Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

Microsoft's September 2026 Patch Tuesday addresses an unprecedented 974 Common Vulnerabilities and Exposures (CVEs), including two zero-day vulnerabilities actively exploited by attackers and twenty "wormable" bugs. This marks a significant escalation in Microsoft's monthly security updates, driven partly by AI-assisted vulnerability discovery. The two zero-days, CVE-2026-85880 and CVE-2026-81963, allow local attackers to escalate privileges to SYSTEM level, with the latter being the first actively exploited Windows Update Stack vulnerability. A critical remote code execution (RCE) flaw in Microsoft Exchange Server (CVE-2026-55007), exploitable via specially crafted Visio attachments, requires immediate attention, as do other high-severity bugs in Exchange and Remote Desktop Services. The large number of wormable vulnerabilities poses a significant risk for rapid malware propagation across networks. Organizations are urged to prioritize patching to mitigate these widespread risks.

AI Signal Decode

Microsoft's September 2026 Patch Tuesday is notable for fixing a record 974 CVEs, highlighting the increasing volume of vulnerabilities being discovered and addressed. This surge is attributed in part to AI-driven code auditing, which is accelerating the pace of vulnerability identification. While the sheer number of patches is staggering, the presence of two actively exploited zero-days and twenty wormable vulnerabilities underscores the immediate threat landscape. Organizations must therefore adapt their patching strategies to cope with this escalating frequency and severity of disclosed security flaws.

The two zero-day vulnerabilities, CVE-2026-85880 and CVE-2026-81963, both allow for privilege escalation, a common tactic for attackers seeking deeper system control. CVE-2026-85880, a heap buffer overflow in Windows ALPC, grants SYSTEM-level privileges, while CVE-2026-81963 affects the Windows Update Stack. The 20 wormable vulnerabilities are particularly concerning, as they can enable unauthenticated remote attackers to execute code and facilitate rapid malware spread without user interaction, reminiscent of past widespread outbreaks. These critical flaws affect core Windows components like Active Directory, DHCP, and DNS.

The Exchange Server RCE vulnerability (CVE-2026-55007) is a critical concern due to its potential impact on a widely used communication and collaboration platform. Although exploitation requires specific low-memory conditions and is deemed unreliable by Microsoft, the ability for an unauthenticated attacker to execute code on the server necessitates immediate patching, especially for internet-facing Exchange servers. Coupled with a severe bug allowing mailbox hijacking (CVE-2026-69380) and a high-severity RCE in Remote Desktop Services (CVE-2026-69525), these vulnerabilities present a substantial risk to enterprise environments.

Looking ahead, the trend of AI-assisted vulnerability discovery suggests that the number of reported CVEs may continue to rise, placing further strain on IT security teams. While Microsoft is rapidly addressing these issues, the effectiveness of patches depends on timely deployment by end-users. Organizations should meticulously prioritize patching based on their specific attack surface and the severity of the vulnerabilities. The significant number of wormable bugs also implies a heightened risk of sophisticated, rapidly spreading cyberattacks in the near future.