Microsoft’s September updates fix a record 973 security flaws


The next Patch Tuesday is scheduled for October 13th, 2026.

Windows security vulnerabilities

A large number of the vulnerabilities—over 700 this time—are spread across the various Windows versions (10, 11, Server) for which Microsoft still provides security updates.

This month, two Windows vulnerabilities classified as high risk are already being exploited in the wild. The CVE-2026-81963 vulnerability in the Windows Update stack allows attackers to gain elevated privileges, enabling them to execute code with system privileges by combining this exploit with an RCE vulnerability.

The second zero-day vulnerability, CVE-2026-85880, is in Windows Advanced Local Procedure Call (ALPC) and it’s also an elevation of privilege (EoP) vulnerability. In this case, the exploit code must be concealed within a document so that a user can trigger it. For both zero-days, it’s unclear how widespread the attacks are.

Critical Windows vulnerabilities

Microsoft has classified 77 Windows vulnerabilities as critical, including 56 RCE vulnerabilities. These include CVE-2026-69525 in the Windows Remote Desktop Service, a use-after-free (UAF) vulnerability that an attacker could exploit to remotely execute injected code without authentication or user interaction.

Windows Hello also has nine vulnerabilities, eight of which are EoP vulnerabilities classified as critical. Microsoft had to patch 64 vulnerabilities in the biometric service, most of them very similar to one another and following the same pattern. In 56 cases, there are buffer overflows. CVE-2026-69727 allows elevated privileges over the network, while CVE-2026-73008 exposes personal data—hardly what one would want or expect from a biometric service.

Exit mobile version