Microsoft patches recorded 974 vulnerabilities, including two exploited zero days

On Tuesday, Microsoft released a record number of patches, fixing 974 CVEs in its products, including two vulnerabilities exploited in the wild as zero-days.

The first exploited zero day, CVE-2026-85880is a stack buffer overflow issue in Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain system privileges.

“An attacker who could execute code in a low-privileged AppContainer could exploit this vulnerability locally to escape the sandbox and elevate the privileges of the affected system. No additional user interaction is required,” Microsoft notes in its consultative.

Microsoft hasn’t patched a flaw in ALPC since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, following CVE-2023-21674 in January 2023, according to Tenable senior research engineer Satnam Narang.

The second zero day, CVE-2026-81963is an improperly resolving a connection before accessing a file (“connection tracking”) flaw in the Windows Update Stack, the components used to install a Windows update. The vulnerability also allows local attackers to elevate their privileges to System.

As Narang notes, this is the first Update Stack security weakness marked as a zero-day of the seven vulnerabilities resolved in the component over the past five years.

Advertising. Scroll to continue reading.

In total, Microsoft patched 723 Windows vulnerabilities and fixed 222 security bugs in its Office suite, including 111 in Office 2016 for this month’s Patch Tuesday. Multiple security issues were also addressed in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9).

Also as part of September 2026 Tuesday patch updatesMicrosoft has released new Service Stack Updates (SSUs) that are classified as critical updates. They apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 version 1607/Server 2016.

Some of the issues of particular note include CVE-2026-55007 (Remote Code Execution (RCE) in Exchange Server), CVE-2026-80097 (Elevation of Privilege (EoP) in Authenticator), CVE-2026-69465 (RCE in SharePoint, CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), Dustin Childs of ZDI says.

According to Childs, 20 of the newly resolved vulnerabilities can be considered harmful because they allow RCE without authentication or user interaction.

“One of the most important things to recognize with the recent spike in Tuesday releases is that while the number of vulnerabilities being patched is increasing, the number of vulnerabilities that can and will affect most organizations remains fairly low,” Narang said.

“AI-assisted vulnerability discovery in 2026 is creating bigger haystacks but not finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being accessible and exploitable, and prioritizing remediation based on that risk context,” he added.

According to Fortra associate director Tyler Reguli, the high number of newly released patches, which is not a Microsoft-specific trend, indicates that proactive vendors are looking to reduce the attack surface.

“Eventually, all of these long-standing, hard-to-find vulnerabilities will be patched and Patch Tuesday will return to its typical rhythm. Until that happens, prioritization is key, and extra coffee gift cards for your admins will probably be appreciated,” Reguly said.

Related: Adobe has patched over 170 vulnerabilities, including Commerce Zero-Day

Related: The hidden instructions that can hijack AI agents

Related: SAP fixes a critical vulnerability in extended passport processing

Related: MikroTik fixes critical vulnerabilities related to hacking routers

Leave a Reply

Your email address will not be published. Required fields are marked *