Back
cybersecurity

Patch Tuesday Decoded, September 2026: A Record Release, Two Zero-Days, and a Bug That Waited Four Years

September's Patch Tuesday set a new record by every count that matters: Microsoft's own tally is 974, the number customers actually need to act on is 964. Two of them were already being exploited before the patches existed.

This is the first entry in a monthly series decoding Patch Tuesday: what the headline number actually means, which fixes were already weapons before they were patches, and what to prioritize instead of working through the list top to bottom.

The Number, and Why It Moves

Microsoft's September release lists 974 CVEs. Ten of those affect cloud services or are fixes Microsoft applies on its own infrastructure, leaving 964 that customers actually need to install, the figure Tenable and Malwarebytes both use as the operative count. Either way, it is the largest Patch Tuesday release in the program's history, more than double August's total.

Other trackers report different numbers again: ZDI counted roughly 972, and at least one automated aggregator lists 1,169. The gap is not disagreement about what shipped, it is what gets counted alongside the core Windows and Office fixes: Chromium-derived Edge patches, previously disclosed Azure and Entra fixes rolled up into the monthly tally, and how strictly a tracker defines "this month's release" versus "everything Microsoft patched in September." Pick one source, cite its methodology, and move on. Chasing an exact universal number is not where the useful information is this month.

The Two That Were Already Exploited

Both confirmed zero-days are local elevation-of-privilege bugs, meaning neither hands an attacker initial access on its own. Both matter because they are exactly what an attacker uses immediately after getting a foothold through something else, phishing, a stolen credential, a web app exploit, to turn that foothold into full SYSTEM control.

CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call, ALPC, the interprocess communication mechanism Windows components use to talk to each other. An attacker who can already run code inside a low-privilege AppContainer sandbox can use it to escape that sandbox and reach SYSTEM, with no user interaction required. Microsoft had not patched an ALPC flaw since April 2023; this is only the second ALPC zero-day the component has seen in about four years.

CVE-2026-81963 is an improper link-resolution flaw, commonly called link following, in the Windows Update Stack, the component responsible for installing updates in the first place. It also escalates a local attacker to SYSTEM. Of seven security fixes issued for the Update Stack over the past five years, this is the first one Microsoft has confirmed was exploited as a zero-day.

Both score 7.8 on CVSS, a reminder that severity scores measure technical impact, not how urgently a given organization should treat a bug. A 7.8 already being used in the wild deserves faster action than a higher-scored bug with no known exploitation.

The One Worth Reading Past the Zero-Day Label

Neither zero-day above is remote. The bug that deserves separate attention this month is CVE-2026-55007, a remote code execution flaw in Exchange Server triggered by a specially crafted Visio attachment processed during content indexing, no user interaction required. What makes it worth understanding rather than just patching on schedule is its precondition: successful exploitation requires the target server already under sustained low-memory pressure, a condition not present during normal operation. That is an unusual gate for a vulnerability to carry. It does not make the bug safe to deprioritize, since memory pressure is exactly the kind of state an attacker can sometimes induce deliberately rather than wait for, but it changes how you would go looking for exploitation attempts if you are checking logs after the fact.

Also worth flagging: CVE-2026-69730, a Windows DNS Server RCE researchers have described as a spiritual successor to SigRed, the DNS Server flaw from 2020 that was wormable at internet scale. It is one of twenty vulnerabilities in this release rated wormable, meaning reachable without authentication over the network in a way that could support self-propagating exploitation, though rated does not mean confirmed exploited.

Wormable Versus Zero-Day, and Why the Difference Matters

These two labels get used almost interchangeably in headlines and they describe different things. A zero-day is a vulnerability that was exploited, or at least publicly known, before a patch existed for it, a statement about timing and prior exposure. Wormable is a statement about mechanism: the flaw is remotely reachable without authentication in a way that, in principle, lets one successful exploitation trigger the next one automatically, the way SigRed and, before it, WannaCry's underlying SMB flaw could in theory chain from host to host with no human in the loop at each step. Neither of this month's confirmed zero-days is wormable, they are local and require an existing foothold. The wormable-rated bugs this month, including the DNS Server flaw, have not been confirmed exploited yet. A bug can be one, the other, both, or neither, and conflating them either overstates or understates what a given month's release actually contains.

A Regression That Cuts Against a Flat Rollout

On September 11, Microsoft confirmed that this same update can make Remote Desktop Services unstable across several Windows client and server versions: RDP connection failures, sign-in issues, and servers that stop responding. Microsoft has marked it mitigated, not resolved. The workaround for an already-inaccessible virtual machine is not a quick service restart, it is stopping the VM, deallocating it, and starting it again.

This is worth knowing before you patch anything, not after. A record patch count by itself is not a reason to slow down. A confirmed regression in the exact protocol many administrators use to reach the servers they are about to patch is.

What to Patch First

Given the items above, in order: the two confirmed zero-days, CVE-2026-85880 and CVE-2026-81963, since they are already in active use for privilege escalation regardless of how an attacker gets initial access. Then internet-facing remote code execution risk, Exchange Server's CVE-2026-55007 and the DNS Server flaw, since both are reachable without any foothold at all. Everything else in the 964 can follow the normal deployment cycle, with one exception: stage the rollout on jump hosts, VDI environments, and anything else that depends on Remote Desktop Services, given the regression above, rather than pushing it everywhere at once. A record-sized release does not mean a record-sized emergency across the board. It means the same handful of bugs matter as much as they always do, buried in a much longer list this time, plus one new reason to test before a full push.