- Start
- Sep 8, 202690% CONFIDENCEfrom the source
Microsoft's September 2026 Patch Tuesday Fixes a Record 966 Flaws
- Microsoft's September 2026 Patch Tuesday, released on 8 September, fixes a record 966 flaws counted on the day, its largest security update ever, after 570 in July and 400 in August; that count leaves out 204 flaws fixed earlier in the month[1]
- Tallies differ with what is counted: SecurityWeek puts the release at 974 CVEs and Tenable at 964[3][4][5]
- Two zero-days were actively exploited before the fix, both letting a local attacker gain SYSTEM: CVE-2026-81963, a link-following flaw in the Windows Update Stack credited to Romain Deperne and Microsoft's Threat Intelligence Centre, and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) found by Volexity and Proofpoint researchers[1][2][4]
- Both zero-days are rated Important with a CVSSv3 score of 7.8; CVE-2026-81963 is the first of seven Windows Update Stack privilege-escalation bugs patched since 2022 to be exploited in the wild[2][5]
- 105 of the flaws are rated Critical, 81 of them remote code execution; by type the release holds 438 elevation-of-privilege, 258 remote-code-execution and 173 information-disclosure bugs[1]
- Trend Micro's Zero Day Initiative flags 20 potentially wormable bugs, including DNS Server flaw CVE-2026-69730, which it calls a spiritual successor to SigRed[2][4]
- BleepingComputer links the jump in volume to Microsoft's use of an AI-powered vulnerability discovery system; Tenable's Satnam Narang says AI-assisted discovery is "creating larger haystacks, but it isn't finding more needles"[1][4]
- Microsoft publishes its monthly security update on the second Tuesday of each month, typically at 10:00 AM Pacific[6]
References 687% CONFIDENCE
The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
- [1]90%bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-daysbleepingcomputer.com· Posted Sep 23, 2026· Starts Sep 8, 2026 ✓· 20% of score
Stated as firm, per bleepingcomputer.com (8 September 2026): "Today is Microsoft's[6] September 2026 Patch Tuesday"; the time is Microsoft Learn's "second Tuesday of each month, typically at 10:00 AM Pacific Time", 17:00 UTC under daylight time.
- [2]86%September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successorhelpnetsecurity.com· Published Sep 9, 2026· 19% of score
Help Net Security covers the record count, the two exploited zero-days and their reporters, and ZDI's warning about 20 wormable bugs including DNS flaw CVE-2026-69730, a 'spiritual successor to SigRed'.
- [3]80%Microsoft fixes record 964 flaws, including 2 exploited zero-daysmalwarebytes.com· Published Sep 9, 2026· 19% of score
Malwarebytes Labs independently reports the September 2026 Patch Tuesday's record vulnerability count and its two actively exploited zero-days.
- [4]92%Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Dayssecurityweek.com· Published Sep 8, 2026· 19% of score
SecurityWeek reports on the day that Microsoft[6] rolled out a record 974 CVEs including the ALPC (CVE-2026-85880) and Windows Update Stack (CVE-2026-81963) zero-days, and quotes ZDI on 20 potentially wormable bugs.
- [5]88%Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)tenable.com· Published Sep 8, 2026· 19% of score
Tenable Research's analysis counts 964 CVEs (104 critical, 860 important), calls it the largest Patch Tuesday, and details both exploited zero-days with CVSS 7.8 scores.
Suggest a correction
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.