Bar chart of Microsoft monthly security update vulnerability counts from April to September 2026, rising from 164 to a record 974
Fig. 1 — Monthly Microsoft security update volume, April-September 2026 (sources: Microsoft advisories, KrebsOnSecurity, Corvus Cybersecurity)

1. Why this release is being called the largest ever

On 8 September 2026 (US local time), Microsoft shipped its largest monthly security update to date, fixing 974 vulnerabilities. That figure is not the result of steady accumulation. It is the endpoint of five months of consecutive escalation: 164 in April, 120 in May, 200 in June, 570 in July, 398 in August, and 974 in September. In under two months the count more than doubled, pushing Microsoft's total for fiscal 2026 past 2,600.

The composition of those 974 matters as much as the total. 113 were rated "Critical," 438 were elevation-of-privilege issues, and 258 were remote code execution (RCE) flaws. In a real attack chain these three categories overlap almost every time: an attacker uses RCE to gain a foothold, uses privilege escalation to reach the domain controller, then moves laterally toward backups and file servers. A team that patches only the RCE items is not secure at this volume.

Tenable senior staff research engineer Satnam Narang puts elevation-of-privilege at roughly 46% of all vulnerabilities in 2026 to date, with September at 41% close to that long-run average. So privilege escalation becoming the dominant class is not a one-month artefact; it is a settled new normal.

As for why the numbers suddenly jumped, Microsoft gave warning back in July: it has been using AI tooling to find zero-day vulnerabilities in bulk, and faster discovery produces faster patch output. That explanation holds up technically, but it creates a new problem: discovery speed has outrun the speed at which humans patch. That is precisely why CISA changed course in September, retiring the weekly-bulletin approach in favour of risk-based prioritisation under BOD 26-04, which requires the highest-risk vulnerabilities to be closed within three days and mandates a full forensic triage afterwards to confirm the system was not already compromised.

Four-stage attack chain: remote code execution, privilege escalation, lateral movement and domain takeover, ending at file servers, backup systems and the domain controller
Fig. 2 — The four stages of a real attack chain. The first two dominate this batch; the last two determine how far an attacker goes
Stacked bar of the 974 CVEs: 438 elevation-of-privilege, 258 remote code execution, 155 other and 2 zero-days, of which 113 were rated Critical
Fig. 3 — Composition of the 974. Only two are zero-days, but both are being exploited

2. The two zero-days that need patching today

Two vulnerabilities in this batch were actively exploited by real attackers before the patch shipped. This is the hardest prioritization signal there is:

CVEComponentTypeMicrosoft ratingWhy it is dangerous
CVE-2026-85880Windows ALPC (Advanced Local Procedure Call)Heap buffer overflow, local privilege escalationSeverity score 7.8An attacker with a low-privilege local account can escalate to SYSTEM
CVE-2026-81963Windows Update stackImproper link resolution, local privilege escalationImportantAbuses a flaw in the update mechanism itself to escalate

One detail here is easy to miss and deserves separate emphasis: both actively exploited flaws are rated below Critical, one at 7.8 and the other merely Important. A team that sorts by CVSS score and works downward would schedule these behind the 113 Critical items, while attackers are already using them. This is the classic failure mode in vulnerability management: the score describes theoretical severity; exploitation status describes actual threat. They are separate dimensions and both must be read.

Two Critical flaws also deserve explicit mention:

Other notable fixes in the same batch include CVE-2026-62878 (DNS Server RCE), CVE-2026-62893 (Deployment Services RCE) and CVE-2026-58231 (Commerce Cloud and NetWeaver). Separately, on 17 September Microsoft shipped an out-of-band fix for Azure AI Foundry (CVE-2026-85889, CVSS 10.0, unauthenticated privilege escalation), though that class of cloud flaw is remediated on Microsoft's backend and requires no customer action.

3. What a 20-person IT team should do with 974 patches

This is the practical problem. A month of 974 patches cannot be triaged, tested and rolled out by a 20-person team in a few weeks. A "patch everything next month" habit is already too slow — CISA's three-day deadline does not bind domestic companies, but the two exploited vulnerabilities will not wait for your schedule either.

Our recommendation is to split patch work into four tiers rather than one long to-do list:

TierTriggerThis batchTesting bar and deadline
Tier 1 · EmergencyActively exploited (in CISA KEV or vendor statement)CVE-2026-85880, CVE-2026-81963Test on representative machines, deploy same day, done in 3 days
Tier 2 · ExposurePre-auth RCE, or running on internet-reachable systemsCVE-2026-69730 (DNS), CVE-2026-69829 (Shell)Map the exposure first, then sequence; within 1 week
Tier 3 · Core assetsCritical flaws on domain controllers, certificate services, identity infrastructureThe identity and directory-service subset of the 113 Criticals2 weeks, scheduled separately
Tier 4 · RoutineEverything elseRoughly 900Normal monthly maintenance window

The step that collapses the workload is narrowing the asset list before ranking patches. 974 CVEs sounds overwhelming, but the components actually running in your environment are typically a few dozen. Walk the estate once and record which components are in use, which machines they sit on, and which of those are reachable from the internet. What is left needing immediate action is usually a dozen items, not a thousand.

The second thing to build is a re-triage trigger. A vulnerability unexploited today can enter the KEV catalogue next week; CVE-2026-33824 is the textbook case, patched four months before it was listed as exploited. So triage is not a one-time sort but a standing rule: when KEV adds a CVE your environment contains, it jumps to Tier 1 regardless of where it started. Automate a daily KEV diff; it takes minutes and it is the highest-return habit in the whole mechanism.

One counter-intuitive reminder: patching is not the same as being secure. Fortra's security research director Tyler Reguly notes that compatibility testing before deployment is labour-intensive and often eats after-hours time. If you test all 974 before shipping any, the two exploited flaws will be exploited repeatedly while you test. Patch what is being exploited, then run the full regression. Reversing that order inverts the priority.

Four-tier priority queue pyramid: from Tier 1 Emergency (exploited, within 3 days) to Tier 4 Routine (about 900, normal maintenance window)
Fig. 4 — The four-tier queue. The criteria are exploitation and exposure, not score

4. A minimum viable approach for small businesses

If you have no dedicated security staff, collapse the four tiers above into three steps:

  1. This week, patch the two zero-days (CVE-2026-85880, CVE-2026-81963). No need to take the whole company offline at once. Validate on two or three representative machines — one domain controller, one internet-facing service, one general office endpoint — then roll out fleet-wide. These two are the only ones in this batch that invite a direct hit if left open.
  2. Immediately inventory any Windows Server 2012 or 2016 machines you still run. If they expose DNS or Remote Desktop, CVE-2026-69730 is an open gap. The correct handling for these old systems is usually not patching — many are out of support — but planning replacement or isolating them at the network layer.
  3. Institutionalise a daily KEV check. No tool purchase required. A script, or five minutes of someone's morning reading CISA's KEV list, beats buying another scanner. This is the highest-leverage step in the whole process.

If your organisation already has ransomware protection or backup requirements, our ransomware incident response order and 3-2-1 backup rule in practice articles cover the next step. A fully patched machine that has already been compromised needs a completely different response sequence.

All figures in this article come from Microsoft's September 2026 security update announcements, the CISA Known Exploited Vulnerabilities catalogue, and reporting from KrebsOnSecurity and SecurityWeek. Every CVE identifier, score and date cited can be traced back to those sources. Our contribution is translating the technical advisories into an executable action list; patch selection and applicability must ultimately be judged against Microsoft's official documentation, because every environment differs and one team's patch order cannot simply be copied to another.

A three-step playbook for a 20-person IT team: patch the two zero-days this week, inventory legacy servers now, institutionalise a daily KEV diff
Fig. 5 — The three-step playbook for a 20-person IT team, requiring no extra budget