September Patch Tuesday broke records. Two zero-days already have teeth.
Vulnerability Management

September Patch Tuesday broke records. Two zero-days already have teeth.

Mathew Potter

Security Analyst

September 9, 2026

Microsoft's September 2026 Patch Tuesday is the largest on record: 974 CVEs across Windows, Office, SQL, Azure, and the rest of the portfolio. Headline writers love the number. Security teams need the two zero-days and a sane rollout plan for everything else.

The two flaws already in use

CVE-2026-81963 is an elevation-of-privilege bug in Windows Update Stack, the components that install updates. Microsoft confirmed in-the-wild exploitation. It is the first Update Stack issue among several patched since 2022 to show up as an active zero-day. An attacker who already has a foothold on a workstation can parlay this into SYSTEM in the right conditions.

CVE-2026-85880 is a heap buffer overflow in Windows ALPC, the internal messaging layer programs use to talk to each other. Exploitation lets code running inside a low-privilege AppContainer escape the sandbox and climb to SYSTEM without extra clicks from the user. Microsoft patched ALPC issues before, but this is the first zero-day there in roughly three years.

CISA listed CVE-2026-81963 in KEV with a federal due date of September 22. Treat both as priority even if your environment is not federal. Attackers do not read org charts.

Beyond the zero-day row in the spreadsheet

Researchers flagged roughly 20 flaws this month as potentially wormable, mostly remote code execution in Windows components. That matters for flat networks and legacy servers still running 2012-era builds in the back office. SQL Server alone accounted for dozens of CVEs. If you run mixed estates, patch Tuesday is not one reboot. It is a sequencing exercise.

The volume also breaks change windows. Teams that test everything for two weeks before production will fall behind. A tiered approach works better: zero-days and KEV items in 72 hours, internet-facing and domain controllers next, general fleet on your normal cycle with clear exceptions for critical RCE.

A rollout plan that survives contact with reality

  • Inventory which builds actually took September cumulative updates. WSUS and Intune reports lie by omission if a machine was offline.
  • Sample ten percent of endpoints for failed updates before you declare victory.
  • Watch for Update Stack issues on machines that have not rebooted since patch install. Some privilege bugs only show up after a full cycle.
  • Document patch status for cyber insurance renewals. Carriers increasingly ask for evidence, not checkbox answers.
  • If you cannot patch a legacy system, segment it and log access. "Cannot patch" is not the same as "cannot see."

Bottom line

Record patch counts are a stress test for IT, not a scoreboard. Focus on the exploited zero-days first, then wormable RCE on exposed services. Forensic Five helps Canadian organizations verify patch posture, scan external exposure, and produce written evidence for boards and insurers. We do not sell dashboards. We tell you what is actually reachable.

Tags

Patch Tuesday Microsoft zero-day Windows vulnerability management

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.