974 Patches, 2 Zero-Days, and the One Reboot You Can't Skip This Month

September 10, 2026 · 7 min read · Patch TuesdayVulnerability Management

Microsoft just had its biggest Patch Tuesday ever: 974 vulnerabilities fixed in one release.

Buried in that pile are two zero-days that attackers are already using. Neither one is flashy. Neither one is rated "Critical." That's exactly why they're dangerous — they're the kind of thing a busy admin scrolls past.

974

vulnerabilities patched in a single release — a new record

Here's what's actually going on, and the triage method I use to get through a patch list this size without burning a whole day on it.

CVE-2026-85880 — Windows ALPC Heap Buffer Overflow

Why it matters: Lets a local attacker with low-privilege code execution escape an AppContainer sandbox and jump straight to System-level privileges — no extra user interaction needed.
  • Affected: Windows Advanced Local Procedure Call (ALPC)
  • Requirement: Attacker already has code execution in a low-privilege sandbox (e.g. a malicious script past endpoint controls, or a compromised browser sandbox)
  • Notable: First ALPC zero-day patched since January 2023 — rare enough that its reappearance is worth flagging on its own
Quick win: Patch and reboot every endpoint that can run untrusted code — browsers, email clients, anything in a sandbox — before anything else on this list.

CVE-2026-81963 — Windows Update Stack Link-Following Flaw

Critical insight: This is a post-compromise tool — an attacker with an existing foothold uses it to go from "I'm in" to "I own this box."
  • Affected: Windows Update Stack
  • Mechanism: Improper link resolution before file access enables local privilege escalation to System level
  • Notable: First Update Stack CVE flagged as a zero-day in five years of patches to that component
Quick win: Don't just patch — reboot. This one doesn't take effect until the next restart, and a patched-but-unrebooted machine is still vulnerable.

Notice the pattern: both are rated "Important," not "Critical" — but both are confirmed being exploited in the wild. Severity rating tells you blast radius. It doesn't tell you what attackers are actually reaching for this week. Treat "actively exploited" as its own top-priority lane, independent of the CVSS score.

What else is in the pile

Twenty of the 974 fixes are "wormable" — remotely exploitable without authentication, the category that produces the worst outbreaks. The ones worth knowing by name:

CVEProductWhy it matters
CVE-2026-55007Exchange ServerRCE — still on-prem? Jump this to the front.
CVE-2026-69465SharePointRCE — classic lateral-movement target.
CVE-2026-69525Remote Desktop ServicesRCE — same category.
CVE-2026-65669SQL ServerElevation of privilege — quiet, but a direct line to your data.
CVE-2026-81959 / 81953ExcelRCE via malicious document.
CVE-2026-81952WordRCE via malicious document — still the most common ransomware foothold.

The 10-minute triage

You're never going to read all 974 advisories, and you don't need to. Here's the order I work through a Patch Tuesday this size:

  1. Filter for "exploited in the wild" first, severity second. This month that's the ALPC and Update Stack zero-days — patch every endpoint that can reach them before anything else.
  2. Then filter for wormable + internet-facing. Exchange, SharePoint, RDS — if it's exposed, it moves to the front of the line.
  3. Then Office RCEs, because phishing doesn't care about your patch schedule.
  4. Everything else gets your normal maintenance window. Not every elevation-of-privilege bug in a niche service needs an emergency change request — that's how patch fatigue turns into nobody patching anything.
  5. Reboot. Actually reboot. A surprising number of these fixes don't take effect until the next restart.

If your patch management workflow doesn't already sort by "exploited in the wild" as its own field, that's worth fixing before the next record-breaking Tuesday — and it's exactly the kind of gap a structured audit catches before an attacker does.

Need a repeatable way to prioritize checks like this?

Our Network Security Audit Checklist is built around exactly this kind of prioritization — mapped to CIS Controls v8, NIST CSF 2.0, and DORA, so "what do I check first" stops being a judgment call every month.

View the Checklist
Editorial note: CVE details above are compiled from security-press coverage of this release, not Microsoft's Security Update Guide directly. Cross-check exact CVE numbers and affected versions against MSRC if you're using this for a change record.

Comments

Comments are moderated. Practical questions and insights are welcome!

R
Robert Just now

This month's patch list is brutal. What's on yours? I read all comments and reply to questions.