Back to blog
Patch TuesdayMicrosoftCVE

September 2026 Patch Tuesday: Record 974 Flaws Fixed, Including Two Exploited Windows Zero-Days

Published on 2026-09-096 min readCleanIssue

> TL;DR: September 2026's Patch Tuesday sets an all-time record: 974 Microsoft vulnerabilities fixed in a single release — 999 counting 25 third-party CVEs. Breakdown: 723 Windows flaws, 111 in Office and Office 2016, 62 in SQL Server, 22 in developer tools, with more than 110 rated Critical. Privilege escalation, remote code execution, and information disclosure account for nearly 90% of the batch. Two zero-days are already exploited in the wild: CVE-2026-85880 (CVSS 7.8), a Windows ALPC heap overflow letting an attacker escape an AppContainer to SYSTEM without user interaction, and CVE-2026-81963 (CVSS 7.8), improper link resolution in the Windows Update Stack. CISA added both to KEV with a September 22, 2026 deadline.

The two zero-days first

CVE-2026-85880 — the AppContainer escape. An attacker already running code in a low-privilege AppContainer can exploit this ALPC (Advanced Local Procedure Call) heap overflow to escape the sandbox and reach SYSTEM — the maximum level — with no additional user interaction. Credited to Volexity and Proofpoint, it is the second ALPC flaw weaponized as a zero-day since CVE-2023-21674 (January 2023). It is the perfect complement to a browser or office RCE exploit: the zero-day closes the chain by elevating the attacker above the entire system.

CVE-2026-81963 — the Windows Update Stack. Improper link resolution lets a locally authorized attacker elevate to SYSTEM by having the update mechanism follow a malicious link replacing a system component with an attacker-controlled imposter. It is the seventh Update Stack privilege escalation since 2022, but the first ever exploited as a zero-day. Credited to Romain Deperne (Airbus Helicopters) and MSTIC.

The rest of the batch: what deserves attention

Beyond the zero-days, a few flaws stand out for a classic SaaS estate: CVE-2026-55007 (double free in Exchange Server, unauthenticated network RCE, CVSS 8.1) — after August's CVE-2026-62911, Exchange returns; CVE-2026-80097 (improper authentication in Microsoft Authenticator, local elevation, 8.6) — the tool carrying your MFA becomes a vector itself; and a run of use-after-free and heap overflows at 9.8 unauthenticated network RCE: RDS (CVE-2026-69525), NFS ONCRPC driver (CVE-2026-69595), DNS Server (CVE-2026-69730), Shell (CVE-2026-69829), and DHCP Server (CVE-2026-72979). These surfaces are typical of Windows servers reachable across network segments — prioritize servers accessible from other sensitive segments.

Why the numbers are exploding — and why they must not paralyze you

The 2026 trend is vertical: 2,760 Microsoft flaws fixed since January per the Zero Day Initiative, already more than double 2020's record (1,245) with three months left. Tenable reports this month exceeds the previous record by nearly 70%. Two engines: proactive cleanup of accumulated technical debt, and AI-assisted discovery accelerating research on both the defender and attacker sides.

The mistake would be treating 974 patches as 974 decisions. Tenable's analysis recalls that the number of vulnerabilities actually impacting a given organization stays small, and no correlated exploitation wave accompanies this batch. The method is unchanged: exposure perimeter first (what is exposed, where, to whom), exploitability next, normal deployment cadence for the rest.

What to do

  • Deploy the two zero-day patches first (ALPC and Update Stack) across all Windows endpoints and servers — the September 22 KEV deadline is a maximum, not a goal.
  • Treat the 9.8 network RCEs immediately on exposed servers: RDS, DNS, DHCP, NFS — especially those reachable from uncontrolled segments (guest Wi-Fi, DMZ, customer networks).
  • Patch Exchange (CVE-2026-55007) without waiting: the platform carries the heaviest exploitation history in the estate.
  • Do not review 999 CVEs manually: filter by actual presence in your inventory, then exposure, then exploitability. That triage is exactly what an exposure audit industrializes.
  • Plan for October: at this pace, the next Patch Tuesday will also be out of the ordinary. A rigorous monthly patch cadence beats a heroic quarterly sprint.
  • The broader lesson

    A 974-flaw record is a mixed signal: Microsoft fixes faster than ever (good) because vulnerability discovery has been industrialized on both sides (bad). For a product team, the consequence is direct: the window between "attacker knows the flaw" and "fix available" is the danger zone, and it is shrinking. Your ability to know within hours whether you are exposed to a given CVE — accurate inventory, exposure mapping, rapid testing — now matters more than any severity ranking.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Written by CleanIssue
    Reviewed on 2026-09-09

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit