A patch load no enterprise can fully absorb in one cycle
Microsoft's September 2026 Patch Tuesday closed out 966 vulnerabilities, the largest single release the company has ever shipped and well over double August's already sizable 400-flaw update. Of those, 105 are rated critical: 81 remote code execution bugs, 20 elevation-of-privilege flaws, two information-disclosure issues, and one security feature bypass. The remainder splits across 438 elevation-of-privilege bugs, 258 remote code execution flaws, 173 information-disclosure issues, 56 denial-of-service bugs, 19 security feature bypasses, and 16 spoofing flaws.
Treating all 966 items as equally urgent buries the two that already have live attackers behind them under nine hundred that do not. Treating the release as routine background maintenance carries its own cost, since it assumes this month behaves like every other month when Microsoft's own data says it does not. The decision every CISO owns this week is which subset to patch first, on what evidence, and how quickly the two confirmed zero-days move from advisory to deployed fix across the full Windows fleet.
Two zero-days are already escalating attackers to SYSTEM
CVE-2026-81963 is a Windows Update Stack elevation-of-privilege flaw rooted in improper link resolution, letting a local attacker escalate to SYSTEM. Microsoft credits Romain Deperne and its own Threat Intelligence Center with the find, and confirms active exploitation. It is the first Windows Update Stack EoP bug exploited as a zero-day since Microsoft began issuing similar patches in 2022, which tells us attackers have been probing this specific subsystem for years and only now found a working path in.
CVE-2026-85880 hits Windows Advanced Local Procedure Call, a heap-based buffer overflow that again escalates a low-privilege attacker to SYSTEM. Volexity, along with researchers Mark Kelly, David Galazin, and Jeremy Hedges at Proofpoint, get the credit, and it is the first ALPC bug on a Patch Tuesday in over three years. Both carry a CVSS score of only 7.8, low enough that automated severity scoring would rank them behind dozens of other bugs in this release, yet both are the two Microsoft confirms attackers are already using against real machines.
The bug that deserves more urgency than either zero-day
CVE-2026-69730 is a Windows DNS Server remote code execution flaw carrying a 9.8 CVSS score, the highest severity rating in this release, along with Microsoft's own "exploitation more likely" assessment attached directly to the advisory. Confirmed active exploitation has not landed yet, and Microsoft's own likelihood label already puts it ahead of most of this month's confirmed bugs in terms of how fast defenders should move. A critical, unauthenticated RCE sitting inside a service that handles enterprise network resolution tends to go from disclosed to weaponized within days once researchers or attackers reverse the patch, a pattern that has repeated across DNS and directory-service flaws for years running.
For any organization running Windows DNS Server on infrastructure reachable from a broader internal network, let alone the internet, this belongs at the top of this week's patch queue, ahead of the two confirmed zero-days. Exploitability likely tomorrow at a 9.8 severity against core network infrastructure carries more weight than exploitability confirmed today against a single endpoint, and patch sequencing should reflect that math rather than default to whatever CVE has the word "exploited" already stamped on it.
Why the volume keeps climbing: AI is finding bugs faster than teams can patch
Microsoft's own account of the surge points to its AI-powered vulnerability discovery system, now generating findings at a pace that has pushed monthly patch counts from roughly 570 in July to 400 in August to 966 in September. That represents a real defender-side win in the sense that bugs are getting found and fixed before adversaries stumble onto them independently, but it also shifts the bottleneck downstream to every IT organization that now has to validate, stage, and deploy patches at a volume their existing change-management processes were built for a much smaller monthly load, not for near-triple-digit growth in a single cycle.
This is the same dynamic playing out industry-wide as AI-assisted fuzzing and code review tools mature: vendors can generate fixes faster than customers can consume them, and that gap between disclosure and deployment is exactly where risk concentrates. A 966-item patch list functions as a forcing argument for automating patch validation and staged rollout, since manual review of a list this size guarantees some fraction of it never gets applied in a timely way regardless of how disciplined the team running it happens to be.
What belongs on this week's action list
Deploy CVE-2026-81963 and CVE-2026-85880 immediately across all Windows fleets; both are confirmed exploited and both grant SYSTEM access, the precondition ransomware operators need for lateral movement and payload deployment on a compromised host. Give CVE-2026-69730 equal or higher priority on any server running Windows DNS Server that sits reachable beyond a tightly controlled management network, given its 9.8 score and Microsoft's own likelihood assessment pointing at imminent exploitation. Confirm patch deployment with an actual scan rather than a change-ticket status, since a 966-item release is exactly the kind of month where a patch marked "applied" in a ticketing system quietly failed to install on a subset of machines.
Sequence the remaining 963 fixes by actual exposure next: internet-facing systems and anything running the Graphics Fonts or IP Helper components tied to this month's other critical RCEs, CVE-2026-72986, CVE-2026-73018, and CVE-2026-72981, come after the top three, with the bulk of the elevation-of-privilege backlog following through the normal patch cycle. A 966-flaw release is not a month to clear every item on the list; it is a month to prove the triage process holds up when the volume finally exceeds what any team can review line by line.



