Microsoft Patches 963 CVEs in September Release as 2 Windows Flaws Face Active Exploitation
Updated
Updated · Computerworld · Sep 14
Microsoft Patches 963 CVEs in September Release as 2 Windows Flaws Face Active Exploitation
3 articles · Updated · Computerworld · Sep 14
Summary
963 CVEs — including 106 critical issues — make Microsoft’s September Patch Tuesday the biggest of 2026, with two Windows vulnerabilities already being exploited: CVE-2026-81963 in the Update Stack and CVE-2026-85880 in Advanced Local Procedure Call.
726 Windows CVEs drive most of the urgency, led by critical 9.8-rated flaws in DHCP Server, DNS Server, Netlogon and other network-facing components; Microsoft and Readiness both place Windows on a Patch Now schedule.
137 Office CVEs and 62 SQL Server CVEs also rank as immediate priorities, with roughly 105 Office flaws affecting Click-to-Run deployments and four critical SQL remote-code-execution bugs pushing database estates onto the Patch Now list.
55 Windows test items are flagged high risk — up from four in August — with printing, fonts, imaging, USB devices and Remote Desktop called out as the likeliest regression areas; Microsoft published no mitigations or workarounds.
October and November support deadlines add pressure beyond this month’s fixes, with Office 2021, Windows 10 2016 LTSB, Server 2012/2012 R2 ESU, .NET 8 and PowerShell 7.4 all nearing or reaching end of support.