Skip to content
feed: live
>_0dayNews
microsoft
● Breaking

Microsoft Patches Record 974 Vulns, 2 Zero-Days

September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

Microsoft Patches Record 974 Vulns, 2 Zero-Days
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·1 min read

Microsoft’s September 8 security update patches 974 CVEs, a new Patch Tuesday record per SecurityWeek. Two of those are confirmed exploited in the wild. CISA added both to its Known Exploited Vulnerabilities catalog on September 8 with a remediation deadline of September 22.

The two zero-days

CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC), CVSS 7.8. An attacker who can execute code inside a low-privilege AppContainer can trigger the overflow to escape the sandbox and escalate privileges on the local system.

CVE-2026-81963 is an improper link resolution flaw in the Windows Update Stack, also CVSS 7.8. A local attacker can exploit it to escalate to SYSTEM.

Both require local code execution as a precondition: neither is remotely exploitable on its own. In practice, post-compromise privilege escalation is the standard next step after initial access, and CISA’s active-exploitation flag on both means attackers are already using them.

Scale

974 patches is a new Patch Tuesday record, per SecurityWeek. Product breakdown: 723 Windows flaws, 222 Office bugs, the rest across SQL Server, SharePoint, Azure, Exchange Server, Skype for Business, and developer tools.

Zero Day Initiative analyst Dustin Childs identified 20 of the newly patched vulnerabilities as potentially wormable: remote code execution achievable without authentication or user interaction. Microsoft has not named which specific CVEs meet that bar; expect breakdowns from ZDI and independent researchers in the days following the release.

Patch now

Apply the September 8 cumulative update. If your organization runs a 30-day patch cycle, pull CVE-2026-85880 and CVE-2026-81963 from it and treat them as out-of-band priorities. Federal agencies must patch by September 22 per BOD 26-04; treat that date as the outside limit for any environment.

Related: CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw | Entra ID CVE-2026-69836: CVSS 10, Exploited, KEV | What Is the CISA KEV Catalog?

Related CVEs
  • [ HIGH ]CVE-2026-85880Microsoft Windows ALPC Heap Buffer Overflow Privilege Escalation
  • [ HIGH ]CVE-2026-81963Microsoft Windows Update Stack Link-Following Privilege Escalation

Found this useful? Share it.