HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Microsoft Releases Record‑Breaking Patch Tuesday: 974 CVEs, 2 Actively‑Exploited Zero‑Days and 20 Wormable Bugs

Microsoft’s September 2026 Patch Tuesday fixed 974 CVEs, including two zero‑days under active exploitation and a critical Exchange RCE. The breadth of the update underscores the need for continuous vulnerability‑management evidence to satisfy audit‑ready control objectives.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Microsoft Releases Record‑Breaking Patch Tuesday: 974 CVEs, 2 Actively‑Exploited Zero‑Days and 20 Wormable Bugs

What Happened – Microsoft’s September 2026 Patch Tuesday delivered fixes for a record‑high 974 CVEs across Windows, Azure, Entra ID, Edge and other services. The release includes two zero‑day flaws that are already being exploited (CVE‑2026‑85880 in ALPC and CVE‑2026‑81963 in the Windows Update stack) and a critical remote‑code‑execution bug in Exchange (CVE‑2026‑55007). Twenty of the patched issues are classified as wormable.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management program that can ingest, prioritize and remediate high‑severity flaws faster than attackers can weaponize them.
  • Provides a concrete audit‑ready evidence point: documented patch cycles, CVE tracking and proof of remediation satisfy the “vulnerability remediation” control objective across multiple frameworks.
  • Highlights the importance of automated evidence collection (e.g., patch‑status dashboards) to maintain a defensible posture for regulators and auditors.

Who Is Affected – Enterprises that run Microsoft Windows, Azure cloud workloads, Microsoft 365/Exchange, Entra ID, or any downstream services that rely on Microsoft code. Typical sectors include technology, financial services, healthcare, and any organization with a large Windows footprint.

Recommended Actions

  1. Verify that the September 2026 patches have been applied to all affected assets; use a centralized patch‑management tool to confirm compliance.
  2. Map each CVE to the relevant “vulnerability remediation” control in your audit framework and capture remediation evidence (patch logs, configuration baselines).
  3. Prioritize the two exploited zero‑days and the Exchange RCE for immediate verification, then schedule the remaining wormable bugs for the next maintenance window.

Technical Notes

  • CVE‑2026‑85880: Heap buffer overflow in Windows Advanced Local Procedure Call (ALPC), CVSS 7.8, local privilege escalation.
  • CVE‑2026‑81963: Flaw in Windows Update stack, CVSS 7.8, remote link leads to privilege escalation after initial foothold.
  • CVE‑2026‑55007: Unauthenticated RCE in Exchange via crafted Visio attachment, CVSS 9.8, remote code execution without user interaction.
  • Additional 20 wormable bugs span Windows kernel, Edge browser, and Azure services; all rated “high” or “critical” by Microsoft.

Source: Security Affairs – Microsoft’s Biggest Patch Tuesday

📰 Original Source
https://securityaffairs.com/198705/security/microsofts-biggest-patch-tuesday-974-cves-2-zero-days-and-20-wormable-bugs.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →