Microsoft released its largest security update in company history on September 8, 2026, fixing between 964 and 974 vulnerabilities, including 112 critical flaws and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). This record-breaking Patch Tuesday is driven by a surge in AI-powered vulnerability discovery tools. Security experts urge immediate deployment, highlighting 20 wormable bugs and a critical Exchange Server flaw (CVE-2026-55007) that allow unauthenticated remote code execution.
September 2026 Patch Tuesday record
- ▪The September 8, 2026 Patch Tuesday release marked Microsoft's third record-breaking security update in a few months, following previous record releases of approximately 570 fixes in July 2026 and 620 fixes in August 2026.
- ▪Microsoft's September 8, 2026 security update included 112 vulnerabilities rated with a critical-severity threshold, with the remainder carrying an important designation.
- ▪By September 8, 2026, Microsoft had fixed over 2,600 vulnerabilities in 2026, more than double the total number of vulnerabilities patched by the company in the entirety of 2025.
- ▪Microsoft released its largest security update in company history on September 8, 2026, fixing between 964 and 974 vulnerabilities depending on the tracker's counting methodology.
AI-driven vulnerability discovery surge
- ▪The September 8, 2026 Microsoft release included CVE-2026-65669, a CVSS 9.6 elevation of privilege vulnerability in SQL Copilot, the AI assistant in SQL Server Management Studio, which allows attackers to access databases using a victim's permissions.
- ▪The surge in software vulnerabilities is driven by security-focused AI models, such as Anthropic's Mythos model released in April 2026 and a cybersecurity model released by OpenAI, which rapidly discover flaws.
- ▪In August 2026, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other organizations published an open letter warning of a narrowing window to patch vulnerabilities before AI-enabled attackers exploit them.
Exchange Server wormable vulnerabilities
- ▪The September 8, 2026 Microsoft release contained 20 wormable vulnerabilities that require no authentication or user interaction, allowing them to potentially propagate across networks automatically.
- ▪The Exchange Server vulnerability CVE-2026-55007 allows unauthenticated remote code execution when the server's content-indexing engine processes a malicious Visio attachment, requiring no user interaction or preview pane activation.
- ▪The wormable vulnerabilities in the September 8, 2026 release affected core enterprise networking components, including Windows DNS Server (CVE-2026-69730), Windows DHCP Server (CVE-2026-69510, CVE-2026-72979), and Windows SMB Client (CVE-2026-72936).
Patch counting methodology discrepancies
- ▪Different security trackers reported varying CVE counts for the September 8, 2026 Patch Tuesday, with Tenable counting 964 CVEs, Ivanti counting 973, Microsoft's release notes listing 974, and Senserva reaching 1,169.
- ▪The discrepancy in Patch Tuesday counts is exacerbated because Microsoft stopped presenting a single monthly CVE list in its Security Update Guide starting with the July 2026 Patch Tuesday, forcing vendors to parse and build their own lists.
Zero-day exploit patching urgency
- ▪The September 8, 2026 release addressed two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which were actively exploited in the wild before the patches were released.
- ▪CVE-2026-85880 is a heap-based buffer overflow vulnerability in the Windows Advanced Local Procedure Call (ALPC) mechanism that allows attackers to escape low-privilege AppContainer sandboxes and elevate to SYSTEM privileges.
- ▪CVE-2026-81963 is a privilege escalation vulnerability in the Windows Update Stack, credited to Romain Deperne and the Microsoft Threat Intelligence Centre, marking the first confirmed zero-day exploit in this component's history.
Debatable claims
- ▪The surge in AI-discovered vulnerabilities harms cybersecurity by overwhelming IT departments
- ▪Cybersecurity vendors should disclose when their vulnerability rankings are AI-generated
Story comments
Loading comments…