# Microsoft's September 2026 Patch Tuesday: A Record-Breaking Security Update

*Published September 9, 2026*
*Source: [https://cybersecuritynews.com/microsoft-patch-tuesday-update-september-2026/](https://cybersecuritynews.com/microsoft-patch-tuesday-update-september-2026/)*

## Executive Summary

Microsoft's September 2026 Patch Tuesday has addressed 973 vulnerabilities, including two zero-days that have been actively exploited. This record-breaking update requires coordinated remediation across a wide range of Microsoft products.

## Article

Microsoft has released its most extensive Patch Tuesday to date for September 2026, addressing a staggering 973 vulnerabilities across its software ecosystem. This includes two zero-day vulnerabilities that have already been actively exploited in attacks. The significant update covers a wide range of Microsoft products such as Windows, Office, SQL Server, Exchange, SharePoint, Azure, and various developer tools, necessitating a coordinated remediation effort across different organizational environments.

Of the total vulnerabilities addressed, 723 are attributed to Windows alone. Elevation of Privilege vulnerabilities account for nearly half of the issues, followed closely by Remote Code Execution flaws. The first zero-day, CVE-2026-85880, affects Windows Advanced Local Procedure Call and allows privilege escalation. The second, CVE-2026-81963, impacts the Windows Update Stack, enabling an attacker to elevate privileges locally. Both flaws are rated as Important and require immediate action from users to mitigate potential risks.

Critical vulnerabilities have also been identified in Windows security components such as Secure Kernel Mode and Virtualization-Based Security Enclaves. Microsoft Office applications, notably Word and Excel, have received several critical patches for remote code execution flaws, which could be exploited through malicious documents. These updates highlight the need for organizations to assess Office products separately from Windows updates.

Additionally, the update addresses vulnerabilities in crucial infrastructure services like SQL Server and Windows DHCP Server, as well as in developer environments, including spoofing in the Microsoft Authentication Library for Node.js. Administrators are advised to follow Microsoft’s release guidance, install the latest servicing stack updates, and use test groups to ensure smooth deployment. Organizations with extensive deployments of SQL Server, DHCP Server, or biometric authentication systems should prioritize testing and deployment for these particular patches.
