News

Microsoft Patch Tuesday hits record 974 CVEs

Microsoft published 974 own-product CVEs on 8 September 2026 Patch Tuesday, including 723 in Windows. Rapid7 counts 999 with 25 non-Microsoft CVEs. Two exploited EoP zero-days, CVE-2026-85880 and CVE-2026-81963, carry a 22 September federal KEV deadline in The Register's reporting.

Microsoft Patch Tuesday hits record 974 CVEs

Rapid7's September 2026 Patch Tuesday analysis says Microsoft published 974 own-product CVEs on 8 September 2026, including 723 in Windows. With 25 non-Microsoft CVEs, Rapid7 puts 999 vulnerabilities on the table. SecurityWeek also leads on 974.

This is Microsoft's September 2026 security update release, as counted by Rapid7 and SecurityWeek against Microsoft's CVE advisories. Whether it is a record depends on the count. 974 is own-product. 999 includes third-party CVEs.

Two elevation-of-privilege bugs are already exploited in the wild. CVE-2026-85880 is a Windows ALPC heap-based buffer overflow to SYSTEM, marked Exploitation Detected. SecurityWeek quotes Microsoft: a low-privilege AppContainer attacker can escape the sandbox and elevate locally with no extra user interaction. Rapid7 reads the patch matrix as giving Server 2025 and Windows 11 no patch for this CVE, which is Rapid7's inference rather than a named Microsoft statement.

CVE-2026-81963 is a Windows Update Stack improper link resolution EoP to SYSTEM. Rapid7 says all supported Windows versions get a patch. Microsoft has not named the actor behind either zero-day.

CISA added both Microsoft bugs to the Known Exploited Vulnerabilities catalog on 8 September. The Register reports a 22 September 2026 federal remediation deadline for those two.

SecurityWeek, citing ZDI's Dustin Childs, puts about 20 of the fixes in the wormable RCE class. Rapid7 flags Windows DNS Server CVE-2026-69730 at CVSS 9.8 (Exploitation More Likely) and Exchange Server CVE-2026-55007 as an RCE often called out in the same pile.

Enterprise patch volume this week also includes SAP's CVSS 10 OVERPASS note, ConnectWise's ScreenConnect file transfer advisory, and F5 BIG-IP memory webshell reporting.

Patch CVE-2026-85880 and CVE-2026-81963 on every still-supported build that receives them before the 22 September federal KEV deadline, then prioritize wormable RCEs such as DNS CVE-2026-69730 and Exchange CVE-2026-55007 ahead of the long tail of 974.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free