Microsoft released its largest Patch Tuesday to date on September 8, 2026: 973 CVEs across Windows, Office, Azure, and server products, more than double August's count. Of those, 113 are rated Critical. Two were already being exploited in the wild when the patches shipped. CISA added both to its Known Exploited Vulnerabilities catalog the same day. The FCEB deadline is September 29, 2026.
The two zero-days to patch first
CVE-2026-85880: Windows ALPC heap buffer overflow (CVSS 7.8, EoP to SYSTEM)
A heap buffer overflow in Windows Advanced Local Procedure Call allows a local attacker to elevate privileges to SYSTEM. This is only the second ALPC zero-day patched since January 2023. Rated Important despite the CVSS 7.8 score, which reflects the local-only attack vector. In practice, local EoP to SYSTEM is a critical stepping stone in any post-exploitation chain: an attacker who lands on a machine via phishing or initial access can use this to own the endpoint before moving laterally.
CVE-2026-81963: Windows Update Stack link following (EoP, Rated Important)
An improper link resolution vulnerability in the Windows Update Stack allows a local authorized attacker to elevate privileges. This is the first Windows Update Stack EoP zero-day exploited in the wild since Microsoft began tracking the class in 2022. Seven Windows Update Stack EoP patches have shipped across Patch Tuesday releases since then; this is the first to carry confirmed in-the-wild exploitation. The Windows Update Stack runs in a privileged context by design, making EoP via this path particularly severe in terms of post-exploitation capability.
How to prioritize 973 CVEs
The scale is disorienting but the triage logic is straightforward. Patch in this order:
- CVE-2026-85880 and CVE-2026-81963: both actively exploited, both EoP, both on KEV. These go in the next maintenance window or emergency change if your environment is exposed to untrusted code execution.
- The 20 wormable bugs in this release: Security Affairs identified 20 vulnerabilities with wormable potential. Cross-reference your Tenable or Rapid7 scan results for these CVE IDs and prioritize internet-facing or network-accessible Windows systems.
- Critical RCE in internet-facing components: 258 RCE patches shipped. Filter for Critical-rated RCE affecting Exchange, SharePoint, IIS, Remote Desktop, or any service with external exposure. These are your next tier.
- Everything else: schedule normally through your standard monthly patch cycle. The 437 EoP patches outside the zero-days are generally Important-rated and require local access. They matter for defense-in-depth but are not emergency patches absent specific threat intelligence.
What the record count means
973 CVEs in a single Patch Tuesday is a record, but the number itself is less important than the distribution. Microsoft has been accelerating its vulnerability disclosure cadence and grouping more CVEs per product under a single advisory cycle. A higher CVE count does not necessarily mean a proportionally higher risk surface if the risk distribution is similar to previous months. What matters this month is the same as every month: are any of the actively exploited or wormable bugs in your environment, and are they patched? The answer to the first question is almost certainly yes for most Windows environments.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help triaging this month's Patch Tuesday for your environment.