Microsoft’s Record Patch Tuesday: 966 Fixes and 2 Exploited Zero-Days in September 2026, as AI Finds More Bugs

Updated October 2026.

On 8 September 2026, Microsoft released fixes for 966 vulnerabilities, its largest monthly security update on record. The previous two months had brought 570 fixes in July and about 400 in August. Microsoft attributed much of the surge to an AI-powered vulnerability discovery system it is now using across its products.

By the numbers

  • 105 rated critical
  • 438 elevation of privilege, 258 remote code execution, 173 information disclosure, 56 denial of service, 19 security feature bypass, 16 spoofing
  • About 200 more cloud-service flaws (Azure, Copilot and others) were fixed separately earlier in the month. Those need no customer action.

The two exploited zero-days

  • CVE-2026-81963: an elevation of privilege flaw in the Windows Update stack that lets an attacker gain SYSTEM privileges.
  • CVE-2026-85880: a heap-based buffer overflow in Windows ALPC that also allows local escalation to SYSTEM.

Both are “local” bugs. Attackers typically chain them with phishing or another initial-access flaw to take full control of a machine. Because they are actively exploited, they should be patched first.

The bigger story: AI on both sides

AI is helping defenders find bugs faster, and attackers too. CERT-In’s 2026 guidance warns that AI shrinks the time between disclosure and exploitation. Higher patch volume is likely to be the new normal.

How IT teams can cope

  1. Prioritise by exploitation, not count. Use known-exploited lists and EPSS scores.
  2. Automate deployment with Intune, WSUS replacements or Autopatch, using staged rings.
  3. Reduce attack surface: remove local admin rights, and enable attack surface reduction rules and EDR.
  4. Keep Windows 10 machines on ESU or upgrade them. Unsupported systems will not get these fixes.

Sources

Note: different trackers report slightly different totals (about 964–974), depending on what they count.

Leave a Reply

Discover more from RP Strativa Globals

Subscribe now to keep reading and get access to the full archive.

Continue reading