Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Microsoft Patches Record Nearly 1,000 Vulnerabilities

Published 10 September 2026

Microsoft released its September 2026 Patch Tuesday update, addressing a record number of security vulnerabilities, including two zero-day flaws that had already been exploited in the wild. The update, which rolled out on September 9, 2026, patched between 966 and 974 primary flaws, significantly exceeding previous monthly totals. Two of the vulnerabilities, identified as CVE-2026-81963 and CVE-2026-85880, were actively exploited by attackers before Microsoft could issue fixes. Both flaws are classified as elevation of privilege vulnerabilities. CVE-2026-81963 affects the Windows Update Stack, allowing attackers to gain SYSTEM privileges through improper link resolution. CVE-2026-85880 targets the Windows Advanced Local Procedure Call (ALPC) component, enabling local privilege escalation and the potential to escape sandboxed environments to achieve SYSTEM-level control. The sheer volume of patches released this month is attributed in part to the increasing use of artificial intelligence in vulnerability discovery. While AI is helping developers find and fix bugs more rapidly, it is also believed to be aiding malicious actors in developing exploit tools.

0:00 / 0:00