Microsoft Sets Patch Record with 974 September Fixes

Microsoft Sets Patch Record with 974 September Fixes

Microsoft's September 2026 Patch Tuesday delivered a record 974 fixes, including two actively exploited zero-day flaws in Windows.

Microsoft's September 2026 Patch Tuesday release fixed at least 974 vulnerabilities across Windows and other software, the company's largest single update batch ever, according to reporting by KrebsOnSecurity. The company says artificial intelligence is helping to speed the discovery of flaws, but security experts warn that many organizations are already struggling to test and deploy so many fixes each month.

The release far exceeds Microsoft's previous record of at least 570 vulnerabilities fixed in July, and pushes the 2026 total to more than 2,600. That is more than twice the previous record-setting year of 1,245 in 2020, and there are still three months left in the year.

Two of the flaws fixed this month are zero-day vulnerabilities, meaning attackers are already using them before a patch was available. Both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on a Windows system, essentially gaining higher access rights than they should have. Microsoft rated 113 of the bugs as critical, the severity level for flaws that could let malware or attackers take over a vulnerable machine with little or no action from the user.

Among the most serious is CVE-2026-69730, a DNS flaw in Windows Server 2012 and later, as well as Windows 10. Microsoft warns that an unauthenticated attacker could exploit it simply by sending a specially crafted packet to an affected system, and that exploitation is likely. DNS, the domain name system, is the internet service that translates human-friendly names like example.com into the numeric addresses computers use to reach each other. A second critical issue, CVE-2026-69829, is a remote code execution flaw in Windows Shell, the part of Windows that provides the desktop and file explorer experience. It carries a CVSS severity score of 9.8 out of 10 and can be exploited with low complexity, no privileges and no user interaction.

Microsoft is not the only large vendor shipping monster patch bundles. Adobe, Cisco, Google, Mozilla and another major software vendor have all recently credited AI-assisted research with increasing their patch cadence and volume, according to the Krebs report. Google said today it is now going to ship security updates every two weeks. Tyler Reguly, associate director of security research and development at Fortra, said a core challenge is that Windows updates need to be tested before being installed across an organization because third-party software may not work seamlessly when the operating system changes. He called on chief information security officers and chief security officers to support their teams through difficult patch cycles, including rewarding after-hours and weekend work and finding budget for meals for staff deploying patches before Monday. Satnam Narang, senior staff research engineer at Tenable, cautioned that while the number of patched vulnerabilities is rising, the number that can and will affect most organizations remains quite low. He said AI-assisted discovery is creating larger haystacks but not finding more needles, and urged organizations to understand which vulnerabilities actually apply to them and prioritize based on that risk context.

For ordinary Windows users, the advice is simpler: you do not need to test patches before installing them, but you do need to open Windows Update periodically or agree to its reminder notices about pending updates. Because these update bundles are growing quickly month after month, letting them pile up creates a bigger window of exposure. Enterprise Windows administrators should watch askwoody.com for reports of updates causing problems, and the SANS Internet Storm Center offers a per-patch breakdown ordered by severity and urgency. For businesses that manage Windows servers or websites, the rising volume of patches makes patch prioritization and testing a critical operational task. AEU-I provides security-first IT and infrastructure consulting, including guidance that can help teams plan and prioritize which Microsoft updates to deploy first in their environment.

How to Protect Yourself

  1. Turn on automatic updates in Windows settings so security fixes install without you having to remember.
  2. When Windows asks to restart to finish an update, save your work and restart soon instead of delaying it for weeks.
  3. Avoid opening email attachments or links from unknown senders because some of these flaws could let attackers take over a computer through tricked files.
  4. Use a standard Windows account for daily work instead of an administrator account (which has full control over the computer).
  5. If you run a website on Windows hosting, ask your hosting provider whether the server has installed the latest Microsoft security updates.

Vulnerabilities & Fixes

  • CVE-2026-69730 A DNS weakness in Windows Server 2012 onward and Windows 10 that an unauthenticated attacker can trigger by sending a specially crafted packet; Microsoft says exploitation is likely and it is fixed this month. View the fix & details →
  • CVE-2026-69829 A critical remote code execution flaw in Windows Shell with a CVSS base score of 9.8 that can be exploited with low complexity, no privileges and no user interaction; fixed this month. View the fix & details →
  • CVE-2026-81963 A zero-day vulnerability actively exploited before the patch; it allows an attacker to elevate privileges on a Windows system and is fixed in this September 2026 update. View the fix & details →
  • CVE-2026-85880 A zero-day vulnerability actively exploited before the patch; it allows an attacker to elevate privileges on a Windows system and is fixed in this September 2026 update. View the fix & details →

Terms Explained

  • Patch Tuesday The monthly day when Microsoft releases security updates for its software.
  • Zero-day A security hole that attackers are already using before the software maker has released a fix.
  • Privilege elevation A type of flaw that lets an attacker gain higher access rights on a computer, such as administrator control.
  • Remote code execution A type of flaw that lets an attacker run their own commands or programs on a target computer from afar.
  • DNS The internet system that turns website names into numeric addresses computers use to connect to each other.
  • CVSS A scoring system that rates how severe a security flaw is from 0 to 10, with 10 being the most severe.
  • Windows Shell The part of Windows that provides the desktop, taskbar and file management experience.

Related AEU services

  • AEU-I IT and security consulting