Microsoft released fixes for 974 unique vulnerabilities in its scheduled security update for September, which until recently would have represented a full year’s worth of CVEs.
Of these, the highest-priority vulnerabilities include two that are already under active exploitation. Additionally, Microsoft rated 13 flaws as "Critical" and 58 it deemed as bugs that attackers are more likely to exploit for different reasons, including low attack complexity and high impact.
Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each. The remaining vulnerabilities were spread across other Microsoft technologies, including 62 in SQL, 22 in Developer Tools, 16 in SharePoint Server, and 12 in Azure. This month's release follows a recent trend of increasingly large and record-setting volumes of CVEs for the software giant's Patch Tuesday.
An Overabundance of Elevation of Privilege Flaws
As has been the pattern in recent months, a plurality of the bugs — about 45%, or 438 — were elevation-of-privilege (EoP) vulnerabilities that can, in many cases, enable attackers to gain administrator- or system-level access to compromised systems. Another 25%, or 260, were remote code execution (RCE) flaws, while about 18%, or 175, involved information disclosure.
Related:AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are CVE-2026-85880 (CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963 (CVSS 7.8), another EoP flaw this time in Windows Update Stack. Both vulnerabilities allow an attacker who already has gained access to a vulnerable system to achieve SYSTEM-level privileges.
Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, pointed to CVE-2026-69380 (CVSS:8.1), a Microsoft Exchange Server EoP, as another vulnerability that organizations should patch immediately, because it "allows low-privileged attackers to impersonate any user and hijack every mailbox in the organization."
A Cluster of Wormable CVEs
Also of high priority in Microsoft's September Patch Tuesday are a cluster of 20 wormable CVEs, Childs warned in an emailed statement. The bugs enable an unauthenticated remote attacker to execute arbitrary code on vulnerable systems. The "zero-click RCE bugs — headlined by a Windows DNS Server flaw (CVE-2026-69730 CVSS:9.8) acting as SigRed’s spiritual successor — creates severe, self-propagating contagion risk across enterprise networks," he wrote.
... continue reading