Visualização de leitura

Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited

Patch Tuesday September 2026

Microsoft's Patch Tuesday September 2026 rollout has broken previous records, with the company addressing 974 CVEs across its product lineup in a single release. Two of these vulnerabilities were already being exploited in the wild before fixes became available, prompting quick action from federal cybersecurity authorities.  The sheer volume of this month's Patch Tuesday September 2026 release dwarfs recent months. Windows accounted for 723 of the fixed flaws, while the Office suite received patches for 222 issues, 111 of which affected Office 2016 specifically.  

Scale of Patch Tuesday September 2026 

SQL Server products saw 62 CVEs resolved, Developer Tools had 22, SharePoint Server received 16 fixes, Azure had 12, Skype for Business had 10, and Exchange Server accounted for 9. More than 110 of the vulnerabilities patched carry a critical severity rating, and nearly 90% of the total fall into three categories: privilege escalation, remote code execution, and information disclosure.   Factoring in fixes for 25 non-Microsoft CVEs, the combined total for this Patch Tuesday September 2026 cycle reaches 999 resolved vulnerabilities.  This release continues a pattern of escalating patch volumes from Microsoft in recent months — 457 CVEs were addressed in August, 663 in July, 220 in June, and 161 in May, making September's numbers a significant jump even against that backdrop. 

The Two Exploited Zero-Days 

Central to this month's Patch Tuesday September 2026 update are two CVEs that Microsoft confirmed had been exploited before patches were issued.  The first, CVE-2026-85880 (CVSS 7.8), is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component. It allows an attacker with local access to escalate privileges and obtain SYSTEM-level control. Microsoft's advisory states that an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system, with no additional user interaction required.  The second actively exploited flaw, CVE-2026-81963 (CVSS 7.8), stems from improper link resolution within the Windows Update Stack. Like the ALPC bug, it enables a local, authorized attacker to escalate privileges and gain SYSTEM access.  Both CVEs have since been added to the Known Exploited Vulnerabilities (KEV) catalog maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Federal Civilian Executive Branch agencies now face a September 22, 2026 deadline to apply the relevant patches. 

Other Notable CVEs Worth Tracking 

Beyond the zero-days, several other CVEs patched in this Patch Tuesday September 2026 batch carry high severity scores and warrant prompt attention from Microsoft administrators: 
  • CVE-2026-55007 (CVSS 8.1) — a double-free flaw in Microsoft Exchange Server enabling remote code execution 
  • CVE-2026-80097 (CVSS 8.6) — improper authentication in Microsoft Authenticator allowing local privilege escalation 
  • CVE-2026-69465 (CVSS 8.8) — missing authorization in Microsoft Office SharePoint permitting remote code execution 
  • CVE-2026-65669 (CVSS 9.6) — an injection flaw in SQL Server enabling remote privilege escalation 
  • CVE-2026-69525 (CVSS 9.8) — use-after-free in Windows Remote Desktop Services allowing remote code execution 
  • CVE-2026-69595 (CVSS 9.8) — use-after-free in the Windows Services for NFS ONCRPC XDR Driver 
  • CVE-2026-69730 (CVSS 9.8) — use-after-free in the Windows DNS server 
  • CVE-2026-69829 (CVSS 9.8) — heap-based buffer overflow in Windows Shell 
  • CVE-2026-72979 (CVSS 9.8) — use-after-free in the Windows DHCP Server 
Alongside the CVE fixes, Microsoft's Patch Tuesday September 2026 release also included new Servicing Stack Updates (SSUs), classified as critical, covering Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.  Given the number of critical-severity CVEs and the confirmed exploitation of two privilege-escalation bugs, security teams are expected to prioritize this Patch Tuesday September 2026 rollout above routine monthly cycles, particularly for internet-facing Windows and Exchange deployments. 

Microsoft fixes record 964 flaws, including 2 exploited zero-days

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.

Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch.

The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of-privilege vulnerabilities that could allow an attacker who already has access to a device to gain SYSTEM privileges. Neither provides remote access by itself, but SYSTEM-level access is valuable to malware operators after they gain an initial foothold through phishing, stolen credentials, or another method.

How to apply patches and check if you’re protected

These updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:

  • Click the Start button, then open Settings.
  • Select Windows Update (usually at the bottom of the menu on the left).
  • Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
Windows 11 up to date
  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
    Windows up to date

Technical details

The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.

Let’s take a closer look at the two zero-day vulnerabilities. Microsoft classifies a vulnerability as a zero-day if it was publicly disclosed or actively exploited before an official fix became available.

The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a CVSS score of 7.8 out of 10, tracked as CVE-2026-81963. The description says:

“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.”

This means Windows can be persuaded to open or modify the wrong file because it follows a shortcut-like pointer without properly checking where that pointer leads. Microsoft says attackers exploited the bug before a patch was available.

The second zero-day, tracked as CVE-2026-85880, also has a CVSS score of 7.8 out of 10. Microsoft describes it as:

“heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.”

Microsoft says an attacker who can execute code in a low-privilege AppContainer could exploit the vulnerability locally to escape the sandbox and elevate their privileges on the affected system. No additional user interaction is required.

Windows ALPC is an internal messaging system in the Windows operating system that allows different programs on the same computer to communicate with each other quickly.

A buffer overflow occurs when an area of memory within a software application reaches its boundary and data spills into an adjacent memory region. The heap is a region of memory used for dynamic memory allocation.

These are not the kinds of bugs a typical victim triggers merely by opening a malicious document or visiting a website. But local privilege escalation is a critical part of many attack chains: After malware runs with limited rights, a SYSTEM-level exploit can help an intruder disable defenses, access protected data, establish persistence, or move through a network.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.

Image: Shutterstock.com, Kirill Makarov.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.

There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.

Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.

Also scary is CVE-2026-69829, a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.

Microsoft’s summary of the security updates released today. Image: msrc.microsoft.com.

Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).

Tyler Reguly, associate director of security research and development at Fortra, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.

“It’s time to put our CISOs and CSOs on notice,” Reguly said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.”

Satnam Narang is senior staff research engineer at Tenable. Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.

“AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,” he said. “It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”

Of course, regular Windows users don’t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program’s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear to be causing problems. As always, the SANS Internet Storm Center has a per-patch breakdown ordered by severity and urgency.

Two critical Chrome flaws put users at risk on malicious websites

Update September 4, 2026

Shortly after this article was published, Google released another Chrome update that patches an actively exploited flaw in the V8 JavaScript engine, tracked as CVE-2026-85046.

Google rates the vulnerability as high severity and says an exploit already exists in the wild. An attacker could use a crafted HTML page to execute arbitrary code inside the Chrome sandbox. Because it is already being exploited, HKCERT rates the overall risk as extremely high.

After installing the latest update, Chrome should be at version 152.0.7977.82/.83 on Windows and Mac, or 152.0.7977.82 on Linux.

Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities.

How to update Chrome

If you don’t want to wait for the rollout to reach you, manually updating is easy.

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind if you never close your browser or if something goes wrong with the update.

To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.

You can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.

Technical details

Let’s look at the two critical vulnerabilities. Both are use-after-free (UAF) vulnerabilities. A use-after-free vulnerability occurs when a program attempts to access a memory location after it has been freed. That can cause crashes or, in some cases, allow an attacker to run their own code.

The first, tracked as CVE-2026-84353, was found in Shared Tab Groups and could allow a remote attacker using social engineering to execute arbitrary code outside the browser sandbox via a crafted HTML page. Here, social engineering likely means an attacker would have to lure you to a malicious website or open an email in HTML format.

The other critical vulnerability, tracked as CVE-2026-84352, was found in WebGL. WebGL, short for Web Graphics Library, is a browser technology that lets websites display interactive 2D and 3D graphics. The vulnerability could allow a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

Chrome vulnerabilities that enable remote code execution outside the browser sandbox are particularly valuable to attackers because they can turn a visit to a malicious or compromised website into direct code running on the underlying operating system, often without requiring additional exploitation steps.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

❌