Updated
Updated · Computerworld · Sep 14
Microsoft Patches 963 CVEs in September Release as 2 Windows Flaws Face Active Exploitation
Updated
Updated · Computerworld · Sep 14

Microsoft Patches 963 CVEs in September Release as 2 Windows Flaws Face Active Exploitation

3 articles · Updated · Computerworld · Sep 14

Summary

  • 963 CVEs — including 106 critical issues — make Microsoft’s September Patch Tuesday the biggest of 2026, with two Windows vulnerabilities already being exploited: CVE-2026-81963 in the Update Stack and CVE-2026-85880 in Advanced Local Procedure Call.
  • 726 Windows CVEs drive most of the urgency, led by critical 9.8-rated flaws in DHCP Server, DNS Server, Netlogon and other network-facing components; Microsoft and Readiness both place Windows on a Patch Now schedule.
  • 137 Office CVEs and 62 SQL Server CVEs also rank as immediate priorities, with roughly 105 Office flaws affecting Click-to-Run deployments and four critical SQL remote-code-execution bugs pushing database estates onto the Patch Now list.
  • 55 Windows test items are flagged high risk — up from four in August — with printing, fonts, imaging, USB devices and Remote Desktop called out as the likeliest regression areas; Microsoft published no mitigations or workarounds.
  • October and November support deadlines add pressure beyond this month’s fixes, with Office 2021, Windows 10 2016 LTSB, Server 2012/2012 R2 ESU, .NET 8 and PowerShell 7.4 all nearing or reaching end of support.

Insights

Microsoft fixed 963 flaws in one Patch Tuesday, but which systems should admins patch first when two Windows bugs are already exploited?
Why is printing the top regression risk in Microsoft’s biggest 2026 patch release, and what should enterprises test before rollout?