Published September 12, 2026 — Redmond, Washington. Microsoft's September 2026 Patch Tuesday broke the all-time record with ~960-974 CVEs (counts vary by source), including two Windows zero-days already exploited in the wild. CISA added both zero-days to the Known Exploited Vulnerabilities catalog the same day the patches shipped. Federal agencies have until September 22, 2026 to apply the fixes.
Data last verified September 12, 2026 from the Microsoft Security Response Center (MSRC) September 2026 release notes, CISA Known Exploited Vulnerabilities catalog, and Expel's Patch Tuesday analysis (September 9, 2026).
Quick Answer
Microsoft's September 2026 Patch Tuesday shipped a record-breaking ~960-974 CVEs (Expel: 964, Register: 974, BleepingComputer: 966). Of these, 104 are rated Critical and 860 Important. Two Windows zero-days were already exploited: CVE-2026-81963 (Windows Update Stack EoP, Win11/Server 2025; CVSS 7.8) and CVE-2026-85880 (Windows ALPC AppContainer sandbox escape; CVSS 7.8). CISA added both to the Known Exploited Vulnerabilities catalog on September 8, 2026. FCEB deadline: September 22 (Microsoft MSRC, September 8, 2026; CISA KEV catalog, September 8, 2026).
September 2026 Patch Tuesday at a glance
| Metric | September 2026 | August 2026 | July 2026 (prior record) |
|---|---|---|---|
| Total CVEs | ~960–974 | 421 | 622 |
| Critical-rated | 104 | ~38 | ~62 |
| Important-rated | 860 | ~383 | ~560 |
| Zero-days (pre-patch exploit) | 2 (Microsoft) + 1 (Adobe) | 2 | 1 |
| Elevation of Privilege % | 44.7% | ~40% | ~38% |
| Remote Code Execution % | 26.8% | ~28% | ~30% |
Source: Microsoft MSRC (September 8, 2026); Expel Patch Tuesday analysis (September 9, 2026); The Register (September 9, 2026).
The two exploited Windows zero-days
Microsoft classified two CVEs as actively exploited before the September 8 fix shipped. Both are elevation-of-privilege vulnerabilities with CVSS 7.8, but they target fundamentally different Windows subsystems:
| CVE | Component | Affected versions | CVSS | Vector | KEV deadline |
|---|---|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Windows 11, Windows Server 2025 | 7.8 | Link-following → SYSTEM | Sep 22, 2026 |
| CVE-2026-85880 | Windows ALPC | Windows 10, multiple Server versions | 7.8 | AppContainer sandbox escape → SYSTEM | Sep 22, 2026 |
Source: Microsoft MSRC September 2026 Security Updates (September 8, 2026); CISA Known Exploited Vulnerabilities catalog (September 8, 2026).
CVE-2026-81963 — Windows Update Stack EoP
This is a link-following flaw in the Windows Update Stack that allows an attacker to gain SYSTEM-level access from any user context. Exploitation requires local code execution but no user interaction. The flaw affects the latest Windows 11 builds and Windows Server 2025. Microsoft's guidance: install the September 2026 cumulative update immediately; no mitigation available beyond patching (Microsoft MSRC, September 8, 2026).
CVE-2026-85880 — Windows ALPC EoP
This is an AppContainer sandbox escape in the Windows Advanced Local Procedure Call subsystem. An attacker running code in a low-privilege AppContainer — the default sandbox for browser tabs, document viewers, and UWP apps — can break out and elevate to SYSTEM. This makes CVE-2026-85880 a natural second-stage exploit for any sandbox-escape initial-access path, including browser exploits, document exploits, and Office macro attacks. It hits a much wider spread of Windows versions than CVE-2026-81963, including Windows 10 and older Windows Server versions (Microsoft MSRC, September 8, 2026; CISA KEV, September 8, 2026).
Adobe's record-breaking Patch Tuesday release
Alongside Microsoft, Adobe released 10 bulletins addressing 172 CVEs on September 8, 2026. The headline: CVE-2026-75650 (CVSS 10.0), dubbed StyleSmuggler by Sansec, an unauthenticated RCE in Adobe Commerce and Magento Open Source that has been exploited in the wild since September 4, 2026. Adobe also shipped the September Commerce security release on September 8, but separately hotfixed StyleSmuggler (VULN-39341) on September 5 — three days before the standard release — and required customers to apply both the hotfix and the September updates, plus rotate encryption keys. CISA added CVE-2026-75650 to the KEV with a September 11, 2026 FCEB deadline (Adobe Security Bulletin APSB26-146, September 8, 2026).
Patching priority framework
With ~960 CVEs to address, IT teams need a strict priority order:
- Tier 1 (this week): CVE-2026-81963 and CVE-2026-85880 (Windows zero-days, KEV, Sep 22 FCEB deadline). Adobe CVE-2026-75650 (Magento StyleSmuggler, Sep 11 FCEB deadline).
- Tier 2 (next 30 days): Critical-rated CVEs in your environment's product mix (Azure services, Exchange Server, SharePoint, Office). Microsoft Defender, Microsoft Entra ID, and Microsoft Intune are commonly exposed.
- Tier 3 (next 60 days): Important-rated EoP and RCE CVEs by exploit prediction score (EPSS). Microsoft Defender for Endpoint surfaces EPSS scores for each CVE.
- Tier 4 (next 90 days): The remaining ~860 Important CVEs in waves by criticality.
For organizations running Adobe Commerce or Magento, the StyleSmuggler hotfix + key rotation is the single most urgent action this week (Expel, September 9, 2026; Microsoft MSRC, September 8, 2026).
Why is the September volume a record?
Microsoft shipped more CVEs in September 2026 than in any prior month in the company's history. The growth reflects three forces: (1) AI-assisted vulnerability discovery is accelerating disclosure rates across the industry; (2) Microsoft's expansion of dedicated security research teams (Microsoft Security Response Center, Microsoft AI Red Team, Microsoft Defender Research) is finding more flaws in its own products; (3) the consolidation of legacy code paths as Windows 10 nears end-of-support creates a final batch of disclosed vulnerabilities in older branches. The shift is not unique to Microsoft — Oracle's October 2025 CPU, Adobe's 2026 releases, and SAP's monthly security notes have all trended upward in disclosed CVEs (Expel, September 9, 2026; The Register, September 9, 2026).
FAQ
Is the September 2026 Patch Tuesday the largest Microsoft has shipped?
Yes. With ~960-974 CVEs, September 2026 is the largest single Patch Tuesday release in Microsoft's history. The previous record was July 2026's 622 CVEs (Expel, September 9, 2026).
Do I need to patch my home Windows PC this week?
If your PC is running Windows 10 or 11, enable automatic updates and let Windows Update install the September 2026 cumulative update. The two exploited zero-days affect consumer versions of Windows, and Microsoft Defender's built-in exploit protection provides partial mitigation until the patch installs (Microsoft MSRC, September 8, 2026).
Are Macs or Linux systems affected?
No. The September 2026 Patch Tuesday zero-days are Windows-specific. macOS, iOS, Linux distributions, and Android are not affected by CVE-2026-81963 or CVE-2026-85880. Apple's iOS 27 release is scheduled for September 14, 2026 (Apple Newsroom, September 9, 2026).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









