The September 2026 Patch Tuesday addresses 105 flaws rated “Critical,” with 81 of those involving remote code execution. Overall, the update covers 438 elevation of privilege vulnerabilities, 258 remote code execution flaws, 173 information disclosure bugs, 56 denial of service vulnerabilities, 19 security feature bypass issues, and 16 spoofing vulnerabilities.
The two actively exploited zero-day vulnerabilities patched this month are:
- CVE-2026-81963 – An elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges. Microsoft described it as “improper link resolution before file access (link following)” and credited Romain Deperne along with the Microsoft Threat Intelligence Centre (MSTIC) for reporting it. No details on how the flaw has been exploited publicly were shared.
- CVE-2026-85880 – A Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability (additional details are limited in the source).
According to BleepingComputer, Microsoft has attributed the surge in Patch Tuesday volume to an AI-powered vulnerability discovery system that identifies more flaws across its software. The total does not include 204 additional bugs fixed earlier this month in products such as Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, and Microsoft Edge (Chromium-based).
Organisations are advised to prioritise deployment of the zero-day patches given active exploitation, while also planning update cycles to manage the unprecedented volume of fixes.