📡 Breaking news
0/0
Analyzing latest trends...
AI Text-to-Speech.

Microsoft Fixes Record 966 Vulnerabilities and 2 Active Zero-Days in September 2026 Patch Tuesday.

Microsoft Fixes Record 966 Vulnerabilities and 2 Active Zero-Days in September 2026 Patch Tuesday.
Microsoft Issues Record-Breaking September 2026 Patch Tuesday Resolving 966 Vulnerabilities and 2 Exploited Zero-Days

Microsoft has officially released its September 2026 Patch Tuesday security updates, setting an all-time record by resolving 966 vulnerabilities across its software ecosystem. The massive update release includes patches for 105 Critical-severity flaws alongside 2 active Zero-Day vulnerabilities that have already been weaponized in real-world cyberattacks.

OS Knowledge Base (KB) Allocation & Critical Flaw Breakdown

System administrators can deploy updates using designated Knowledge Base identifiers based on OS build generations:

  • Windows 11 (Versions 25H2 and 24H2): Updated under KB5124008.

  • Windows 11 (Version 23H2): Updated under KB5122880.

  • Windows 10 (Version 22H2 & Enterprise LTSC ESU): Updated under KB5122878.

  • Critical Severity Profile (105 Total): Encompasses 81 Remote Code Execution (RCE) vulnerabilities, 20 Elevation of Privilege (EoP) flaws, 2 Information Disclosure bugs, and 1 Security Feature Bypass.

  • Excluded Non-Patch Tuesday Fixes: The 966 figure excludes 204 additional vulnerabilities patched earlier in September across cloud services including Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Edge, Microsoft Fabric, and Power Automate.

Detailed Analysis of Actively Exploited Zero-Day Vulnerabilities

Both actively exploited zero-day flaws carry a CVSS severity score of 7.8/10 and permit local attackers to acquire full system-level privileges:

  • CVE-2026-81963 (Windows Update Stack EoP): Caused by improper link resolution handling within the Windows Update Stack. A local attacker with low-privilege access can exploit this flaw to escalate privileges to SYSTEM rights without requiring user interaction. Discovered by Romain Deperne alongside the Microsoft Threat Intelligence Center (MSTIC), it has been added to CISA's Known Exploited Vulnerabilities catalog.

  • CVE-2026-85880 (Windows ALPC EoP): A heap-based buffer overflow flaw residing within the Windows Advanced Local Procedure Call (ALPC) subsystem. Authenticated local attackers can exploit inter-process communication mechanisms to obtain SYSTEM permissions. Discovered by Volexity alongside researchers from Proofpoint, CISA has formally confirmed active exploitation.

The surge from ~570 patches in July and ~400 in August to 966 in September reflects Microsoft's integration of AI-driven vulnerability scanners. Deploying static and dynamic analysis tools backed by automated LLM fuzzing allows security teams to detect complex memory corruption bugs, link resolution flaws, and logic errors across millions of lines of legacy code faster than human security researchers alone.

While EoP vulnerabilities like CVE-2026-81963 and CVE-2026-85880 require local system access, they serve as crucial secondary stages in modern ransomware and espionage playbooks. Threat actors typically gain initial access via phishing or stolen credentials, then deploy EoP zero-days to elevate privileges to SYSTEM level, disabling security sensors, exfiltrating data, and deploying domain-wide malware payloads.

Because both zero-days affect core Windows kernel subsystems (Update Stack and ALPC) and require zero user interaction once an attacker is inside the network, system administrators should prioritize deploying KB5124008, KB5122880, and KB5122878 immediately across high-risk enterprise workstations, multi-user terminal servers, and domain infrastructure.

Source: BleepingComputer 

💬 AI Content Assistant

Ask me anything about this article. No data is stored for your question.

Comments