Microsoft just dropped what security researchers are calling its largest Patch Tuesday release on record.
The company’s September 2026 security updates span Windows, Office, Exchange Server, SharePoint, and numerous other Microsoft products. SecurityWeek counted 974 CVEs across the broader release, while BleepingComputer counted 966 vulnerabilities released specifically on Patch Tuesday. The release includes two Windows privilege-escalation flaws that Microsoft confirmed were exploited before patches became available.
For defenders, the sheer size of the release makes prioritization critical. The two actively exploited Windows flaws belong near the front of the queue, but critical remote code execution vulnerabilities affecting enterprise infrastructure also demand attention.
Two Windows zero-days are already under attack
Among the vulnerabilities patched this month, two elevation-of-privilege flaws are already being exploited in the wild: CVE-2026-81963 and CVE-2026-85880.
CVE-2026-81963 affects the Windows Update Stack. The vulnerability involves improper link resolution before file access and can allow an authorized local attacker to elevate privileges to SYSTEM. Microsoft has not disclosed details about the attacks or how widely the flaw has been exploited.
The second exploited vulnerability, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). Successful exploitation can allow an attacker with local code execution to elevate privileges to SYSTEM.
Neither vulnerability provides attackers with an unauthenticated remote entry point on its own. Instead, they could help attackers who have already gained access to a Windows system obtain deeper control.
Both vulnerabilities carry CVSS scores of 7.8 and are rated Important, according to ZDI’s September review. However, their active exploitation makes severity scores only part of the risk calculation.
The new fixes arrive only weeks after Microsoft’s August Patch Tuesday addressed hundreds of vulnerabilities and another exploited Windows privilege-escalation zero-day.
Critical RCE flaws expand the patching priority list
The zero-days are not the only vulnerabilities security teams need to examine.
BleepingComputer counted 105 Critical vulnerabilities among the flaws released specifically on Patch Tuesday, including 81 remote code execution bugs. Its overall tally includes 438 elevation-of-privilege vulnerabilities, 258 RCE flaws, 173 information disclosure vulnerabilities, 56 denial-of-service bugs, 19 security feature bypasses, and 16 spoofing vulnerabilities.
One of the more serious enterprise vulnerabilities is CVE-2026-69525, a Remote Desktop Services use-after-free vulnerability with a CVSS score of 9.8. ZDI said the flaw could allow a remote, unauthenticated attacker to execute arbitrary code on an affected system, although Microsoft says the attacker must be on the same network.
Exchange Server also receives a notable fix for CVE-2026-55007. According to ZDI, an unauthenticated remote attacker could potentially achieve code execution by sending an affected Exchange server an email containing a malicious Visio attachment. The server’s processing of the message can trigger the vulnerability without the recipient opening the attachment.
Microsoft’s September Exchange Server security update lists CVE-2026-55007 as one of the vulnerabilities addressed in the release.
SharePoint is another area administrators should examine closely. September includes multiple SharePoint vulnerabilities, including remote code execution flaws, at a time when SharePoint servers have been a recurring target for attackers. Organizations running externally accessible on-premises SharePoint infrastructure should review Microsoft’s advisories and prioritize patches according to their exposure.
ZDI flagged numerous vulnerabilities from September as potentially wormable, including several flaws that could allow remote, unauthenticated code execution without user interaction.
Record release makes prioritization the real challenge
September’s vulnerability totals vary depending on how researchers count the updates.
SecurityWeek counted 974 CVEs across Microsoft’s September release. BleepingComputer’s Patch Tuesday count puts the number at 966 because its methodology counts vulnerabilities Microsoft released specifically on Patch Tuesday. BleepingComputer said its tally excludes 204 vulnerabilities Microsoft fixed earlier in September, including flaws affecting Azure, Copilot Studio, Entra ID, Edge, Microsoft Fabric, and other products.
BleepingComputer called the 966-flaw release Microsoft’s largest security update ever, surpassing the 570 vulnerabilities it counted in July.
Other researchers use different methodologies, further illustrating why Patch Tuesday totals can vary between reports. The differing numbers do not change the larger story: September left security teams with an unusually large remediation workload.
The volume puts renewed emphasis on patch management and risk-based prioritization, particularly for enterprises maintaining large Windows endpoint and server environments.
Automated inventory and remediation tracking, combined with assessments of the effectiveness of existing security controls, can help organizations prioritize updates based on actual exposure and on whether compensating controls reduce risk.
Microsoft is also trying to make that workload easier to process. Beginning with the September release, the company said it is publishing machine-readable VEX statements for all Microsoft-assigned CVEs.
Vulnerability Exploitability eXchange, or VEX, provides standardized, machine-readable vulnerability information that security tools can process automatically. Microsoft said the expansion is intended to help organizations automate portions of vulnerability analysis and reduce the manual work required to interpret security advisories.
What security teams should do now
Security teams should start with CVE-2026-81963 and CVE-2026-85880 because Microsoft has confirmed both vulnerabilities were exploited before patches became available.
Organizations should identify affected Windows systems and prioritize updates where attackers could combine these privilege-escalation flaws with another vulnerability or an existing foothold to gain SYSTEM-level access.
From there, remediation should be based on actual exposure. Internet-facing and business-critical systems affected by remote code execution vulnerabilities should generally take precedence over vulnerabilities that require authentication, local access, user interaction, or other preconditions.
Administrators should pay particular attention to affected infrastructure such as Remote Desktop Services, Exchange Server, SharePoint, and other systems that could provide attackers with paths deeper into enterprise environments. The urgency for each vulnerability will depend on whether the affected service is exposed, reachable, and actually deployed within the organization.
Organizations should test updates against critical workloads before broad deployment where operational requirements permit, but confirmed exploitation should shorten the testing window for the two Windows zero-days.
Security teams should also continue to monitor Microsoft’s advisories and threat intelligence for details on how the exploited vulnerabilities are being used. Microsoft has confirmed exploitation but has released little public information about the attacks themselves.
September’s release is ultimately as much a prioritization problem as a patching problem. With nearly 1,000 vulnerabilities competing for attention, defenders should first focus on known exploitation and remotely reachable attack paths, then work through the remaining fixes based on exposure, exploitability, and the importance of the affected systems.
For additional Windows security context, Microsoft recently addressed the ShieldBreak Windows Defender vulnerability, another privilege-escalation issue demonstrated against Windows systems.





