Microsoft's record Patch Tuesday fixes 974 flaws and two exploited Windows zero-days
Microsoft shipped its largest-ever Patch Tuesday, fixing a record 974 vulnerabilities, including two Windows zero-days already exploited in attacks. Both zero-days are local privilege-escalation flaws that let an attacker gain SYSTEM access: CVE-2026-85880 is a heap buffer overflow in the Advanced Local Procedure Call component that can let code in a low-privilege sandbox escape and elevate, and CVE-2026-81963 is a link-following flaw in the Windows Update Stack. The release also includes about 20 potentially wormable flaws, remotely exploitable without authentication, across services like DNS, DHCP, SMB, and Active Directory, plus critical fixes in Exchange, SharePoint, SQL Server, and Kerberos. The sheer volume makes prioritization essential.
- Check
- Prioritize the two exploited zero-days and the roughly 20 wormable, internet-facing flaws in this month's update, deploying them first, then work through the rest based on exposure and asset criticality.
- Affected
- Windows and Microsoft server environments across the board (CVE-2026-85880, CVE-2026-81963, and others); the exploited zero-days give local attackers SYSTEM privileges, while wormable flaws in core network services could spread remotely without authentication.
- Fix
- Apply the September updates promptly, patching exploited and wormable issues first, watch for privilege-escalation activity these flaws enable when chained with initial access, and test large rollouts given the release size.