counting methodologies: BleepingComputer reports 966 flaws, Tenable cites 964, and Cybersecurity News reports 973. BleepingComputer identifies 105 of these as 'Critical,' including 81 remote code execution flaws, 20 elevation of privilege issues, two information disclosure vulnerabilities, and one security feature bypass. Tenable reports a slightly lower count of 104 Critical flaws.
One of the most pressing threats is CVE-2026-81963, a Windows Update Stack Elevation of Privilege vulnerability. This zero-day allows attackers to gain higher-level permissions on a system, potentially bypassing security controls to execute malicious code. The presence of two actively exploited zero-days indicates that attackers are successfully utilizing gaps in the Windows ecosystem before patches can be deployed.
The Growing Attack Surface
The scale of this update highlights an expanding attack surface for Windows users. The concentration of 'Critical' remote code execution (RCE) flaws is especially concerning for enterprise environments. RCE vulnerabilities are highly prized by threat actors because they allow the execution of arbitrary code from a remote location, often without requiring user interaction. This increases the risk of widespread, automated attacks that can move laterally through a network if systems remain unpatched.
Industry Implications
This release follows a broader trend of increasing vulnerability counts throughout 2026. The volume of fixes required in a single monthly cycle suggests that the complexity of the Windows ecosystem is creating more opportunities for discovery by both security researchers and malicious actors. For IT administrators, the record-breaking number of CVEs complicates the triage process, as they must balance the need for immediate patching against the risk of update-induced system instability.
What to Watch
Organizations are urged to prioritize the two zero-day fixes and the high-severity RCE vulnerabilities immediately. Security teams should monitor for any signs of exploitation related to CVE-2026-81963 and other elevation of privilege flaws. While Microsoft has provided the patches, the industry will be watching to see if further out-of-band updates are required should new exploits emerge from the remaining hundreds of addressed flaws.