Microsoft shipped fixes for 1,169 vulnerabilities across 60 update articles on September 8, 2026. That is the biggest release document of the year, bigger than August's 751, and most of what makes it big does not touch a Windows machine. The part that does is where the week goes.
Two of the 1,169 are already being exploited. Both are Windows, both are local elevation of privilege, both score CVSS 7.8, and neither was public before today. That is the story.
Start here: two Windows zero-days under attack
CVE-2026-81963 is an elevation of privilege vulnerability in the Windows Update Stack, the component that installs updates. Microsoft describes it as improper link resolution before file access, a link-following flaw, and marks it Exploitation Detected. An attacker who already has a foothold can use it to become SYSTEM on the machine. The irony is not lost on anyone: the fix for the update stack ships through the update stack.
CVE-2026-85880 is an elevation of privilege vulnerability in Windows Advanced Local Procedure Call, ALPC, the kernel's message-passing layer between processes. A heap-based buffer overflow, and again Exploitation Detected. ALPC bugs have been the second stage of real intrusions for years because every Windows machine has it and it runs where it matters.
A CVSS of 7.8 looks ordinary next to the Critical entries lower in this release, and that is exactly why local elevation of privilege gets underestimated. It does not get an attacker onto a machine. It takes an attacker who is already there, through a phishing link or an exposed service, and makes them administrator. Two of these, both confirmed in use on release day, is the sharpest opening a Patch Tuesday has had this year.
The fixes ship in this month's cumulative updates. The Update Stack fix rides in KB5122871 and KB5124008 among others; the ALPC fix in KB5122876 and KB5122882 among others. Each CVE page lists every update article carrying its fix, by Windows version, so the one for your builds is one click away.
118 Critical, and where they live
Microsoft rates 118 of the 1,169 as Critical. The location matters more than the count. The highest-scored entries this month are not on Windows at all: CVE-2026-70352 in Azure AI Language and CVE-2026-83711 in Azure Active Directory B2C both carry a CVSS of 10.0, CVE-2026-83941 in Microsoft Entra ID scores 9.9, and CVE-2026-66302 in Skype for Business Server is a 9.8 remote code execution. All four are elevation of privilege or remote code execution in identity and cloud services.
That is the same pattern August showed with SharePoint, Teams and Azure SQL, and it has the same consequence. Cloud-service entries are fixed by Microsoft on Microsoft's side; there is usually nothing to deploy. Server products like Skype for Business are on your side and rarely share a maintenance window with the domain controllers. If your update process stops at the Windows cumulative update, this is the second month running that it shows.
What the number 1,169 actually contains
A headline count is only useful if you know what it counts. Microsoft's release document lists 1,169 entries first published this month. Microsoft's own Severity split covers 1,146 of them: 118 Critical, 910 Important, 104 Moderate and 14 Low. The remaining 23 carry no Severity rating at all.
The trusted press counts this release at 966 to 972, and the difference is not a disagreement. 174 of the 1,169 are Azure Linux entries and 23 are Chromium entries republished for Edge, which the analyst reviews exclude. Take those out and you get 972, which is the Zero Day Initiative's number to the digit. Senserva tracks 914 of the 1,169 against update articles we hold pages for, which is why our Patch Tuesday page shows both figures, each labeled. Microsoft's 1,169 is the number this release is known by, and we lead with it. Our 914 is the number that maps to something you can deploy.
By impact, the month's entries in our CVE catalogue are 438 elevation of privilege, 255 remote code execution, 154 information disclosure, 53 denial of service, 14 security feature bypass, 14 spoofing and 12 tampering. Elevation of privilege being the largest bucket by a wide margin is the third month in a row, and it is the category both zero-days belong to.
What to do this week
- The two exploited ones first. Windows Update Stack and ALPC, this month's cumulative update, today rather than at the weekend. Both are local, so the machines that matter most are the ones people log into: workstations, jump hosts, RDS.
- Server products next. Skype for Business Server carries a 9.8 remote code execution and does not patch itself.
- Check the identity services. Entra ID and Azure AD B2C entries are fixed on Microsoft's side, but if you run conditional access or B2C policies, read the advisories for anything you are asked to change.
- Watch the KEV list. As of release day, none of the 1,169 is on CISA's Known Exploited Vulnerabilities catalog; the two zero-days usually land there within days, and the deadlines start when they do. Our exploited this week page tracks the additions daily.
- Know what you actually run. 1,169 fixes only matter to the extent they land on machines you own. Patch Tuesday is when a good many organizations discover their inventory was an estimate.
The research behind this page
Every figure above is on a page you can check. The September 2026 release page carries Microsoft's Severity split, both zero-days by name, the highest-risk CVEs and every one of the 60 update articles, worst first. The Patch Tuesday hub holds 27 months of releases measured the same way, so a spike is visible rather than asserted, and what the other Patch Tuesday trackers are saying, with their own lead lines. The Microsoft patch tracker ranks this month's updates by what is actually being exploited, and what is hot shows which of them people are searching for today. The wider argument for ranking by exploitation rather than by Severity label is in We Published the Intelligence Half, and what a release looks like three weeks on, when the KEV additions and revisions have landed, is in Patch Day 2. For the operational side, the Microsoft patching guide and AI patch management pages are the long form.
Get told when this changes, free
The hardest part of a release this size is not today. It is the next three weeks, when Microsoft revises entries, CISA adds the two zero-days to its catalog with a deadline attached, and a CVE that looked routine on Tuesday turns out to be under attack by Friday. That is what happened to a SharePoint entry in August.
Senserva Watch tells you when it changes. It is free, it takes one email address, and it covers the CVEs and updates you care about: a KEV addition, a revised advisory, a new known issue on an update you deployed. Members also get the Patch Tuesday wire on release day and three free unlimited audits of the whole Microsoft 365 tenant. And if the question this page leaves you with is which of these updates are still missing on your own machines, that is what Siemserva by Senserva answers: your patch state, every device, ranked the same way this page is.
Sources
- Microsoft Security Response Center, September 2026 Security Updates. The primary source for every figure above, read from the CVRF release data on release day.
- Zero Day Initiative, "The September 2026 Security Update Review", September 8, 2026. The 972 count and the two CVEs under active attack.
- BleepingComputer, "Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days", September 8, 2026.
- CISA, Known Exploited Vulnerabilities catalog. The authority on "actively exploited"; no September 2026 Microsoft entry as of release day.
Every CVE and update article named above resolves to Microsoft's own release data as read on September 8, 2026, and every source is on our trusted list. Figures as of release day; the September page updates daily as Microsoft revises entries.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.