Skip to content
vulnerabilityCVE

Microsoft Sept 2026 Patch Tuesday: 974 CVEs, Two Exploited Zero-Days

2 min read
Share

The two zero-days under active exploitation

CVE-2026-85880 (CVSS 7.8) is a heap overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem. Successful exploitation grants a locally authenticated attacker SYSTEM-level privileges. CVE-2026-81963 (CVSS 7.8) is an improper link resolution vulnerability in the Windows Update Stack that enables a sandbox escape and privilege escalation to SYSTEM. Both are confirmed exploited in the wild. CISA added both to its Known Exploited Vulnerabilities catalog and mandated federal civilian agencies patch by September 22, 2026. That deadline has now passed.

The broader critical-severity landscape

Beyond the two zero-days, this cycle includes CVSS 9.8 flaws in Remote Desktop Services, DNS Server, DHCP Server, and Services for NFS, along with a heap overflow in Windows Shell. An SQL Server injection vulnerability carries CVSS 9.6. A Microsoft Authenticator improper authentication flaw (CVSS 8.6) adds risk for organizations using Microsoft's own MFA tooling. The RDS and DNS/DHCP vulnerabilities are network-accessible with no user interaction required, meaning a compromised perimeter exposes them to remote exploitation. This is the largest single-month patch cycle in Microsoft's history at 974 total CVEs with 110+ rated critical.

Prioritization guidance

Treat CVE-2026-85880 and CVE-2026-81963 as urgent catch-up patches if not already applied. Prioritize RDS, DNS Server, DHCP Server, and Services for NFS patches next, as these are network-reachable and critical-severity. Apply the Microsoft Authenticator patch in parallel for any organization relying on Microsoft MFA. SQL Server environments should follow immediately given the CVSS 9.6 injection vulnerability. The scale of this release (974 CVEs) increases the risk of patch fatigue; use automated patching tools to ensure broad coverage rather than attempting manual triage of every vulnerability.

What to watch

Watch for proof-of-concept releases for the two zero-days, which typically follow within days of Patch Tuesday disclosures. Monitor Microsoft's Security Response Center blog for revisions to CVSS scores or exploitation status on the CVSS 9.8 network-reachable vulnerabilities. Threat intelligence vendors will publish detailed analysis of the ALPC and Update Stack zero-days within the next 48 to 72 hours.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you want to discuss this post or our security research.