# Microsoft's Record-Breaking September Patch Tuesday Fixes 966 Flaws and Two Zero-Days

> Microsoft's September 2026 Patch Tuesday fixes a record 966 vulnerabilities, including two actively exploited zero-days. Learn how to update your Windows PC now.

- Canonical URL: https://coreiten.com/en/article/microsofts-record-breaking-september-patch-tuesday-fixes-966-flaws-and-two-zero-days
- Language: en
- Section: Microsoft
- Author: Sami
- Published: 2026-09-10T10:02:06+03:00
- Modified: 2026-09-10T10:02:06+03:00
- Publisher: CoreITen (https://coreiten.com)
- Keywords: Microsoft Patch Tuesday September 2026, Windows security update, zero-day vulnerabilities, CVE-2026-81963, CVE-2026-85880, Windows Update Stack

## Summary

Microsoft's September Patch Tuesday delivered a record-breaking update fixing 966 vulnerabilities and two active zero-days, highlighting an escalating AI-driven cybersecurity arms race.

- September's release nearly doubles the previous record of flaws patched in July, driven by AI tools accelerating both vulnerability discovery and patching.
- CVE-2026-81963 is an elevation-of-privilege zero-day in the Windows Update Stack discovered by Romain Deperne and the Microsoft Threat Intelligence Centre.
- CVE-2026-85880 is a second actively exploited zero-day located in the Windows Advanced Local Procedure, found by researchers from Volexity, Proofpoint, and other contributors.
- The 966 core flaws include 438 elevation-of-privilege, 258 remote-code-execution, 173 information disclosure, 56 denial-of-service, 19 security feature bypass, and 16 spoofing vulnerabilities.
- An additional 204 vulnerabilities across other Microsoft products were also patched earlier in the month alongside the core Windows updates.

**Why it matters:** The surge to nearly 1,000 monthly fixes signals that generative AI is transforming threat discovery, threatening to render traditional Patch Tuesday models obsolete.

---

Microsoft has just released a massive, record-breaking security update for Windows users, addressing an unprecedented 966 vulnerabilities in a single rollout. With two actively exploited zero-day flaws threatening system integrity, installing this month's Patch Tuesday update is critical to protecting your PC from immediate compromise.

Security updates have been trending larger, but September's release approaches double the number of flaws patched in July, which held the previous record. This massive jump is largely driven by the integration of AI in cybersecurity. Artificial intelligence is making it easier for bad actors to develop tools to exploit vulnerabilities, while simultaneously allowing developers to find and fix them at a much faster rate.

### The Zero-Day Threats: CVE-2026-81963 and CVE-2026-85880

One of the most critical zero-days addressed this month is an elevation-of-privilege vulnerability in the Windows Update Stack. Tracked as [CVE-2026-81963](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-81963), this flaw allows attackers to gain SYSTEM privileges via improper link resolution before file access. The discovery of this bug has been attributed to researcher Romain Deperne and the Microsoft Threat Intelligence Centre.

The second zero-day, [CVE-2026-85880](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-85880), is another elevation-of-privilege vulnerability located in the Windows Advanced Local Procedure. An attacker could execute code in a low-privilege AppContainer, allowing the vulnerability to escape the sandbox and gain SYSTEM privileges locally. This flaw was discovered by Volexity, alongside Mark Kelly, David Galazin, and Jeremy Hedges with Proofpoint.

Both zero-days have been actively exploited in the wild. While Microsoft has patched the vulnerabilities, the company has not provided specific details regarding how these exploits were deployed in real-world attacks.

### Breakdown of the 966 Vulnerabilities

The sheer volume of fixes in the September 2026 Patch Tuesday highlights a broad spectrum of security risks. The 966 flaws are broken down across the following categories:

- 438 elevation-of-privilege vulnerabilities
- 258 remote-code-execution vulnerabilities
- 173 information disclosure vulnerabilities
- 56 denial-of-service vulnerabilities
- 19 security feature bypass vulnerabilities
- 16 spoofing vulnerabilities

These figures represent only the core Windows updates and do not include an additional 204 vulnerabilities across other Microsoft products that were patched earlier this month.

### How to Protect Your System Now

Because these zero-day vulnerabilities are already being exploited, it is imperative to apply the September Patch Tuesday updates immediately. While most PC users should receive these updates automatically, you can manually force the installation to ensure your system is secure.

1. Open the Start menu and select **Settings**.
2. Navigate to the **Windows Update** section.
3. Click on **Check for Windows updates** and allow the system to download the latest patches.
4. Restart your PC to fully apply the critical security fixes.

### The AI Arms Race in Cybersecurity

The staggering leap to nearly 1,000 patched vulnerabilities in a single month signals a fundamental shift in the cybersecurity landscape. This is not merely a backlog of old bugs; it is the direct result of generative AI being weaponized by threat actors and simultaneously deployed by defenders. Hackers are using advanced language models to automate the discovery of code weaknesses, forcing tech giants like Microsoft to scale up their own automated scanning and patching infrastructure.

As this AI-driven arms race accelerates, the traditional monthly Patch Tuesday model may soon become obsolete. The window between vulnerability discovery and active exploitation is shrinking rapidly, meaning users and enterprise IT administrators can no longer afford to delay updates. Moving forward, organizations will likely need to adopt continuous, automated deployment pipelines to ensure systems are not left exposed to zero-day threats for even a few hours.

## Sources

- [lifehacker.com](https://lifehacker.com/tech/microsofts-record-setting-patch-tuesday-update-fixes-nearly-1000-flaws)

## Related topics

- [zero-day vulnerabilities](https://coreiten.com/en/topic/zero-day-vulnerabilities)
