Microsoft’s September 2026 Patch Tuesday addresses 973 vulnerabilities, with 113 rated critical and two already exploited in the wild, according to Cisco Talos. The massive update arrives amid a broader surge in security patches driven by automated vulnerability discovery tools.
Microsoft released its September 2026 Patch Tuesday updates, deploying fixes for a 973 vulnerabilities across its software ecosystem. Among the hundreds of fixes, 113 are rated critical, with remote code execution flaws dominating the highest-severity tiers. Cisco Talos reported that two of the targeted security holes are already being exploited by attackers in real-world attacks. This month’s total of 973 vulnerabilities is a sharp increase from the 163 flaws Microsoft fixed in its April 2026 Patch Tuesday, as previously reported.
Active Zero-Day Exploits Target Windows Update Stack and ALPC
The actively exploited flaws are CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, both carrying a CVSS score of 7.8.
Critical Remote Code Execution Flaws and High-Severity CVEs
Among the critical issues, 82 are remote code execution vulnerabilities. Several are rated 9.8 on the CVSS scale, including flaws in Windows DNS Server (CVE-2026-69730), Windows DHCP Server (CVE-2026-69845 and CVE-2026-72979), Skype for Business (CVE-2026-66302), Windows Imaging Component (CVE-2026-70296), Windows RRAS (CVE-2026-69590), Windows SSTP (CVE-2026-73009), Microsoft Failover Cluster (CVE-2026-73010), and Windows Graphics Component (CVE-2026-77493). Other notable fixes include a CVSS 9.0 elevation of privilege in Spring Cloud Azure (CVE-2026-69854) and a CVSS 9.6 SQL Server elevation of privilege (CVE-2026-65669). Azure Cosmos DB spoofing (CVE-2026-69857) and Windows Kerberos RCE (CVE-2026-69676) were also patched.
The release also covers multiple remote code execution flaws in Microsoft Excel (CVE-2026-81948, CVE-2026-81950, CVE-2026-81951, CVE-2026-81959, CVE-2026-81953) and an Outlook RCE (CVE-2026-78525). Additional fixes span Windows RRAS, RMCAST, DirectWrite, IP Helper, Media Foundation, Graphics Kernel, and other components.
AI-Driven Vulnerability Discovery Supercharges Patch Volumes
The sheer scale of the September release reflects a broader shift across the cybersecurity industry. Sources familiar with Microsoft’s security operations indicate that the rapid increase in monthly patches is directly tied to automated security-focused AI models that are discovering flaws at an unprecedented pace. The company’s own AI system, MDASH, had identified 16 Windows vulnerabilities that were fixed in the May 2026 Patch Tuesday.

Earlier in the year, AI models developed by firms like Anthropic and OpenAI demonstrated the capability to find deep-seated weaknesses in major operating systems and web browsers within hours rather than weeks. Sources tell me that Microsoft will set another patch Tuesday record today, the third in just a few months. Microsoft typically patches around 100 flaws every month, but in June it set a new record of around 200 fixes. July’s patch Tuesday was even bigger, with Microsoft patching at least 570 security holes, almost triple the number of June’s record-breaking release. Microsoft engineers had a chance to catch their breath a bit in August when they plugged nearly 400 security vulnerabilities.
The Growing Patch Gap and Pressure on IT Teams
The rapid influx of hundreds of monthly security updates places immense strain on corporate IT departments. Enterprise administrators must thoroughly test patches before deployment to ensure updates do not disrupt internal business applications, creating a dangerous window known as the patch gap. IT admins typically have to test patches from Microsoft to ensure any fixes don’t interfere with critical business applications. This process can create what’s called a “patch gap” between a vulnerability being disclosed and people applying the fix. In an AI era of security vulnerabilities being rapidly discovered and disclosed, there’s a huge amount of pressure on businesses to close the patch gap. Anthropic discovered earlier this year that Mythos could even create working exploits for newly disclosed software vulnerabilities in a matter of hours, instead of weeks. This puts businesses at risk of being hit by an exploit if they don’t patch soon enough.

As automated tools continue to uncover vulnerabilities faster than traditional deployment cycles can easily accommodate, security experts urge organizations to streamline their testing processes and apply critical updates immediately to mitigate the risk of active exploitation. When hundreds of vulnerabilities are now being discovered every month, time is very much of the essence.
Читайте также

