Microsoft September 2026 Patch Tuesday: 973 CVEs Fixed, 2 Actively Exploited Flaws Confirmed
Microsoft released its largest Patch Tuesday to date, addressing 973 vulnerabilities across Windows, Office, and server products, with 113 rated Critical. Two Elevation of Privilege flaws are confirmed actively exploited in the wild, including CVE-2026-81963 affecting Windows Update Stack and CVE-2026-85880 targeting the Advanced Local Procedure Call component, prompting an immediate 24-hour patch recommendation. The release nearly doubles the August count at 973 CVEs, fueling the "Patch Apocalypse" trend driven by AI-assisted vulnerability discovery, while Hotpatching is now generally available for Windows Server Azure Edition VMs to reduce reboot downtime. Organizations should prioritize deploying KB5122871 and KB5122876 immediately, as critical RCE flaws in DNS and Remote Desktop Services also land this month, and several products including Windows Server 2012 and Exchange 2016 are approaching end-of-life support.
Microsoft September 2026 Patch Tuesday: 973 CVEs Fixed, 2 Actively Exploited Flaws Confirmed
Microsoft's September 2026 Patch Tuesday is its largest ever, addressing 973 vulnerabilities, including 113 rated Critical, with two actively exploited Elevation of Privilege flaws prompting urgent patch recommendations. The significant increase in vulnerabilities, nearly doubling the previous month's count, is attributed to the "Patch Apocalypse" trend driven by AI-assisted vulnerability discovery. Organizations are advised to prioritize the deployment of critical patches for Remote Code Execution and to consider the upcoming end-of-life for several products, including Windows Server 2012 and Exchange 2016. Additionally, the introduction of Hotpatching for Windows Server Azure Edition VMs allows for kernel patch applications without reboot, which is significant for managing the extensive number of vulnerabilities
