INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft Fixes Record 964 Flaws Including Zero-Days
| 2026-09-09 10:01 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The latest patch Tuesday brings fixes for two high-severity zero-day vulnerabilities in Windows, including a critical buffer overflow exploit that can elevate privileges locally. Microsoft describes the vulnerability as "heap-based buffer overflow" and notes it has a CVSS score of 7.8 out of 10. The affected software includes Windows Update Stack, Remote Desktop Services, Exchange Server, SharePoint, SQL Server, and core Windows components. Users are advised to download Malwarebytes today to protect their devices from these threats.
Technical Mitigations AI-generated
* Use an up-to-date operating system and software, such as Windows 11 or macOS High Sierra or later.
* Keep your operating system and software applications updated to the latest versions.
* Avoid opening malicious documents or clicking on suspicious links, which can lead to local privilege escalation vulnerabilities like those mentioned in the article.
* Be cautious when using cloud services, especially if they are not properly configured or monitored for security risks.
* Use a reputable antivirus program and keep it up-to-date to protect against malware and other types of cyber threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81963CVE-2026-81963
CVE-2026-80097CVE-2026-80097
CVE-2023-21674CVE-2023-21674
CVE-2026-69465CVE-2026-69465
CVE-2026-69730CVE-2026-69730
CVE-2026-72979CVE-2026-72979
CVE-2026-85880CVE-2026-85880
CVE-2026-55007CVE-2026-55007
CVE-2026-69829CVE-2026-69829
CVE-2026-69595CVE-2026-69595
CVE-2026-69525CVE-2026-69525
CVE-2026-65669CVE-2026-65669
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
Office 2016
Threat actors exploited zero-day vulnerabilities in Microsoft's Windows and Office software to target various versions of these applications.
Click on any entity below to view its context and source!
infrastructure
Windows
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
general_metric
723 flaws
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
general_metric
111 flaws
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
general_metric
22 flaws
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
organisation
SQL
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
general_metric
62 vulnerabilities
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
January 2023
Threat actors exploited CVE-2023-21674, a previously unpatched vulnerability, to target systems affected by the newly released Microsoft patch for CVE-2026-85880.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85880
As for CVE-2026-85880, it's the second to be weaponized as a zero-day since
CVE-2023-21674
, which was addressed in January 2023.
vulnerability
CVE-2023-21674
As for CVE-2026-85880, it's the second to be weaponized as a zero-day since
CVE-2023-21674
, which was addressed in January 2023.
2026/09/09
Threat actors exploited a zero-day vulnerability in Microsoft's latest software update, targeting users on September 9.
2026/09/09
Microsoft addressed 974 security flaws across its product suite, including two actively exploited zero-day vulnerabilities.
Click on any entity below to view its context and source!
infrastructure
Windows
Per exposure management and vulnerability assessment platform Tenable, there have been seven privilege escalation flaws in the Windows Update Stack since 2022.
The release includes fixes for two actively exploited Windows zero-days.
How to apply patches and check if you’re protected
These updates fix security problems and help keep your Windows PC protected.
Windows will search for the latest security updates.
Windows 11 up to date
If updates are available, they’ll start downloading automatically.
After restarting, go back to
Windows Update
and check again.
Technical details
The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.
The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a
CVSS score
of 7.8 out of 10, tracked as
CVE-2026-81963
.
The description says:
“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.”
This means Windows can be persuaded to open or modify the wrong file because it follows a shortcut-like pointer without properly checking where that pointer leads.
Microsoft describes it as:
“heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.”
Windows ALPC is an internal messaging system in the Windows operating system that allows different programs on the same computer to communicate with each other quickly.
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days.
These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
CVE-2026-81963
(CVSS score: 7.8) -
An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
"An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880.
"
Adam Barnett, lead software engineer at Rapid7, said all supported versions of Windows receive a patch for CVE-2026-81963, a move that "presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter.
The Windows maker said it has detected zero-day exploitation efforts targeting the flaws, but did not disclose any specifics as to who is behind them, the scale of such efforts, and if those attacks have successfully breached any victims.
A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network
CVE-2026-69595
(CVSS score: 9.8) -
A use-after-free vulnerability in Windows Services for NFS ONCRPC
A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network
CVE-2026-69829
(CVSS score: 9.8) -
A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network
CVE-2026-72979
(CVSS score: 9.8) -
A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network
Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows.
The vulnerabilities actively exploited prior to disclosure —
CVE-2026-81963
affecting the Windows Update Stack and
CVE-2026-85880
affecting Windows Advanced Local Procedure Call — both have CVSS ratings of 7.8 and allow attackers to escalate privileges.
organisation
Windows Update
After restarting, go back to
Windows Update
and check again.
organisation
Remote Desktop Services
Technical details
The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.
organisation
SharePoint
Technical details
The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.
infrastructure
7.8
The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a
CVSS score
of 7.8 out of 10, tracked as
CVE-2026-81963
.
The vulnerabilities actively exploited prior to disclosure —
CVE-2026-81963
affecting the Windows Update Stack and
CVE-2026-85880
affecting Windows Advanced Local Procedure Call — both have CVSS ratings of 7.8 and allow attackers to escalate privileges.
organisation
Microsoft
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days.
Microsoft fixes record 964 flaws, including 2 exploited zero-days.
Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time.
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities.
organisation
Office and Office 2016
These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
organisation
Windows Advanced Local Procedure Call
A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
CVE-2026-81963
(CVSS score: 7.8) -
The vulnerabilities actively exploited prior to disclosure —
CVE-2026-81963
affecting the Windows Update Stack and
CVE-2026-85880
affecting Windows Advanced Local Procedure Call — both have CVSS ratings of 7.8 and allow attackers to escalate privileges.
organisation
AppContainer
An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
"An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880.
Microsoft says
an attacker who can execute code in a low-privilege AppContainer could exploit the vulnerability locally to escape the sandbox and elevate their privileges on the affected system.
organisation
the Windows Update Stack
An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
"An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880.
The vulnerabilities actively exploited prior to disclosure —
CVE-2026-81963
affecting the Windows Update Stack and
CVE-2026-85880
affecting Windows Advanced Local Procedure Call — both have CVSS ratings of 7.8 and allow attackers to escalate privileges.
organisation
Windows Remote Desktop Services
A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network
CVE-2026-69595
(CVSS score: 9.8) -
organisation
NFS
A use-after-free vulnerability in Windows Services for NFS ONCRPC
organisation
CVE-2026
Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows.
However, CVE-2026-81963 is the first zero-day as well as the first to be exploited in the wild.
organisation
Microsoft Exchange
A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network
CVE-2026-80097
(CVSS score: 8.6) -
organisation
CVSS
The second zero-day, tracked as
CVE-2026-85880
, also has a CVSS score of 7.8 out of 10.
organisation
The Hacker News
"September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026," Satnam Narang, senior staff research engineer at Tenable, said in a statement shared with The Hacker News.
organisation
Patch Tuesday
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering
974 vulnerabilities
spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.
The two are among
973 bugs
disclosed on Patch Tuesday by Microsoft.
organisation
Microsoft Authenticator
An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally
CVE-2026-69465
(CVSS score: 8.8) -
infrastructure
Microsoft Office
A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network
CVE-2026-65669
(CVSS score: 9.6) -
organisation
Microsoft Office SharePoint
A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network
CVE-2026-65669
(CVSS score: 9.6) -
data_breach
569 previous record
"To put it into context, this month's Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year's total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go.
organisation
Fortra
"I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning," Tyler Reguly, associate director of Security R&D at Fortra, said.
organisation
Exchange
More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.
infrastructure
22,000 Exchange servers
More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.
organisation
Automox
An attacker who owns the update stack owns the thing you'd use to evict them,” Automox engineer Serena DiPenti said.
organisation
Adobe
Qualys cybersecurity expert Diksha Ojha added that another vulnerability
announced
by Adobe this month was a
critical-severity bug
in Adobe Commerce.
organisation
Adobe Commerce
Qualys cybersecurity expert Diksha Ojha added that another vulnerability
announced
by Adobe this month was a
critical-severity bug
in Adobe Commerce.
organisation
Trend Micro’s Zero Day Initiative
“AI-assisted vulnerability discovery shows no signs of slowing down,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, wrote in a
blog post
Tuesday.
organisation
Microsoft’s Security Response Center
The full list of vulnerabilities addressed this month is available in
Microsoft’s Security Response Center
.
September 2026
Threat actors exploited zero-day vulnerabilities in Microsoft's September 2026 Patch Tuesday patches.
Click on any entity below to view its context and source!
organisation
Critical
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.
organisation
Important
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.
general_metric
104 CVEs
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.
September 22, 2026
Threat actors exploited zero-day vulnerabilities in Microsoft software to target the Federal Civilian Executive Branch.
Click on any entity below to view its context and source!
attribution
Known Exploited
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
both flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
tactic
T1588.006 - Vulnerabilities
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
both flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
attribution
KEV
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
both flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
attribution
Federal Civilian Executive Branch
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
both flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
attribution
FCEB
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
both flaws to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.
September 22
Microsoft's zero-day exploits were used to target federal agencies on Patch Tuesday.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The release includes fixes for two actively exploited Windows zero-days.
How to apply patches and check if you’re protected
These updates fix security problems and help keep your Windows PC protected.
Windows will search for the latest security updates.
Windows 11 up to date
If updates are available, they’ll start downloading automatically.
After restarting, go back to
Windows Update
and check again.
Technical details
The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.
The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a
CVSS score
of 7.8 out of 10, tracked as
CVE-2026-81963
.
The description says:
“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.”
This means Windows can be persuaded to open or modify the wrong file because it follows a shortcut-like pointer without properly checking where that pointer leads.
Microsoft describes it as:
“heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.”
Windows ALPC is an internal messaging system in the Windows operating system that allows different programs on the same computer to communicate with each other quickly.
Per exposure management and vulnerability assessment platform Tenable, there have been seven privilege escalation flaws in the Windows Update Stack since 2022.
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days.
These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
CVE-2026-81963
(CVSS score: 7.8) -
An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
"An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880.
"
Adam Barnett, lead software engineer at Rapid7, said all supported versions of Windows receive a patch for CVE-2026-81963, a move that "presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter.
The Windows maker said it has detected zero-day exploitation efforts targeting the flaws, but did not disclose any specifics as to who is behind them, the scale of such efforts, and if those attacks have successfully breached any victims.
A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network
CVE-2026-69595
(CVSS score: 9.8) -
A use-after-free vulnerability in Windows Services for NFS ONCRPC
A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network
CVE-2026-69829
(CVSS score: 9.8) -
A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network
CVE-2026-72979
(CVSS score: 9.8) -
A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network
Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows.
The vulnerabilities actively exploited prior to disclosure —
CVE-2026-81963
affecting the Windows Update Stack and
CVE-2026-85880
affecting Windows Advanced Local Procedure Call — both have CVSS ratings of 7.8 and allow attackers to escalate privileges.
The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
Metrics
infrastructure
7.8
Software Version
The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a
CVSS score
of 7.8 out of 10, tracked as
CVE-2026-81963
.
The vulnerabilities actively exploited prior to disclosure —
CVE-2026-81963
affecting the Windows Update Stack and
CVE-2026-85880
affecting Windows Advanced Local Procedure Call — both have CVSS ratings of 7.8 and allow attackers to escalate privileges.
Metrics
infrastructure
Microsoft Office
Affected Product
A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network
CVE-2026-65669
(CVSS score: 9.6) -
Metrics
data_breach
569
Previous Record
"To put it into context, this month's Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year's total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go.
Metrics
infrastructure
22,000
Exchange Servers
More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.
Intelligence Sources
The Hacker News
2026-09-09
Malware Bytes
2026-09-09
TheRecord
2026-09-08
CyberScoop
2026-09-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-10T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
Windows Update
entity
12x
vulnerability
Exploited CVE
CVE-2026-81963
cve
11x
attribution
Attributing Entity
Cybersecurity companies Volexity
authority
9x
timeline
Temporal Reference
2026/09/09
date
7x
general metric
Flaws
964
flaws
5x
tactic
Cyber Operation Type
Phishing
tactic
3x
tactic
MITRE ATT&CK Technique
T1584.002 - DNS Server
technique
3x
general metric
Score
8
score
3x
general metric
Vulnerabilities
457
vulnerabilities
2x
infrastructure
Affected Product
Windows
software
2x
general metric
%
90
%
2x
general metric
Bugs
1,000
bugs
Contextual Telemetry
Context Block
18 METRICS
general metric
Windows
11
windows
vulnerability
CVSS Score
8
score
infrastructure
Software Version
7.8
version
general metric
Cves
104
cves
general metric
Entities
10
entities
general metric
Cve-2026
85,880
cve-2026
general metric
Double Free Vulnerability
9
double free vulnerability
general metric
Improper Authentication Vulnerability
9
improper authentication vulnerability
general metric
Missing Authorization Vulnerability
10
missing authorization vulnerability
data breach
Previous Record
569
previous record
general metric
Year
1,245
year
general metric
Shortcomings
110
shortcomings
general metric
August
663
august
general metric
July
220
july
general metric
June
161
june
general metric
Security Flaws
2,760
security flaws
infrastructure
Exchange Servers
22,000
exchange servers
general metric
Security Vulnerabilities
600
security vulnerabilities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.