Microsoft — Record-Breaking 974 Flaws Patched with Two Active Windows Zero-Days (CVE-2026-85880 & CVE-2026-81963)
Publication date: September 9, 2026
Category: Zero-Day / Vulnerability
Introduction
In an unprecedented milestone for the software industry, Microsoft set a new record during its September 2026 Patch Tuesday cycle by addressing a staggering 974 vulnerabilities (999 when including non-Microsoft CVEs). Among this massive deployment of security fixes, the corporation confirmed two zero-day vulnerabilities actively exploited in the wild. This discovery and subsequent emergency response prompted cybersecurity agencies such as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to immediately mandate both flaws into its Known Exploited Vulnerabilities (KEV) catalog.
What is Microsoft’s Patch Ecosystem and Critical Flaws? (General Analysis)
The record-breaking volume of 974 flaws spans across core components of Microsoft’s portfolio, notably featuring 723 in Windows, 111 in Office, 62 in SQL Server, and 22 in Developer Tools. Over 110 of these shortcomings received a critical severity rating. Privilege escalation, remote code execution (RCE), and information disclosure account for nearly 90% of all patched issues.
Prominent vectors include two critical local privilege escalation flaws directly impacting the Windows operating system architecture:
- CVE-2026-85880: A heap-based buffer overflow vulnerability in the Windows Advanced Local Procedure Call (ALPC) component. It carries an official CVSS v3.1 score of
7.8(HIGH,AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and is mapped to CWEs CWE-122 and CWE-908. It is officially listed in the CISA KEV catalog. - CVE-2026-81963: An improper link resolution before file access (’link following’) vulnerability in the Windows Update Stack. It carries an official CVSS v3.1 score of
7.8(HIGH,AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and is mapped to CWEs CWE-59 and CWE-284. It is officially listed in the CISA KEV catalog.
Additionally, critical remote code execution and privilege escalation vulnerabilities in server and network infrastructure were addressed:
- CVE-2026-55007: Double free in Microsoft Exchange Server. Official CVSS:
8.1(HIGH,AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), CWE-415. - CVE-2026-65669: Injection in SQL Server. Official CVSS:
9.6(CRITICAL,AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), CWE-74. - CVE-2026-69525: Use after free in Windows Remote Desktop Services (RDS). Official CVSS:
9.8(CRITICAL,AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), CWE-416.
How Does It Work? (Technical Analysis)
An analysis of the exploitation mechanics behind the zero-day vectors and high-severity flaws reveals sophisticated reverse engineering and privilege abuse patterns:
- Sandbox Escape and ALPC Escalation (CVE-2026-85880):
An attacker capable of executing code within a low-privilege AppContainer can interact maliciously with the kernel ALPC interface. Due to inadequate heap buffer management, an overflow condition is triggered, allowing the overwriting of critical kernel data structures, successfully escaping the sandbox and elevating privileges to SYSTEM without requiring user interaction. - Link Manipulation in Windows Update Stack (CVE-2026-81963):
This flaw stems from insufficient validation when resolving symbolic links or junction points prior to file operations within the update stack. A local attacker can redirect update write operations toward critical operating system components, overwriting them with attacker-controlled imposter files to compromise system integrity upon the next reboot. - Remote Exploitation in Network Services:
Vulnerabilities such as CVE-2026-69525 in RDS or CVE-2026-55007 in Exchange enable unauthenticated attackers to execute arbitrary code across the network by transmitting malformed data streams that trigger use-after-free or double-free conditions in network heap and COM object handling.
Affected Systems / Environments
The impact spans virtually all enterprise and consumer environments running supported versions of Microsoft operating systems and platforms:
- Workstations and servers across all supported versions of Microsoft Windows.
- Collaboration and database server infrastructure: Microsoft Exchange Server, Microsoft Office SharePoint, and Microsoft SQL Server.
- Connectivity components and network services: Windows Remote Desktop Services (RDS), Windows DNS Server, Windows DHCP Server, and the ONCRPC XDR driver for Windows Services for NFS.
| CVE | Category (CWE) | Impact | CVSS | Vector (summary) |
|---|---|---|---|---|
| CVE-2026-85880 | CWE-122, CWE-908 | Privilege Escalation | 7.8 (HIGH) | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-81963 | CWE-59, CWE-284 | Privilege Escalation | 7.8 (HIGH) | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2023-21674 | CWE-416 | Privilege Escalation | 8.8 (HIGH) | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVE-2026-55007 | CWE-415 | Remote Code Execution | 8.1 (HIGH) | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-65669 | CWE-74 | Privilege Escalation | 9.6 (CRITICAL) | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| CVE-2026-69525 | CWE-416 | Remote Code Execution | 9.8 (CRITICAL) | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Mitigation and Detection
Remediation
- Immediately apply official cumulative security updates released by Microsoft during the September 2026 Patch Tuesday.
- Prioritize remediation for systems covered under the CISA KEV catalog (CVE-2026-85880 and CVE-2026-81963), adhering to federal compliance deadlines (September 22, 2026) and extending them across enterprise infrastructure.
- Review internet exposure for critical exposed services (Exchange, SharePoint, RDS) and implement network segmentation and WAF rules while patches are deployed.
Detection
- Monitor Security Event Logs for anomalous secondary process creation originating from AppContainer contexts or unusual alterations in OS file paths managed by update services.
- Deploy behavior-based detection rules to identify abnormal symbolic link resolution patterns within operating system directories.
“With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”
Wrapping Up
The historic milestone of 974 patched vulnerabilities in September 2026 underscores both the growing complexity of modern software and the accelerated impact of automated vulnerability discovery methodologies. With two active Windows zero-days and multiple critical RCE flaws in infrastructure services, organizations must shift away from blind patch accumulation toward exposure management rooted in real-world exploitability and risk contextualization.
References
- Lakshmanan, R. (2026). Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days. The Hacker News. https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html
- Microsoft Security Response Center. (2026). September 2026 Security Updates. https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep
- Cybersecurity and Infrastructure Security Agency. (2026). CISA Adds Four Known Exploited Vulnerabilities Catalog. https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-85880. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-81963. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2023-21674. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21674
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-55007. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55007
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-80097. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80097
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-69465. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69465
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-65669. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65669
- National Vulnerability Database. (2026). NIST NVD Details for CVE-2026-69525. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69525