Vulnerability
Published 2026-09-08
Verified 2026-09-19

Microsoft September 2026 Patch Tuesday: record ~966–974 CVEs; 2 exploited zero-days

Microsoft’s 8 September 2026 Patch Tuesday is its largest security release on record. BleepingComputer counts 966 flaws shipped on Patch Tuesday itself (105 Critical, including 81 RCE), excluding 204 flaws fixed earlier in the month in cloud products; SecurityWeek and Krebs count about 974 CVEs across the broader September bundle. Two actively exploited elevation-of-privilege zero-days are fixed: CVE-2026-81963 (Windows Update Stack link-following to SYSTEM; credited to Romain Deperne and MSTIC) and CVE-2026-85880 (Windows ALPC heap buffer overflow to SYSTEM / AppContainer sandbox escape; Volexity and Proofpoint researchers). Coverage notes ~20 potentially wormable unauthenticated RCEs in the set and calls out Exchange (CVE-2026-55007), SharePoint (CVE-2026-69465), RDS (CVE-2026-69525), SQL (CVE-2026-65669), and Authenticator (CVE-2026-80097) among high-priority items. Microsoft attributes the volume increase partly to AI-assisted vulnerability discovery. NEW 8 Sep KEV: CISA added both exploited zero-days to the Known Exploited Vulnerabilities catalog on 2026-09-08 (catalog 2026.09.08) — CVE-2026-81963 and CVE-2026-85880 (FCEB dueDate 2026-09-22). WA SOC advisory 20260909001 (9 September 2026, TLP:CLEAR) summarises the September Monthly Updates as addressing 973 vulnerabilities, highlights critical CVE-2026-69730 and CVE-2026-69525 (CVSS 9.8) plus the two known-exploited EoPs (CVSS 7.8), notes Microsoft detected exploitation of one or more of the mentioned vulnerabilities, and says WASOC has not received WA Government exploitation reports at the time of writing. Prioritise the two exploited EoPs, internet-facing roles, and Extended Security Updates where applicable.

Product
Microsoft Windows / Office / Exchange / SharePoint / SQL / Azure (September 2026 cumulative)
Versions
See Microsoft Update Guide for CVE-specific affected builds; Windows 10 ESU KB5122878 and Windows 11 KB5124008/KB5122880 noted in same-day coverage
Exploited in Australia?
unknown
Patch to
Install September 2026 security updates promptly; prioritise CVE-2026-81963 and CVE-2026-85880 (exploited EoP) and internet-facing Exchange/SharePoint/RDS roles

Primary: BleepingComputer — September 2026 Patch Tuesday (8 Sep 2026) · Vendor: Microsoft Security Update Guide — 2026-Sep release note · CVE: CVE-2026-81963, CVE-2026-85880, CVE-2026-55007, CVE-2026-69465, CVE-2026-69525, CVE-2026-65669, CVE-2026-80097, CVE-2026-69730 · WA SOC 20260909001 (9 Sep 2026); also SecurityWeek / Krebs

vulnerabilities cloud identity australia