Record-Breaking Patch Tuesday: Microsoft Fixes 966 Flaws Including Two Active Exploits

Microsoft's September 2026 Patch Tuesday is its largest ever, resolving 966 vulnerabilities, with 105 critical and two zero-days actively exploited. The zero-days include a Windows Update Stack elevation of privilege flaw. The surge is attributed to Microsoft's AI-powered vulnerability discovery system.
The September release includes 105 critical flaws, with remote code execution dominating that tier. Microsoft attributes the unprecedented volume to its new AI-driven discovery tool, which has outpaced recent monthly totals (570 in July, 400 in August). Additionally, 204 separate vulnerabilities were patched earlier in the month across Azure and Edge products.
The two actively exploited flaws both enable local privilege escalation to SYSTEM, one via a link-following issue in the Update Stack and the other via a heap overflow in ALPC. Beyond Microsoft, Adobe addressed an exploited Commerce backdoor, while Cisco, ConnectWise, and CrowdStrike issued advisories or mitigations for their own products.
The sheer volume of fixes could overwhelm enterprise IT teams, potentially delaying deployment and leaving systems exposed to the actively exploited zero-days. These flaws may allow attackers to gain SYSTEM privileges on unpatched Windows devices, increasing the risk of data breaches or ransomware. Microsoft's AI-driven discovery may also signal a new normal, forcing organizations to adopt more automated patch management to keep pace with an accelerating vulnerability landscape.