CYBERSECURITY & PRIVACY • WINDOWS SECURITY • UPDATED SEPTEMBER 14, 2026
Microsoft’s September 2026 Patch Tuesday Fixes Two Exploited Zero-Days: What Windows Users Should Do
Microsoft’s September security release is one of the biggest Patch Tuesday cycles ever reported, but the number that matters most is two: Microsoft says two Windows vulnerabilities were already being exploited before patches became available.
By Digital Pulse Brief Editorial Desk • 10 min read

The short version
- Patch now: Microsoft says CVE-2026-85880 and CVE-2026-81963 were exploited before the September 8 updates were released.
- Home users: open Settings → Windows Update → Check for updates, install the September security update and restart when prompted.
- Businesses: prioritize exposed and privileged systems, test critical applications where required, then accelerate deployment rather than waiting for a routine maintenance window.
- Do not obsess over the headline count: security outlets report totals ranging from 966 to 999 because their counting scopes differ. The two exploited Windows flaws are the urgent part.
Digital Pulse Brief recommendation: if your supported Windows device has not installed the September 2026 security update, treat it as a priority update.
Why this Patch Tuesday matters
Microsoft released its September 2026 security updates on September 8 and explicitly urged customers to apply them promptly. The company confirmed that two vulnerabilities had already been exploited before fixes were published: CVE-2026-85880, an elevation-of-privilege flaw in Windows Advanced Local Procedure Call, and CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update stack.
That is the definition of a high-priority patching situation. A zero-day does not automatically mean every Windows PC is compromised, and an elevation-of-privilege bug typically requires an attacker to gain some foothold first. But once a vulnerability is being used in the wild, defenders are no longer patching only against a theoretical future attack.
Microsoft’s official Windows message center says the September security update is available for all supported Windows versions and recommends installing it promptly. For Windows 11, Microsoft’s September release notes include versions 26H1, 25H2, 24H2 and 23H2.

Why are some reports saying 966, 974 or 999 vulnerabilities?
If you searched for the September Patch Tuesday numbers, you probably saw conflicting totals. BleepingComputer counted 966 flaws in Microsoft’s September release. TechRadar reported 974 vulnerabilities. Rapid7 commentary cited 999 vulnerabilities across Microsoft and non-Microsoft products.
Those figures are not necessarily evidence that one outlet is simply wrong. Patch Tuesday totals can change depending on what a publication includes: Microsoft-only CVEs versus a broader vendor ecosystem, how advisories and republished vulnerabilities are counted, and the exact snapshot of Microsoft’s continuously updated Security Update Guide.
For ordinary Windows users, the practical conclusion is the same: this was an unusually large security release, and the two actively exploited Windows vulnerabilities deserve more attention than the difference between competing headline totals.
The two exploited Windows zero-days
CVE-2026-85880: Windows ALPC elevation of privilege
Microsoft identifies CVE-2026-85880 as a Windows Advanced Local Procedure Call elevation-of-privilege vulnerability. In simple terms, an elevation-of-privilege bug can allow an attacker who already has some level of access to gain more powerful permissions.
That makes these flaws particularly relevant in multi-stage attacks. A phishing attachment, malicious download or compromised account might provide an initial foothold; a privilege-escalation vulnerability can then help an attacker move from limited access toward higher control. Microsoft has not said that every affected device is being targeted, but it has confirmed exploitation occurred before the patch was available.
CVE-2026-81963: Windows Update stack elevation of privilege
The second confirmed exploited flaw, CVE-2026-81963, affects the Windows Update stack. Microsoft also classifies it as an elevation-of-privilege vulnerability and specifically calls for customers to apply the September updates quickly.
Because the Windows servicing and update infrastructure is a trusted part of the operating system, vulnerabilities in this area are important even when the public technical details are deliberately limited. Users do not need exploit details to make the correct defensive decision: install the vendor’s security update.
Who needs to update?
Anyone running a supported Windows version should check that September 2026 security updates are installed. Microsoft’s official release information covers current Windows 11 branches and supported Windows Server products, while separate September security releases also address Microsoft Office and Exchange vulnerabilities.
Organizations should pay particular attention to administrator workstations, servers, internet-facing systems, remote-access machines, shared devices and endpoints used by people with access to sensitive data. Those systems can offer a higher payoff if an attacker successfully chains an initial compromise with privilege escalation.

How to install the September 2026 Windows security update
For most home PCs, the safest route is Windows Update rather than downloading random installers from search results.
- Open Settings.
- Select Windows Update.
- Choose Check for updates.
- Install the available September 2026 cumulative/security update.
- Restart the PC if Windows asks for a restart.
- Return to Windows Update and confirm the device reports that it is up to date.
Microsoft notes that automatic updates are enabled by default for most consumer Windows installations, so many PCs will already have received the patch. Checking manually is still useful if the computer has been offline, updates were paused, or a restart has been postponed.
Before updating a business-critical machine
For business systems, “patch quickly” does not mean “ignore change control.” Maintain current backups, verify recovery procedures, review Microsoft’s known-issues notes for the Windows version you manage, and use a staged deployment where an application outage would cause serious business impact.
The balance matters: a week-long testing process that was reasonable for an ordinary quality update may be too slow when a vulnerability is already exploited. Security teams should compress testing and prioritize systems based on exposure and privilege.
What IT teams should prioritize first
A practical order is to start with systems that combine high exposure and high privilege. That typically means administrator endpoints, remote-access infrastructure, servers reachable from less-trusted networks, developer workstations with production credentials and devices used by finance or executives.
Next, confirm deployment rather than assuming an update policy worked. Endpoint-management dashboards can report failed installations, pending restarts and devices that have not checked in. A vulnerability remains unpatched if the update is approved but never successfully installed.

What the record-size update does—and does not—mean
A giant monthly vulnerability count can sound alarming, but it needs context. More disclosed CVEs can mean more software complexity and more attack surface, but it can also reflect better discovery, expanded product coverage and faster disclosure. Security researchers increasingly use automation and AI-assisted analysis to find bugs that might previously have remained hidden longer.
For users, the security outcome is positive when vulnerabilities are found responsibly and fixed before attackers can exploit them. The concern is the subset that attackers discover first—or begin exploiting before a patch is widely deployed.
That is why the exploited status of CVE-2026-85880 and CVE-2026-81963 is more useful for prioritization than the raw monthly total.
Do you need to panic about the zero-days?
No. You need to patch, not panic.
Microsoft has confirmed real-world exploitation, which raises urgency. But “actively exploited” does not mean every Windows device has been breached. It means defenders should close the known path promptly, keep endpoint protection enabled and pay attention to unusual account or device activity.
Home users should be especially skeptical of emails, ads or websites claiming that a special “zero-day removal tool” is required. Use Windows Update and Microsoft’s official support channels. Security news itself is often used as bait for fake update pages and malware downloads.
What about Microsoft Office and Exchange?
The September release is broader than Windows. Microsoft published separate security updates for Office products, including fixes for remote code execution and information-disclosure vulnerabilities, and issued September security updates for Exchange Server.
Businesses running on-premises Exchange or legacy Office deployments should therefore treat September as an ecosystem-wide Microsoft patch cycle, not only a Windows desktop update.

Five checks after you patch
- Confirm installation: check Windows Update history or your endpoint-management console.
- Restart where required: a downloaded update is not always a completed update.
- Watch for failed devices: identify endpoints that are offline, out of storage or stuck on an error.
- Keep Microsoft Defender or your endpoint protection current: patching and endpoint detection address different parts of the risk.
- Monitor privileged accounts: because both confirmed exploited flaws involve elevation of privilege, unexpected administrator activity deserves attention.
Frequently asked questions
Was the September 2026 Microsoft Patch Tuesday really the biggest ever?
Multiple security publications describe it as record-setting or the largest Microsoft Patch Tuesday they have tracked. Exact totals differ by methodology, with major reports ranging from 966 to 999 vulnerabilities depending on scope.
Which September 2026 Windows vulnerabilities were already exploited?
Microsoft specifically names CVE-2026-85880 and CVE-2026-81963 as vulnerabilities exploited before the September updates were released.
Should home users install the update immediately?
Yes. Microsoft recommends installing the September security updates promptly. For a normal consumer PC, use the built-in Windows Update service.
Does installing the update guarantee my PC is secure?
No single patch can guarantee security. It closes vulnerabilities addressed by that update. Users should also keep browsers and applications updated, use endpoint protection, enable strong account security and avoid suspicious downloads.
What if Windows Update says there are no updates?
If the PC is on a supported Windows version and says it is fully up to date after checking manually, it may already have the September cumulative update. Review update history if you need to confirm the installed KB/build for your version.
Bottom line
September 2026 is a patch cycle where speed matters. Microsoft has confirmed exploitation of two Windows privilege-escalation vulnerabilities and is telling customers to install the security updates promptly. The dramatic “nearly 1,000 vulnerabilities” headline explains the scale, but the actionable story is much simpler: update supported Windows devices, verify the update actually installed, and prioritize privileged or exposed business systems first.
Sources and related coverage
- Microsoft Security Response Center: September 2026 security update
- Microsoft Windows Message Center
- BleepingComputer: September Patch Tuesday analysis
- TechRadar: record September security release
More from Digital Pulse Brief: explore Cybersecurity & Privacy, read our GPT-6 Astra guide, or see the iPhone Duo price and specs guide.
Editorial note: Microsoft can revise Security Update Guide entries after publication. This article reflects information available on September 14, 2026.
Get clear AI, technology and business insights in your inbox
Breaking developments, practical explainers, reviews and useful tech intelligence — without the noise.
How to Back Up Windows 11 Properly: OneDrive, External Drives and the 3-2-1 Rule
Prompt Injection Explained: Why AI Agents Can Follow Malicious Instructions and How to Reduce the Risk
