Microsoft Patches Record Nearly 1,000 Vulnerabilities
Microsoft released its September 2026 Patch Tuesday update, addressing a record number of security vulnerabilities, including two zero-day flaws that had already been exploited in the wild. The update, which rolled out on September 9, 2026, patched between 966 and 974 primary flaws, significantly exceeding previous monthly totals. Two of the vulnerabilities, identified as CVE-2026-81963 and CVE-2026-85880, were actively exploited by attackers before Microsoft could issue fixes. Both flaws are classified as elevation of privilege vulnerabilities. CVE-2026-81963 affects the Windows Update Stack, allowing attackers to gain SYSTEM privileges through improper link resolution. CVE-2026-85880 targets the Windows Advanced Local Procedure Call (ALPC) component, enabling local privilege escalation and the potential to escape sandboxed environments to achieve SYSTEM-level control. The sheer volume of patches released this month is attributed in part to the increasing use of artificial intelligence in vulnerability discovery. While AI is helping developers find and fix bugs more rapidly, it is also believed to be aiding malicious actors in developing exploit tools.