Microsoftβs September 2026 Patch Tuesday is its largest ever, fixing 966 flaws and two actively exploited zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC. The update spans major products including Windows, Office, SQL Server, Exchange Server, Entra ID, Azure services, and Microsoft Edge, with 105 Critical vulnerabilities addressed overall. #WindowsUpdateStack #WindowsALPC #EntraID #MicrosoftExchangeServer #MicrosoftOffice #SQLServer #MicrosoftEdge
Keypoints
- Microsoft patched a record 966 vulnerabilities in the September 2026 Patch Tuesday.
- Two actively exploited zero-days were fixed: CVE-2026-81963 and CVE-2026-85880.
- The release includes 105 Critical flaws, many of them remote code execution bugs.
- Major affected products include Windows, Office, SQL Server, Exchange Server, Entra ID, and Azure services.
- Microsoft said the surge in findings is linked to its AI-powered vulnerability discovery system.