HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Microsoft Patches Record 964 Flaws, Including Two Actively Exploited Zero‑Day Elevation‑of‑Privilege Bugs

Microsoft’s September 2026 Patch Tuesday delivered fixes for 964 vulnerabilities, among them two zero‑day elevation‑of‑privilege bugs already being exploited. Timely remediation is a key control‑assurance signal for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 malwarebytes.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Microsoft Patches Record 964 Flaws, Including Two Actively Exploited Zero‑Day Elevation‑of‑Privilege Bugs

What Happened — Microsoft’s September 2026 Patch Tuesday released fixes for 964 CVEs (104 Critical, 860 Important), the largest batch on record. The update contains patches for two zero‑day elevation‑of‑privilege (EoP) bugs that were already being exploited in the wild.

Why It Matters for Trust & Control Assurance

  • Unpatched EoP flaws undermine the “maintain a secure configuration” control objective, a cornerstone of continuous control‑assurance programs.
  • Demonstrating timely patch deployment provides defensible audit evidence that your organization meets vulnerability‑management expectations across multiple frameworks.
  • Verisq’s Control Mapping capability can automatically collect and correlate patch‑status evidence, simplifying proof of compliance.

Who Is Affected – Enterprises across technology, finance, healthcare, and any sector that runs Windows desktops or servers.

Recommended Actions – Verify that the September 2026 updates are applied to all Windows endpoints, enable automatic update enforcement, inventory patch status in a CMDB, and capture evidence of remediation for audit readiness. Source: Malwarebytes Labs

Technical Notes – The two zero‑days (CVE‑2026‑81963, CVE‑2026‑85880) are local EoP bugs (CVSS 7.8) that let an attacker with initial access obtain SYSTEM privileges. Additional high‑severity RCE bugs affect Windows DNS Server, Remote Desktop Services, Exchange, SharePoint, SQL Server, and Office. Source: [Microsoft Security Advisory]

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →