Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft addressed a record 974 vulnerabilities across its software portfolio, including two actively exploited Windows zero-day flaws, in its latest Patch Tuesday update.
Intelligence analysis by Gemini 2.5 Flash

Microsoft's September Patch Tuesday set a new record by fixing 974 vulnerabilities, with over 110 rated critical. Notably, two Windows zero-day flaws, CVE-2026-85880 and CVE-2026-81963, were actively exploited, prompting the U.S. CISA to mandate immediate patching for federal agencies.
Imagine Microsoft makes lots of computer programs, like building blocks. This month, they found a record number of tiny cracks and weak spots in almost a thousand of their blocks! Two of these cracks were super important because some bad guys had already found them and were using them to sneak into computers. So, Microsoft rushed out a huge fix to patch all these cracks and keep everyone's computers safe, especially the ones used by the government.
Analysis
Record-Setting Vulnerability Patches
Microsoft's September Patch Tuesday marked an unprecedented event, with the company addressing an astounding 974 vulnerabilities across its extensive software ecosystem. This figure shatters previous records, significantly surpassing the 457 flaws patched in August and the 663 in July. The sheer volume of fixes highlights a growing trend in vulnerability disclosures, with over 110 of these shortcomings assigned a critical severity rating. Privilege escalation, remote code execution, and information disclosure collectively accounted for nearly 90% of the patched flaws, indicating common attack vectors targeted by malicious actors. This continuous surge in discovered vulnerabilities, totaling 2,760 this year alone according to TrendAI's Zero Day Initiative, suggests that advanced methods, potentially including AI-assisted vulnerability discovery, are accelerating the identification of security weaknesses.
Actively Exploited Windows Zero-Days
Central to this month's update were two Windows zero-day vulnerabilities, CVE-2026-85880 and CVE-2026-81963, both of which Microsoft confirmed were under active exploitation in the wild. CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally to SYSTEM. Similarly, CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack, also enables local privilege escalation to SYSTEM. These vulnerabilities are particularly concerning because attackers had already weaponized them before patches were available, posing an immediate threat to unpatched systems. Cybersecurity firms Volexity and Proofpoint, along with Romain Deperne and the Microsoft Threat Intelligence Center (MSTIC), were credited with reporting these critical flaws, emphasizing the collaborative effort required to identify and mitigate such sophisticated threats.
CISA and Broader Critical Flaws
The active exploitation of these two Windows zero-days prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add them to its Known Exploited Vulnerabilities (KEV) catalog. This designation mandates that Federal Civilian Executive Branch (FCEB) agencies apply the necessary fixes by September 22, 2026, underscoring the urgency and severity of these particular vulnerabilities. Beyond the zero-days, Microsoft also addressed several other high-severity flaws, including CVE-2026-55007, a double free vulnerability in Microsoft Exchange Server allowing remote code execution, and CVE-2026-69525, a use-after-free vulnerability in Windows Remote Desktop Services with a CVSS score of 9.8. The comprehensive nature of these patches, covering critical components like SQL Server, SharePoint, DNS server, and DHCP Server, highlights the broad attack surface that organizations must defend and the continuous effort required to maintain a secure posture against evolving cyber threats.
Key points
- Microsoft patched a record 974 vulnerabilities in its September Patch Tuesday update.
- Two Windows zero-day flaws (CVE-2026-85880 and CVE-2026-81963) were actively exploited in the wild.
- These zero-days allow local privilege escalation to SYSTEM privileges.
- CISA added both zero-days to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 22, 2026.
- The total number of flaws patched by Microsoft this year has exceeded 2,760, indicating a significant increase in vulnerability discoveries.
Microsoft's proactive and record-setting patching efforts demonstrate a strong commitment to addressing security vulnerabilities, including those actively exploited. The swift action by CISA to mandate fixes for federal agencies ensures that critical government systems are rapidly secured against known threats.
The unprecedented volume of vulnerabilities, particularly the increasing trend and the presence of actively exploited zero-days, highlights the persistent and growing challenge for IT teams to keep systems secure. The undisclosed specifics of the zero-day attacks also leave users uncertain about the full scope of potential compromises.


