IGMPI facebook Microsoft’s September Security Update Addresses Record 973 Vulnerabilities
IGMPI Logo
Centre for Cyber Forensic and Cyber Security

(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)

Competency based placement focussed Education | Training | Research | Consultancy

18001031071 (Toll Free), +91 11 26512850
Regular | Part-time (Online Live Classes) Modes
Microsoft’s September Security Update Addresses Record 973 Vulnerabilities

Microsoft’s September Security Update Addresses Record 973 Vulnerabilities

Microsoft has released security fixes for 973 vulnerabilities in its September 2026 Patch Tuesday update, marking the first time the company's monthly security release has crossed the 900-vulnerability threshold.

Among the vulnerabilities receiving immediate attention are CVE-2026-81963 and CVE-2026-85880. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that both were already being exploited by attackers and directed federal agencies to apply the necessary patches by September 22.

CVE-2026-81963 affects a Windows component involved in installing updates, while CVE-2026-85880 concerns a Windows messaging mechanism. Security specialists have highlighted the risks associated with privilege-escalation vulnerabilities because attackers can combine them with other weaknesses to gain deeper control over compromised systems.

Such vulnerabilities can also become part of multi-stage cyberattacks. An attacker may initially gain access through phishing or stolen credentials before exploiting another weakness to increase privileges and move further into an organisation's network.

The scale of the September release represents a sharp increase in reported vulnerabilities. Microsoft had set another record only two months earlier when its July security updates addressed more than 600 flaws.

According to cybersecurity researchers, Microsoft's vulnerability count for 2026 has already exceeded 2,600, more than double the previous annual record recorded in 2020.

The September update arrives amid growing concern about the increasing number of software vulnerabilities and the possibility of attackers combining multiple weaknesses into more damaging attack chains.

With actively exploited vulnerabilities included in the latest release, organisations are facing renewed pressure to maintain effective patch-management procedures and reduce delays between the availability of security fixes and their deployment.

08-09-2026