Microsoft’s September updates fix a record 973 security flaws
Yesterday was September Patch Tuesday, which means Microsoft released security updates addressing 973 new security vulnerabilities. That’s more than twice as many as last month and a new record.
Along with Windows and Office, other products have been updated, including Defender, Exchange Server, Hyper-V, Skype for Business, Visual Studio, and Microsoft’s cloud services. Microsoft classifies 113 of the 973 vulnerabilities as critical, including 83 remote code execution (RCE) issues. The remaining vulnerabilities are classified as high risk, and two are already being exploited in the wild.
The next Patch Tuesday is scheduled for October 13th, 2026.
Windows security vulnerabilities
A large number of the vulnerabilities—over 700 this time—are spread across the various Windows versions (10, 11, Server) for which Microsoft still provides security updates.
This month, two Windows vulnerabilities classified as high risk are already being exploited in the wild. The CVE-2026-81963 vulnerability in the Windows Update stack allows attackers to gain elevated privileges, enabling them to execute code with system privileges by combining this exploit with an RCE vulnerability.
The second zero-day vulnerability, CVE-2026-85880, is in Windows Advanced Local Procedure Call (ALPC) and it’s also an elevation of privilege (EoP) vulnerability. In this case, the exploit code must be concealed within a document so that a user can trigger it. For both zero-days, it’s unclear how widespread the attacks are.
Critical Windows vulnerabilities
Microsoft has classified 77 Windows vulnerabilities as critical, including 56 RCE vulnerabilities. These include CVE-2026-69525 in the Windows Remote Desktop Service, a use-after-free (UAF) vulnerability that an attacker could exploit to remotely execute injected code without authentication or user interaction.
Windows Hello also has nine vulnerabilities, eight of which are EoP vulnerabilities classified as critical. Microsoft had to patch 64 vulnerabilities in the biometric service, most of them very similar to one another and following the same pattern. In 56 cases, there are buffer overflows. CVE-2026-69727 allows elevated privileges over the network, while CVE-2026-73008 exposes personal data—hardly what one would want or expect from a biometric service.
Microsoft Office security vulnerabilities
Microsoft has fixed 137 vulnerabilities in its Office products, slightly more than in August. These include 22 RCE vulnerabilities classified as critical, five of which are in Excel alone. In the case of critical RCE vulnerabilities in Office, the preview pane is often an attack vector—a user doesn’t need to open a malicious file for an attack to succeed.
Meanwhile, RCE vulnerabilities classified as high risk can be exploited when a user opens a malicious file in a vulnerable Office product (called “open-and-own”). In SharePoint, Microsoft has patched 16 vulnerabilities, six of which are RCE vulnerabilities.
Microsoft Exchange Server vulnerabilities
This month, Microsoft has fixed nine vulnerabilities in Exchange Server, all of which are classified as high risk. These include two RCE vulnerabilities: CVE-2026-55007 and CVE-2026-69355.
In the case of CVE-2026-55007, an attacker need only send an email containing a malicious Visio file. The exploit is triggered when the email is processed, without the need for a preview pane.
Microsoft Edge security vulnerabilities
The latest security update to Edge 152.0.4191.66 is dated September 4th and is based on Chromium 152.0.7977.83. It addresses one zero-day vulnerability as well as other Chromium vulnerabilities that aren’t included in the total number of vulnerabilities mentioned above.