Microsoft on September 8, 2026 delivered its Patch Tuesday batch, closing out 974 vulnerabilities across Windows, Office, SQL Server, Exchange, SharePoint, Azure, and developer tools. Included are two zero-day threats already under active exploitation—making this release especially critical. Microsoft urged organizations to apply fixes across all relevant endpoints, servers, and enterprise applications.
Zero-Days Under Threat
The first zero-day, CVE-2026-85880, exploits the Windows Advanced Local Procedure Call (ALPC) mechanism to elevate privileges. Despite being rated “Important,” its confirmed exploitation demands immediate attention. The second, CVE-2026-81963, is a privilege-escalation flaw in the Windows Update Stack tied to improper link resolution before file access (known as link following), also confirmed as exploited. These vulnerabilities are not publicly disclosed in full but flagged as exploited—often a sign of private, active attacks.
What Else Is at Risk
A broad set of critical and important vulnerabilities beyond the zero-days are included this month. In Windows, three “Critical” bugs require customer action: CVE-2026-83939 (affecting Secure Kernel Mode), CVE-2026-83498 (impacting Virtualization-Based Security Enclave privileges), and CVE-2026-83501 (an information disclosure issue). Office apps also receive urgent updates for remote code execution risks, with multiple vulnerabilities in Excel and Word. Windows Print Spooler, Remote Desktop Client, Message Queuing, and more receive important fixes for remote code execution and elevation-of-privilege.
Other less-obvious areas, such as Windows Biometric Service, NTFS, Error Reporting, and the Resilient File System’s Deduplication Service are also patched, emphasizing the depth of this update. Additional vulnerabilities address availability and integrity issues—such as denial of service bugs in Services for NFS ONCRPC, tampering in Cloud Files Mini Filter driver, and spoofing in MSAL for Node.js and remote code execution in Azure CLI.
Microsoft clarifies that Windows 10 and 11 updates are cumulative. Administrators are advised to install the latest servicing-stack updates and pay attention to known issues for Exchange, SQL Server, and Windows Server before deploying widely. Using representative test groups and staged deployments—such as via Intune update rings with deadlines and restart control—is strongly recommended.
This release breaks down as follows: 723 issues in Windows, 111 in Office, 62 in SQL Server, 22 in developer tools, 16 in SharePoint Server, and 9 in Exchange. In addition, 25 republished non-Microsoft CVEs are listed separately and do not count toward the 974 Microsoft-specific vulnerabilities.
Analysts flag one under-appreciated risk: sticking to only “Critical” patches is no longer sufficient. Zero-days and serious “Important”-rated flaws are present in this update, underscoring the need for broad, rapid remediation across all layers, not just the most glaring threats.