Microsoft Patches Record 964 Flaws, Including Two Actively Exploited Zero‑Day Elevation‑of‑Privilege Bugs
What Happened — Microsoft’s September 2026 Patch Tuesday released fixes for 964 CVEs (104 Critical, 860 Important), the largest batch on record. The update contains patches for two zero‑day elevation‑of‑privilege (EoP) bugs that were already being exploited in the wild.
Why It Matters for Trust & Control Assurance
- Unpatched EoP flaws undermine the “maintain a secure configuration” control objective, a cornerstone of continuous control‑assurance programs.
- Demonstrating timely patch deployment provides defensible audit evidence that your organization meets vulnerability‑management expectations across multiple frameworks.
- Verisq’s Control Mapping capability can automatically collect and correlate patch‑status evidence, simplifying proof of compliance.
Who Is Affected – Enterprises across technology, finance, healthcare, and any sector that runs Windows desktops or servers.
Recommended Actions – Verify that the September 2026 updates are applied to all Windows endpoints, enable automatic update enforcement, inventory patch status in a CMDB, and capture evidence of remediation for audit readiness. Source: Malwarebytes Labs
Technical Notes – The two zero‑days (CVE‑2026‑81963, CVE‑2026‑85880) are local EoP bugs (CVSS 7.8) that let an attacker with initial access obtain SYSTEM privileges. Additional high‑severity RCE bugs affect Windows DNS Server, Remote Desktop Services, Exchange, SharePoint, SQL Server, and Office. Source: [Microsoft Security Advisory]