Microsoft's Record 966-Fix Patch Tuesday Has Two Exploited Bugs, Both Local
Security / news
Microsoft's Record 966-Fix Patch Tuesday Has Two Exploited Bugs, Both Local
The count differs by outlet, but the operational risk sits in 20 wormable remote code execution flaws.

Microsoft's September 8 security release fixed 966 flaws, according to BleepingComputer, the largest single Patch Tuesday the company has shipped. Only two were known to be exploited, and both need local access. The number that matters to administrators is smaller than the headline: 20 of the bugs are remote code execution flaws that need no login and no user click.
That last figure comes from Dustin Childs of the Zero Day Initiative, as SecurityWeek quoted it: "20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction."

Why every outlet reports a different total
Four outlets counted the same release and got four totals.
| Source | Count reported |
|---|---|
| Tenable | 964 CVEs |
| BleepingComputer | 966 flaws |
| SecurityWeek | 974 vulnerabilities |
| Zero Day Initiative | 997 CVEs, counting 972 new Microsoft CVEs plus external and Chromium bugs |
The gaps come from what each outlet includes. Tenable counts Microsoft's own CVEs. The Zero Day Initiative's review adds third-party and Chromium fixes that Microsoft ships in the same cycle. None of the four articles fully explains its own method, so treat any single number as approximate and use the two-zero-day count, which every outlet agrees on.
- August400 flaws
- July570 flaws
- September966 flaws
Source: BleepingComputer, September 2026 Patch Tuesday report, accessed 2026-09-28
BleepingComputer puts July at 570 and August at 400. September is therefore 1.7 times July, the previous high.
The two exploited bugs are local
Both zero-days score 7.8 on CVSS and give an attacker who already runs code on a machine SYSTEM privileges. Neither is a way in.
| CVE | Component | Bug class |
|---|---|---|
| CVE-2026-81963 | Windows Update Stack | Improper link resolution before file access, known as link following |
| CVE-2026-85880 | Windows ALPC | Heap-based buffer overflow in the Advanced Local Procedure Call component |
Tenable notes that Microsoft says CVE-2026-81963 is the first of seven similar Update Stack flaws patched since 2022 to be exploited as a zero-day. It describes CVE-2026-85880 as the first ALPC bug in a Patch Tuesday in more than three years. SecurityWeek quotes Tenable's Satnam Narang saying ALPC has had a second zero-day resolved "in nearly four years". Neither source says who exploited either flaw, or against whom.
What the 20 wormable bugs change
The Zero Day Initiative treats wormable as a separate class: remote code execution with no authentication and no interaction. Tenable singles out CVE-2026-69730, a Windows DNS remote code execution flaw rated 9.8, which Microsoft marks "Exploitation More Likely". It also lists CVE-2026-69676, a Windows Kerberos remote code execution flaw at 8.8.
The scale of the release comes, per BleepingComputer, from Microsoft's use of "an AI-powered vulnerability discovery system". Narang, the Tenable researcher SecurityWeek quotes, put it this way: "AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but isn't finding more needles."
BleepingComputer breaks the release down as 438 elevation of privilege, 258 remote code execution, 173 information disclosure, 56 denial of service, 19 security feature bypass and 16 spoofing. Of the 105 rated Critical, 81 are remote code execution.
What to do first
Prioritise by exposure, not by count. Domain controllers and DNS servers come first because of CVE-2026-69730. Then patch the two exploited local bugs on every endpoint, because they are the only ones with confirmed attacks. Everything else can follow the normal ring schedule.
For comparison with a much smaller, older story, see this site's coverage of the Siemens Keycloak password-reset flaw and the LuaRocks sandbox escape.
Microsoft's next scheduled release is the October Patch Tuesday. Whether it repeats September's volume will show whether the AI-driven discovery is a one-off backlog or a new baseline.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.