Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
4 mins read

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

This Patch Tuesday addresses 105 “Critical” vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.

The approximate number of bugs in each vulnerability category is listed below:

  • 438 Elevation of Privilege Vulnerabilities
  • 19 Security Feature Bypass Vulnerabilities
  • 258 Remote Code Execution Vulnerabilities
  • 173 Information Disclosure Vulnerabilities
  • 56 Denial of Service Vulnerabilities
  • 16 Spoofing Vulnerabilities

When GeekFeed reports on Patch Tuesday security updates, we only count vulnerabilities released by Microsoft on Patch Tuesday itself.

Therefore, today’s total does not include 204 flaws fixed earlier this month, including vulnerabilities in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge (Chromium-based), Microsoft Fabric, and Power Automate.

This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August.

The increase in Patch Tuesday security updates comes after Microsoft began using an AI-powered vulnerability discovery system to identify more security flaws across its software products.

To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5124008 & KB5122880 cumulative updates and the Windows 10 KB5122878 extended security update.

Microsoft patches 2 zero-days

This month’s Patch Tuesday fixes two actively exploited zero-day vulnerabilities.

Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.

The actively exploited zero-day vulnerabilities addressed during this the September 2026 Patch Tuesday are:

CVE-2026-81963 – Windows Update Stack Elevation of Privilege Vulnerability

Microsoft has patched an actively exploited elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges.

“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.,” warns Microsoft.

The flaws were credited to Romain Deperne and the Microsoft Threat Intelligence Centre (MSTIC).

No details have been shared on how the flaw was exploited in attacks.

CVE-2026-85880 – Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

Microsoft has fixed a Windows Advanced Local Procedure Call (ALPC) flaw that was exploited in attacks to gain SYSTEM privileges.

“Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally,” explains Microsoft.

Microsoft has not shared any details on how this flaw was exploited in attacks.

The flaw were discovered by Volexity and Mark Kelly, David Galazin, Jeremy Hedges with Proofpoint

Recent updates from other companies

Other vendors who released updates or advisories in August 2026 include:

The September 2026 Patch Tuesday Security Updates

Below is the complete list of resolved vulnerabilities in the September 2026 updates. Note, this report does include the flaws fixed earlier this month.

One thought on “Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Leave a Reply

Your email address will not be published. Required fields are marked *