- Microsoft fixes 974 vulnerabilities in its September 2026 security release, making it another record-breaking Patch Tuesday.
- The broader Windows product family accounts for 723 vulnerabilities, covering Windows client and Server products.
- Two Windows flaws, CVE-2026-85880 and CVE-2026-81963, are already being exploited to elevate privileges to SYSTEM.
- AI-assisted vulnerability discovery is contributing to a much higher volume of security fixes, putting more pressure on organizations to patch quickly.
Microsoft released its September 2026 security updates, fixing 974 vulnerabilities across its products, including 723 flaws on Windows 11, 10, and Windows Server, and two Windows vulnerabilities already being exploited in attacks. The September 8 release, which also includes the update KB5124008 for Windows 11 25H2 and 24H2, follows another unusually large Patch Tuesday in August, when the company addressed hundreds of security issues across its software.
The two exploited Windows vulnerabilities, CVE-2026-85880 and CVE-2026-81963, are elevation-of-privilege flaws that can allow an attacker with local access to obtain SYSTEM-level privileges.
This release sets another Patch Tuesday record, with 974 vulnerabilities addressed across its products.
September breaks Microsoft’s recent Patch Tuesday records
Microsoft’s September release is the latest in a string of unusually large security updates.
In my August 2026 Windows 11 security update coverage, the company had already patched 421 vulnerabilities across its products. September now pushes the volume considerably higher, with 974 Microsoft CVEs listed in the company’s Security Update Guide.
Windows products account for 723 of those vulnerabilities. The company also addressed 222 Office vulnerabilities, along with flaws in SQL Server, Developer Tools, SharePoint Server, Azure, Skype for Business, and Exchange Server.
Two Windows flaws are already being exploited
The most important fixes affect Windows itself.
CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC). An attacker who can execute code in a low-privilege AppContainer can exploit the flaw to escape the sandbox and elevate privileges.
CVE-2026-81963 affects the Windows Update Stack. The flaw involves improper link resolution before file access and can also allow a local attacker to elevate privileges to SYSTEM.
Neither vulnerability provides an attacker with remote access on its own. The attacker needs an initial foothold on the machine. However, gaining SYSTEM privileges after compromising a device can give malware significantly more control over the operating system.
AI is helping uncover more Windows vulnerabilities
The enormous September release also comes as the software giant and other technology companies increasingly use AI to find security weaknesses.
Microsoft typically patches around 100 vulnerabilities in a normal month. That number has risen sharply this year, with July reaching around 570 fixes and August approaching 400. September is another record-breaking release.
The important distinction is that AI isn’t necessarily creating these vulnerabilities. It’s helping researchers discover weaknesses that may have existed for years.
That is good news for security, but it creates a difficult problem for organizations. More discoveries mean more patches, more testing, and more opportunities for attackers to exploit systems before administrators can deploy the fixes.
The result is a shrinking patch window.
Why the patch gap is becoming a bigger problem
Organizations can’t always install Microsoft’s updates immediately. Network administrators often need to test cumulative updates against apps, drivers, security software, and custom configurations before deploying them across production systems.
As a result, this creates a gap between when Microsoft releases a fix and when an organization actually installs it.
The problem becomes more serious when vulnerabilities are already being exploited.
For home users, there is far less reason to wait. If Windows Update offers the September security update, installing it’s the practical approach, particularly given the two exploited vulnerabilities.
Organizations should prioritize the vulnerabilities that actually affect their systems rather than treating all 974 CVEs as equally urgent.
September’s update is about more than Windows
The September security release also covers Microsoft’s server and business products.
Microsoft has patched vulnerabilities in Exchange Server, SharePoint Server, SQL Server, Azure, Skype for Business, Developer Tools, and Office. Some of these include remote code execution vulnerabilities that could have greater consequences in enterprise environments.
The company also lists known issues for several server products, so administrators should review the applicable release information before broad deployment.
For Windows users, however, the immediate priority remains the cumulative security update for their supported version of Windows, including Windows 11.
Pureinfotech’s Take
I’ve covered Microsoft’s increasingly large Patch Tuesday releases throughout this year, and the progression from August to September is hard to ignore.
How concerned are you about Microsoft's record-breaking September Patch Tuesday?
Voting closes: September 16, 2026 1:00 pm
I also wouldn’t look at the growing CVE counts as proof that Windows is suddenly less secure. Better automated security research is finding more problems, and Microsoft is fixing them. That’s better than leaving those vulnerabilities undiscovered.
For regular users, I would install this month’s update rather than put it off. For businesses, prioritization matters more than reacting to the 974 figure.
The bigger concern is how quickly the security landscape is changing. If AI continues to accelerate vulnerability discovery and exploit development, the time organizations have to test and deploy patches could become increasingly difficult to maintain.

