Skip to content
vulnerabilityCVEendpoint-security

Microsoft's September 2026 Patch Tuesday: record 973 CVEs, two Windows zero-days under active attack

2 min read
Share

Microsoft shipped its largest Patch Tuesday on record on September 8, 2026, fixing 973 vulnerabilities across Windows, Office, Azure, and server products. Of these, 113 are rated Critical. Two zero-days were exploited in the wild before patches shipped, and both are now on CISA's Known Exploited Vulnerabilities catalog with a September 29 federal deadline.

The two zero-days you need to patch today

CVE-2026-81963 is an elevation-of-privilege flaw in the Windows Update Stack. It involves improper link resolution before file access, a class of bug called link following. An attacker with local access can exploit it to elevate privileges. CVSS score: 7.8 (Important). Confirmed exploited in the wild.

CVE-2026-85880 is more interesting from an attacker's perspective. It is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). An attacker already operating inside an AppContainer sandbox, such as a compromised browser renderer process, can trigger the overflow and escape to SYSTEM. CVSS score: 7.8 (Important). This makes it a natural second-stage payload after a browser or document exploit, chained to achieve full system compromise.

Four CVEs added to CISA KEV on September 8

Alongside the two Windows zero-days, CISA added CVE-2026-75650 (Adobe Commerce and Magento template engine injection, exploited in active e-commerce attacks) and CVE-2026-86218 (N-able N-central static code injection, enabling unauthenticated remote code execution on the remote management platform) to the KEV catalog. Federal agencies must patch all four by September 29.

What to do now

Apply September 2026 Windows updates immediately. Prioritize CVE-2026-85880 if you run any process that renders untrusted content inside an AppContainer, including modern browsers, Office Online, and PDF viewers. For Adobe Commerce and Magento operators: the template injection flaw is being used in targeted e-commerce attacks, so patch or take the affected system offline. N-able N-central administrators should patch immediately or isolate the platform from internet exposure; remote management platforms are premium initial-access targets.

Tenable flagged 20 potentially wormable vulnerabilities in this patch batch. Wormable Windows networking flaws spread without user interaction and are historically leveraged by ransomware operators for lateral movement. Tenable's September 2026 Patch Tuesday breakdown is the reference for full prioritization.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you're assessing your patch management posture or need help prioritizing zero-day response.