September’s Patch Tuesday is Microsoft’s biggest ever, and it opens with a warning for IT teams. The September 9 release closes 974 vulnerabilities, two of which attackers have already exploited, according to the company’s advisories. Windows soaked up the largest share with 723 patches, Office and SQL Server together account for 173 more and developer tools for 22, and over 110 fixes carry critical ratings. Factoring in 25 flaws from other vendors, Microsoft resolved 999 issues in one cycle, roughly doubling a month ago’s output of 457.
Both exploited bugs end with SYSTEM privileges. In the Windows Advanced Local Procedure Call service, CVE-2026-85880 is a heap overflow that lets code running in a low-privilege AppContainer break out of the sandbox. The other, CVE-2026-81963, marks the first zero-day ever seen in the Windows Update Stack: flawed link resolution lets an attacker overwrite a system component with a malicious impostor. Volexity, Proofpoint and Microsoft’s threat intelligence center get the credit for reporting them.
Beyond the exploited pair, ZDI’s Dustin Childs flags a cluster of 20 bugs on most Windows versions as potentially wormable. His list leads with CVE-2026-69730, a DNS vulnerability with no user interaction required that he calls the spiritual successor to SigRed. He also warns on CVE-2026-69676, a Kerberos authentication bypass where one phished workstation account can end in code execution on a domain controller.
Rapid7’s Adam Barnett points out that every supported Windows release received the Windows Update Stack patch. Microsoft has stayed quiet on how widespread the zero-day attacks are, but with exploit activity confirmed, the two bugs above are where patching should start.
