
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
This Patch Tuesday addresses 105 “Critical” vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.
The approximate number of bugs in each vulnerability category is listed below:
- 438 Elevation of Privilege Vulnerabilities
- 19 Security Feature Bypass Vulnerabilities
- 258 Remote Code Execution Vulnerabilities
- 173 Information Disclosure Vulnerabilities
- 56 Denial of Service Vulnerabilities
- 16 Spoofing Vulnerabilities
When GeekFeed reports on Patch Tuesday security updates, we only count vulnerabilities released by Microsoft on Patch Tuesday itself.
Therefore, today’s total does not include 204 flaws fixed earlier this month, including vulnerabilities in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge (Chromium-based), Microsoft Fabric, and Power Automate.
This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August.
The increase in Patch Tuesday security updates comes after Microsoft began using an AI-powered vulnerability discovery system to identify more security flaws across its software products.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5124008 & KB5122880 cumulative updates and the Windows 10 KB5122878 extended security update.
Microsoft patches 2 zero-days
This month’s Patch Tuesday fixes two actively exploited zero-day vulnerabilities.
Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.
The actively exploited zero-day vulnerabilities addressed during this the September 2026 Patch Tuesday are:
CVE-2026-81963 – Windows Update Stack Elevation of Privilege Vulnerability
Microsoft has patched an actively exploited elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges.
“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.,” warns Microsoft.
The flaws were credited to Romain Deperne and the Microsoft Threat Intelligence Centre (MSTIC).
No details have been shared on how the flaw was exploited in attacks.
CVE-2026-85880 – Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Microsoft has fixed a Windows Advanced Local Procedure Call (ALPC) flaw that was exploited in attacks to gain SYSTEM privileges.
“Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally,” explains Microsoft.
Microsoft has not shared any details on how this flaw was exploited in attacks.
The flaw were discovered by Volexity and Mark Kelly, David Galazin, Jeremy Hedges with Proofpoint
Recent updates from other companies
Other vendors who released updates or advisories in August 2026 include:
- Adobe released a security update for max-severity zero-day Adobe Commerce vulnerability dubbed StyleSmuggler that was exploited in attacks to backdoor websites.
- Cisco released security updates for numerous products, including Cisco IOS XR, Cisco Nexus 9000 Series Switches, and Cisco Phones.
- ConnectWise shared mitigations for a ScreenConnect Remote Access vulnerability that it plans to patch later this week.
- CrowdStrike warned customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting after an anonymous researcher released a zero-day flaw for the software.
- Google released Chrome security updates for an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
- Hewlett Packard Enterprise (HPE) patched a critical RCE vulnerability in the ArubaOS-CX network operating system.
- MicroTik released security updates for two actively exploited flaws used to hijack devices over SSH.
- N-able released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. The flaw is believed to potentially exploited in attacks.
- Plex released security updates for multiple vulnerabilities this week, urging customers to install them as soon as possible without providing any further details.
- SAP released the September security updates for numerous products, including a maximum-severity “OVERPASS” flaw in the SAP Kernel code.
- SonicWall released security updates for two SMA1000 zero-day vulnerabilities that are being chained in RCE attacks.
The September 2026 Patch Tuesday Security Updates
Below is the complete list of resolved vulnerabilities in the September 2026 updates. Note, this report does include the flaws fixed earlier this month.



One thought on “Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days”