Microsoft September 2026 Patch Fixes Record 972 Flaws, 112 Critical
Microsoft's September 2026 update fixes about 972 flaws, including 112 critical bugs, two exploited zero days and at least 20 wormable threats this month.
Summary
Microsoft's September 8, 2026 release fixes roughly 972 vulnerabilities, or 997 when including Chromium fixes ported into Edge. Exact totals vary because some bugs were previously addressed or affect non Microsoft products. Dustin Childs of the Zero Day Initiative counted 112 critical flaws, with the rest rated important. Microsoft has fixed 2,760 vulnerabilities this year, more than twice 2025's total, following records of 570 in July and about 620 in August. At this pace, 2026 will exceed 2023, 2024 and 2025 combined.
Two exploited Windows zero days, CVE-2026-81963 in Windows Update and CVE-2026-85880 in Windows Advanced Local Procedure, have unknown attackers and reach. CVE-2026-55007 lets an unauthenticated attacker compromise Exchange Server by emailing a malicious Visio attachment. CVE-2026-80097 elevates privileges through Microsoft Authenticator. CVE-2026-69465 covers roughly 17 SharePoint code execution flaws. CVE-2026-65669 is among 60 SQL Server privilege escalation bugs and is triggered through SQL Copilot. Remote Desktop Services flaw CVE-2026-69525 enables remote code execution and scores 9.8. Childs stopped counting wormable flaws at 20, meaning they need no user interaction and can spread between machines.
Two weeks earlier, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and 100 companies and organizations warned that AI enabled attacks could outrun patching. Childs calls record patch volumes the new normal but sees no corresponding exploit surge yet. Critics cite AI hunting costs, false positives and vendor incentives after billions in investment, while Mozilla said Mythos found 271 vulnerabilities in May with almost no false positives. Long term effectiveness may take at least a year to establish.
Positives
- Roughly 972 vulnerabilities were fixed, rising to 997 when Chromium patches ported into Edge are counted.
- Microsoft patched 112 critical flaws alongside hundreds rated important in its September 8, 2026 release.
- Microsoft has fixed 2,760 vulnerabilities in 2026, more than twice its total for 2025.
- Mozilla's Mythos found 271 vulnerabilities in May with almost no false positives.
- No corresponding surge in active exploitation has appeared yet despite record vulnerability discovery, Dustin Childs said.
Risks & concerns
- Two Windows zero days, CVE-2026-81963 and CVE-2026-85880, are being exploited, with their attackers and reach unknown.
- At least 20 flaws are wormable, requiring no user interaction and potentially spreading autonomously between machines.
- CVE-2026-55007 can compromise Exchange Server when an attacker sends an email containing a malicious Visio attachment.
- Remote Desktop Services flaw CVE-2026-69525 enables remote code execution and carries a 9.8 severity score.
- AI enabled attacks may exploit vulnerabilities before organizations patch them, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and others warned.