INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft Shatters Patch Tuesday Record
| 2026-09-09 09:40 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The September CVE list spans Microsoft's product portfolio, with Windows affected by most, at 723, followed by Office at 111. The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in the number of security updates they will need to apply to Windows products as a result of its use of agentic AI tools to discover zero-day vulnerabilities. This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally, and the other flaw CVE-2026-81963 is an improper link resolution before file access in Windows Update Stack, allowing an authorized attacker to elevate privileges locally.
Technical Mitigations AI-generated
* Implement a risk-based approach to vulnerability management, prioritizing flaws that pose the biggest risks to business operations.
* Regularly review and update patch lists to ensure they remain accurate and up-to-date with emerging threats.
* Utilize automated tools and scripts to automate the process of identifying and applying security patches, reducing human error and increasing efficiency.
* Conduct regular security audits and penetration testing to identify vulnerabilities that may have gone undetected during the Patch Tuesday release.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81963CVE-2026-81963
CVE-2026-69380CVE-2026-69380
CVE-2026-62878CVE-2026-62878
CVE-2020-1350CVE-2020-1350
CVE-2026-78510CVE-2026-78510
CVE-2026-69730CVE-2026-69730
CVE-2026-62823CVE-2026-62823
CVE-2026-65789CVE-2026-65789
CVE-2026-85880CVE-2026-85880
CVE-2026-58231CVE-2026-58231
CVE-2026-69829CVE-2026-69829
CVE-2026-69595CVE-2026-69595
CVE-2026-62893CVE-2026-62893
Target & Sectors
Global Scope
Incident Timeline
July 2026
The incident involved a remote code execution vulnerability in Windows Advanced Local Procedure Call (ALPC) with 974 CVE fixes.
Click on any entity below to view its context and source!
infrastructure
Windows
The September CVE list spans Microsoft’s product portfolio, with Windows affected by most, at 723, followed by Office at 111.
The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in the number of security updates they will need to apply to Windows products as a result of its
use of agentic AI
tools to discover zero-day vulnerabilities.
This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.
The other flaw,
CVE-2026-81963
, is an improper link resolution before file access in Windows Update Stack, which allows an authorized attacker to elevate privileges locally.
A remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow, given a critical rating of 9.8
CVE-2026-62823
.
A remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow, given a high severity rating of 8.8
CVE-2026-62893
.
A remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition, given a critical rating of 9.8
CVE-2026-65789
.
A remote code execution vulnerability in Windows DNS caused by a use-after-free condition, given a high severity rating of 8.1
CVE-2026-58231
.
organisation
Office
The September CVE list spans Microsoft’s product portfolio, with Windows affected by most, at 723, followed by Office at 111.
organisation
Windows Advanced Local Procedure Call
This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.
organisation
AppContainer
This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.
organisation
Windows Deployment Services
A remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition, given a critical rating of 9.8
CVE-2026-65789
.
September 8
Threat actors exploited two zero-day flaws in Microsoft's update on September 8.
Click on any entity below to view its context and source!
organisation
AI-Discovered
”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its
update
on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
tactic
T1588.006 - Vulnerabilities
”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its
update
on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
organisation
Microsoft Warns
”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its
update
on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
organisation
Actively Exploited Flaws
”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its
update
on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
general_metric
1 %
”
Read now: Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
Microsoft Warns of Two Actively Exploited Flaws
As part of its
update
on September 8, Microsoft highlighted two zero-day flaws that are being actively exploited by threat actors.
2026/09/09
Microsoft released a massive security update in September 2026, which included 974 unique vulnerabilities.
Click on any entity below to view its context and source!
infrastructure
Windows
Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each.
The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are
CVE-2026-85880
(CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and
CVE-2026-81963
(CVSS 7.8), another EoP flaw this time in Windows Update Stack.
The "zero-click RCE bugs — headlined by a Windows DNS Server flaw (
CVE-2026-69730
CVSS:9.8) acting as SigRed’s spiritual successor — creates severe, self-propagating contagion risk across enterprise networks," he wrote.
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
Amol Sarwate, head of security research and REDLab at Cohesity, advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane this month.
organisation
Office and Office 2016
Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each.
organisation
Windows Advanced Local Procedure Call
The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are
CVE-2026-85880
(CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and
CVE-2026-81963
(CVSS 7.8), another EoP flaw this time in Windows Update Stack.
infrastructure
7.8
The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are
CVE-2026-85880
(CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and
CVE-2026-81963
(CVSS 7.8), another EoP flaw this time in Windows Update Stack.
organisation
SigRed
The "zero-click RCE bugs — headlined by a Windows DNS Server flaw (
CVE-2026-69730
CVSS:9.8) acting as SigRed’s spiritual successor — creates severe, self-propagating contagion risk across enterprise networks," he wrote.
infrastructure
9.8
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
organisation
Critical RCE Flaws
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
organisation
CVE-2026
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
organisation
NFS
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
organisation
Cohesity
Amol Sarwate, head of security research and REDLab at Cohesity, advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane this month.
organisation
Office
Related:
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
"On the endpoint front, security teams should prioritize the Office stack, as attackers can exploit a condition in the SMB client and create a malicious Word RTF or a malicious message in the Outlook Reading Pane that can lead to code execution," he cautioned.
organisation
SMB
Related:
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
"On the endpoint front, security teams should prioritize the Office stack, as attackers can exploit a condition in the SMB client and create a malicious Word RTF or a malicious message in the Outlook Reading Pane that can lead to code execution," he cautioned.
organisation
RCE
Another 25%, or 260, were
remote code execution
(RCE) flaws, while about 18%, or 175, involved information disclosure.
organisation
Trend Micro's
Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, pointed to
CVE-2026-69380
(CVSS:8.1), a Microsoft Exchange Server EoP, as another vulnerability that organizations should patch immediately, because it "allows low-privileged attackers to impersonate any user and hijack every mailbox in the organization.
organisation
Microsoft Exchange
Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, pointed to
CVE-2026-69380
(CVSS:8.1), a Microsoft Exchange Server EoP, as another vulnerability that organizations should patch immediately, because it "allows low-privileged attackers to impersonate any user and hijack every mailbox in the organization.
organisation
Microsoft
Microsoft released fixes for 974 unique vulnerabilities in its scheduled security update for September, which until recently would have represented a full year’s worth of CVEs.
organisation
DNS
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
SigRed (
CVE-2020-1350
) was a maximum severity RCE flaw in DNS servers from 2020 that allowed an unauthenticated attacker to gain Local System/Domain Administrator-level control and potentially spread across a network without user interaction.
organisation
Local System/Domain Administrator
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
SigRed (
CVE-2020-1350
) was a maximum severity RCE flaw in DNS servers from 2020 that allowed an unauthenticated attacker to gain Local System/Domain Administrator-level control and potentially spread across a network without user interaction.
organisation
September Patch
"
A Cluster of Wormable CVEs
Also of high priority in
Microsoft's September Patch Tuesday
are a cluster of 20 wormable CVEs, Childs warned in an emailed statement.
organisation
DHCP
Attackers could exploit these flaws by sending unauthenticated packets to DNS, DHCP, RDS, and Netlogon listeners on domain controllers and Microsoft Exchange, he said in a statement.
organisation
RDS
Attackers could exploit these flaws by sending unauthenticated packets to DNS, DHCP, RDS, and Netlogon listeners on domain controllers and Microsoft Exchange, he said in a statement.
organisation
Netlogon
Attackers could exploit these flaws by sending unauthenticated packets to DNS, DHCP, RDS, and Netlogon listeners on domain controllers and Microsoft Exchange, he said in a statement.
organisation
Narang
"
Security teams should focus on understanding the vulnerabilities that actually apply to their organizations, figure out if the flaws are reachable and exploitable in their specific environments, and prioritize based on risk context, Narang said.
organisation
Tyler Reguly
It's also important to keep in mind that the massive surge in vulnerability discovery and disclosure is likely temporary, noted Tyler Reguly, associate director of security R&D at Fortra, in a statement.
organisation
Fortra
It's also important to keep in mind that the massive surge in vulnerability discovery and disclosure is likely temporary, noted Tyler Reguly, associate director of security R&D at Fortra, in a statement.
September 2026
Microsoft released a September 2026 Patch Tuesday update containing 974 CVE fixes.
Click on any entity below to view its context and source!
organisation
Microsoft Shatters
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026.
general_metric
974 CVE Fixes
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026.
organisation
Microsoft
Microsoft has announced fixes for a record 974 CVEs in its September 2026 Patch Tuesday release.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The September CVE list spans Microsoft’s product portfolio, with Windows affected by most, at 723, followed by Office at 111.
The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in the number of security updates they will need to apply to Windows products as a result of its
use of agentic AI
tools to discover zero-day vulnerabilities.
This is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which can enable an attacker who can execute code in a low-privilege AppContainer to elevate privileges locally.
The other flaw,
CVE-2026-81963
, is an improper link resolution before file access in Windows Update Stack, which allows an authorized attacker to elevate privileges locally.
A remote code execution vulnerability in Windows DNS Server caused by a stack-based buffer overflow, given a critical rating of 9.8
CVE-2026-62823
.
A remote code execution vulnerability in Windows DHCP Server caused by a heap-based buffer overflow, given a high severity rating of 8.8
CVE-2026-62893
.
A remote code execution vulnerability in Windows Deployment Services caused by a use-after-free condition, given a critical rating of 9.8
CVE-2026-65789
.
A remote code execution vulnerability in Windows DNS caused by a use-after-free condition, given a high severity rating of 8.1
CVE-2026-58231
.
Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each.
The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are
CVE-2026-85880
(CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and
CVE-2026-81963
(CVSS 7.8), another EoP flaw this time in Windows Update Stack.
The "zero-click RCE bugs — headlined by a Windows DNS Server flaw (
CVE-2026-69730
CVSS:9.8) acting as SigRed’s spiritual successor — creates severe, self-propagating contagion risk across enterprise networks," he wrote.
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
Amol Sarwate, head of security research and REDLab at Cohesity, advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane this month.
Metrics
infrastructure
7.8
Software Version
The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are
CVE-2026-85880
(CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and
CVE-2026-81963
(CVSS 7.8), another EoP flaw this time in Windows Update Stack.
Metrics
infrastructure
9.8
Software Version
"
Critical RCE Flaws
Researchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set:
CVE-2026-69829
, an RCE in Windows Shell;
CVE-2026-69595
, an RCE in Windows Services for NFS ONCRPC XDR Driver; and
CVE-2026-78510
, a Microsoft Word RCE.
Intelligence Sources
Infosecurity-Magazine
2026-09-09
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Infosecurity-Magazine
Dark Reading
2026-09-08
Patch Tuesday Sets Another Record With 974 CVEs
Dark Reading
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-10T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
Office
entity
13x
vulnerability
Exploited CVE
CVE-2026-85880
cve
7x
general metric
%
1
%
5x
attribution
Attributing Entity
Critical
authority
5x
timeline
Temporal Reference
September 2026
date
4x
tactic
Cyber Operation Type
Buffer Overflow
tactic
3x
tactic
MITRE ATT&CK Technique
T1584.002 - DNS Server
technique
2x
industry
Targeted Sector
Manufacturing
sector
2x
general metric
Cve-2026
85,880
cve-2026
2x
general metric
Substantial Rise
570
substantial rise
2x
infrastructure
Software Version
7.8
version
Contextual Telemetry
Context Block
12 METRICS
infrastructure
Affected Product
Windows
software
general metric
Cve Fixes
974
cve fixes
general metric
Tuesday
120
tuesday
general metric
Critical Vulnerabilities
119
critical vulnerabilities
vulnerability
CVSS Score
8
score
general metric
Zero Days
1,000
zero days
general metric
Rce Bugs
10
rce bugs
general metric
Technologies
62
technologies
general metric
Developer Tools
16
developer tools
general metric
Flaws
13
flaws
general metric
Critical
58
critical
general metric
Wormable Bugs
20
wormable bugs
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.