Microsoft released its largest Patch Tuesday to date, addressing 973 vulnerabilities across Windows, Office, and server products, with 113 rated Critical. Two Elevation of Privilege flaws are confirmed actively exploited in the wild, including CVE-2026-81963 affecting Windows Update Stack and CVE-2026-85880 targeting the Advanced Local Procedure Call component, prompting an immediate 24-hour patch recommendation. The release nearly doubles the August count at 973 CVEs, fueling the "Patch Apocalypse" trend driven by AI-assisted vulnerability discovery, while Hotpatching is now generally available for Windows Server Azure Edition VMs to reduce reboot downtime. Organizations should prioritize deploying KB5122871 and KB5122876 immediately, as critical RCE flaws in DNS and Remote Desktop Services also land this month, and several products including Windows Server 2012 and Exchange 2016 are approaching end-of-life support.
Microsoft's September Patch Tuesday Slams 973 CVEs Through the Door
Microsoft just shipped its biggest Patch Tuesday ever. The September 2026 update addresses 973 distinct vulnerabilities across Windows, Office, SQL Server, and developer tools, with 113 landing in the Critical bucket and two confirmed actively exploited in the wild. If you are running a server or a corporate desktop fleet, this is the month you cannot afford to push updates to the back burner.
The numbers track a bizarre acceleration that security teams have started calling the Patch Apocalypse. July delivered 621 fixes. August followed with 421. September nearly doubled the August count at 973. That is the largest month-over-month jump in Patch Tuesday history, and it is landing right on your schedule.
Actively Exploited Flaws Demand Immediate Action
Two Elevation of Privilege bugs are already being weaponized. CVE-2026-81963 rides through the Windows Update Stack to hand an authenticated attacker system-level access. CVE-2026-85880 chains through the Advanced Local Procedure Call component to do the same thing. Both sit at a CVSS of 7.8 and land in the Important severity tier, which means they would get buried if you sort your dashboard by CVSS score. Don't do that. Deploy KB5122871 and KB5122876 within 24 hours. Exploitation status matters more than a severity rating.
The window between finding a bug and deploying a fix used to be measured in months. Now it is measured in days, if you are lucky. Microsoft says the ongoing memory and storage crunch pushed it to revise some of its earlier shipping timelines, but the security side of the equation is moving even faster. Attackers are not waiting for the patch window to widen.
The Rest of the Damage Report
If Elevation of Privilege flaws aren't your nightmare, the Remote Code Execution category should be. Microsoft fixed a 10.0 CVSS rating bug (CVE-2026-70352) that it says is more likely to be exploited. The Windows DNS Server and Remote Desktop Services both picked up 9.8 RCE flaws. Kerberos, Deployment Services, and Schannel round out the high-severity list.
On the component front, the Windows Biometric Service took a heavy hit with 64 fixes, followed by SQL Server at 61 and Office Word at 38. You will also see patches rolling out for Excel, NTFS, Win32K, and the standard XPS viewing stack. It is a rather expensive list to digest, though the cumulative nature of the updates means you only have to run a handful of KBs.
The release also quietly ships a major operational shift. Hotpatching is now generally available for Windows Server Azure Edition virtual machines, meaning kernel patches can be applied without a reboot. That is a meaningful win when you are trying to patch nearly a thousand vulnerabilities without waking your sysadmins.
End-of-life reminders are sitting right next to the patches. Windows 11 Version 24H2 Home and Professional will receive their final updates this October. Server 2012 and 2012 R2, along with Exchange 2016 and 2019, are also approaching the end of their Extended Security Update cycles. If you have not migrated off those platforms yet, the calendar just got stricter.
The sheer volume is drawing sharp commentary from the security industry. Todd Schell, a senior product manager at Ivanti, noted that the Patch Apocalypse continues unabated, pointing out that AI-assisted vulnerability discovery is pushing monthly counts to record highs. Microsoft's own Igor Sahknov has been pushing defenders to treat the network as a temporary control plane to buy time while the patch window collapses. It is a fair point. You cannot always patch faster than the bugs land.
Deployment should follow a three-tier approach. Patch the two actively exploited Elevation of Privilege flaws first. Target all critical RCE vulnerabilities within seven days. Roll out the remaining Important and Critical fixes across Office, Exchange, SharePoint, and SQL Server over the rest of the month. Edge Chromium vulnerabilities will update through Edge's own updater, and Azure Linux package fixes live in a separate repository.
Keep in mind that Microsoft has flagged known issues for several Exchange and SQL Server cumulative updates, so test before pushing to production.
Head here to the full MSRC Security Update Guide.
