September Patch Tuesday: Two Zero-Days, and a Number Nobody Agrees On
Security / news
September Patch Tuesday: Two Zero-Days, and a Number Nobody Agrees On
Six publishers reported six different CVE totals for the same release. The two flaws under active attack score 7.8, and the 9.8 is not among them.
Microsoft released fixes on Sept. 8 for two Windows vulnerabilities that attackers are already using, and CISA added both to its Known Exploited Vulnerabilities catalog the same day, setting a remediation deadline of Sept. 22 for federal agencies.
Both flaws carry a CVSS score of 7.8. Microsoft rates each of them Important, not Critical.
The two bugs under active attack
CVE-2026-81963 affects the Windows Update Stack. Microsoft's advisory text describes it as "improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally." Tenable said a successful attack lets an intruder "elevate to SYSTEM privileges." Microsoft credits Romain Deperne and its own Threat Intelligence Centre with the report.
CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call. Microsoft's text says the flaw "allows an authorized attacker to elevate privileges locally." The credit line names Volexity, Mark Kelly, David Galazin and Jeremy Hedges of Proofpoint.
Neither bug gets an attacker onto a machine. Both turn a foothold into control of it, which is why they show up in the second stage of an intrusion rather than the first.
The 9.8 is not the one being exploited
The highest-scoring flaw in the release is CVE-2026-69730, a use-after-free in Windows DNS Server that Tenable puts at CVSS 9.8 and rates Critical, with Microsoft's exploitability index at "Exploitation More Likely." It is not in the KEV catalog. Neither is CVE-2026-69676, a Windows Kerberos remote code execution flaw at CVSS 8.8.
That inversion is the operational point. A team patching in CVSS order would install the DNS fix first and the two bugs under active attack later. CISA's deadline runs the other way.
Six publishers, six totals
The size of the release is where the reporting stops agreeing.
BleepingComputer put the count at 966 flaws with 105 rated Critical, and broke it down as 438 elevation of privilege, 258 remote code execution, 173 information disclosure, 56 denial of service, 19 security feature bypass and 16 spoofing. Tenable, publishing the same day, counted 964 CVEs with 104 Critical and 860 Important.
A search on Sept. 10 returned four more headlines on the same release citing 973, 974, 1,169 and 1,186 CVEs, from Cybersecurity News, The Cyber Express, Senserva and a post on DEV Community.
Neither BleepingComputer nor Tenable states its counting method. The gap between the totals is the sort of thing that gets decided by whether Chromium, Mariner and other republished third-party advisories are folded in, but no publisher in this set says which it did.
For anyone using the headline figure to size a patch window, the number is not a measurement. It is a house convention.
What the deadline actually requires
CISA listed both zero-days on Sept. 8 under Binding Operational Directive 26-04, with remediation due Sept. 22. The catalog entry for CVE-2026-81963 is titled "Microsoft Windows Link Following Vulnerability" and the entry for CVE-2026-85880 is "Microsoft Windows Heap-Based Buffer Overflow Vulnerability." Both are marked "Unknown" for known ransomware campaign use.
The directive binds federal civilian agencies. For everyone else the catalog is the cheaper signal to follow, because it reports what is being exploited rather than what could be.
Version 2026.09.09 of the KEV catalog carries 1,703 entries.
For the wider pattern of vendors choosing which numbers to publish, see our analysis of Intel's Crescent Island disclosure and the vendor-supplied benchmark scores behind GPT-6 Astra.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.