NEWS
Microsoft’s Record Patch Tuesday Overloads the Fix Queue
AI-driven scanning pushed Microsoft Patch Tuesday to 974 CVEs, so wormable DNS and Exchange bugs share the same fix queue as the rest.
Microsoft shipped 974 Microsoft CVEs in the September release on September 8, 2026, a new Patch Tuesday record that includes two Windows bugs already used in attacks. Windows alone took 723 of those fixes. Qualys counted 113 as critical.
CISA put both exploited bugs on its Known Exploited Vulnerabilities list the same day, with a September 22 due date for federal civilian agencies. Most shops now have to pull 20 wormable server flaws, an Exchange Visio bug, and two SYSTEM bugs out of that 974-item pile before the change window closes.
974 CVEs Landed in a Single Patch Tuesday
Microsoft’s Security Update Guide is the count that matters, and it is not a rounding error. The company also republished 25 non-Microsoft CVEs beside that 974. Elevation of privilege led the mix, with 438 bugs in that class, and 258 were remote code execution.
Office and Office 2016 share a set of 111 CVEs, listed twice because the servicing model differs. SQL Server took 62. SharePoint Server took 16. Exchange Server took nine. Those server products are where a late patch still turns into a breach, even if a desktop can wait a week.
SEPTEMBER PRODUCT FAMILY COUNTS
| Product family | CVEs addressed |
|---|---|
| Windows | 723 |
| Office (same set as Office 2016) | 111 |
| SQL Server | 62 |
| Developer Tools | 22 |
| SharePoint Server | 16 |
| Azure | 12 |
| Skype for Business | 10 |
| Exchange Server | 9 |
| Other | 9 |
Satnam Narang, senior staff research engineer at Tenable, noted that September’s haul sits not far off the 1,130 CVEs Microsoft issued in all of 2025. Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative, counted 972 new CVEs under his own method and 997 once Chromium and external bugs are folded in. The working figure in this piece is Microsoft’s 974.
Microsoft Told Customers in July to Expect More Patches
On July 9, 2026, Pavan Davuluri, executive vice president for Windows + Devices, said AI had changed how fast Windows can find holes in its own code. The tool is Microsoft Security’s multi-model agentic scanning harness, or MDASH, which runs several models, including third-party ones, against Windows binaries on dedicated cloud kit.
A scanner pipeline checks candidates through what Microsoft calls multi-model debate. Confirmed finds then go to a Windows-specific prove pipeline that is meant to strip out false positives before engineers see them. Davuluri tied that pipeline to a customer-facing fact: more findings would show up in each monthly packet.
As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release.
Pavan Davuluri, Executive Vice President, Windows + Devices, Windows Experience Blog
He called that volume evidence that defenders are getting better at finding issues. Microsoft also pointed customers at the Security Update Validation Program and at hotpatching for some Windows Server Azure Edition virtual machines, which is now generally available. Those are the company’s answers to a packet that no longer fits a quiet Tuesday night.
THE PATCH SURGE SINCE JULY
- July 9, 2026: Davuluri publishes the MDASH note and warns of a higher volume of security updates in each release.
- September 8, 2026: Microsoft ships 974 CVEs; CISA adds the two exploited Windows bugs to KEV.
- September 22, 2026: Federal civilian agencies face the KEV due date for those two bugs.
- October 13, 2026: The next Patch Tuesday lands, on the usual second-Tuesday cycle.
A finite backlog of old bugs can still be a real cleanup, and that is the kinder reading of MDASH. It does not shrink this month’s change calendar. Childs put the mood in plainer terms: the security teams inside Microsoft can patch at this rate, and AI-assisted discovery shows no sign of slowing down, but he has not seen a matching spike in live attacks yet.
Two Exploited Windows Bugs Already Grant SYSTEM
Both exploited bugs are local elevation-of-privilege flaws rated Important at CVSS 7.8. Neither is a remote break-in on its own. Each is the second stage after phishing, a stolen token, or a code-execution bug has already put a low-rights process on the box.
CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call, the inter-process plumbing Windows uses all day. Microsoft said an attacker who can run code in a low-privilege AppContainer could use it to leave that sandbox and raise rights on the machine, with no extra click. Tenable’s notes say 16 ALPC bugs have been patched since 2022, that this is the first ALPC item on Patch Tuesday since April 2023, and that it is only the second ALPC zero-day since CVE-2023-21674 in January 2023. Proofpoint researchers reported it. It hits Windows 10 and Windows Server 2012 through 2022.
CVE-2026-81963 sits in the Windows Update Stack, the code that actually installs updates. Microsoft described it as improper link resolution before file access, which lets a logged-in low-rights attacker reach SYSTEM. Tenable counted seven Update Stack elevation bugs since 2022 and said this is the first one confirmed in live attacks. Microsoft’s Threat Intelligence Centre is on the credit line. Childs said he doubts the automatic update path itself is compromised, and that the bug is more likely being chained with a code-execution flaw to spread malware or ransomware. It hits Windows 11 versions 23H2, 24H2, 25H2 and 26H1, plus Windows Server 2025.
Microsoft rated 58 of this month’s fixes as more likely to be exploited. The two already in use still sit at the front of that list because someone is using them now.
WHAT WE KNOW
- KEV status: The Canadian Centre for Cyber Security said CISA listed both bugs on September 8 and set a September 22 remediation date for U.S. federal civilian agencies, a 14-day clock.
- Attack path: Both bugs need local, authorized access and then raise the process to SYSTEM, which is why they pair with an earlier foothold.
- Who found them: Proofpoint is on the ALPC report; Microsoft’s own threat team is on the Update Stack report.
WHAT IS UNCONFIRMED
- Scale of use: Microsoft has not said how widely either exploit is being used, or which crews are using it.
- The chain: No public write-up yet shows the first-stage bug paired with CVE-2026-81963 in the wild.
- Build proof: Administrators still have to confirm their own OS builds after the September cumulatives, because Microsoft has not published a single public victim list.
Assume they are coming, Childs said, and patch quickly. That is the whole operational fact hiding under 974 line items.
Why Exchange Admins Should Patch the Visio RCE First
CVE-2026-55007 lets a stranger on the network send a Visio file that Exchange may run while it indexes mail, with no click from a user. Microsoft rates it Important at CVSS 8.1 and Exploitation Less Likely, and it needs the server under memory pressure to fire, but Childs still calls it the Exchange patch that cannot wait. Microsoft listed nine Exchange Server bugs this month, and this is the one that turns an unopened message into code on the server.
An unauthenticated attacker could send a specially crafted Visio attachment to an affected Exchange server. The server could process the attachment during content indexing, and successful exploitation could allow the attacker to execute code on the server. User interaction is not required.
Microsoft, CVE-2026-55007 advisory
The same advisory says a successful hit needs sustained low memory, which is not the usual state of a healthy server, and that this is why the specially crafted Visio attachment is hard to fire on demand. Childs’s reply is the one that matters for anyone still running Exchange on the internet: an attacker only needs to get it right once. Microsoft’s known-issue list for this packet already names Exchange Server Subscription Edition, Exchange Server 2019, CU14, and Exchange 2016 CU23, so test the downtime, then take it.
CVE-2026-69380 is the sibling that security teams should not park behind a desktop wave. Childs described a low-rights mailbox user who abuses request and token checks to impersonate any user and take over every mailbox, reading mail, sending as others, and pulling attachments. After a phish, that turns one account into the whole org’s mail. He also flagged CVE-2026-69356, a crafted calendar invite that runs script in the victim’s context when they hit Join. An unauthenticated mail-processing RCE and a mailbox-takeover elevation in the same cumulative update is a chain on paper: first access, then lateral movement, one installer.
Wormable Code Hits DNS, DHCP, RDP, and SMB
Childs counted 20 patches that meet the old worm test: remote, no login, no user click, arbitrary code. He wrote that having 20 of them in a single release is something else. The affected components are the ones every Windows domain actually runs, including DHCP Server, Active Directory Domain Services, DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, Internet Connection Sharing, SSTP, and failover clustering.
CVE-2026-69730 is the DNS bug he called SigRed’s spiritual successor, a nod to the 2020 Windows DNS wormable flaw. Tenable scored this one at CVSS 9.8, Critical, a use-after-free that lets a remote attacker with no login send a crafted packet and run code. Childs’s DNS notes go further than one CVE: 18 DNS bugs this month, 10 of them code execution, mostly use-after-frees in record handling, on the service that lives on domain controllers.
Remote Desktop is the other 9.8. CVE-2026-69525 is a use-after-free that lets an in-network attacker with no login run code. Microsoft still tags the vector as in-network, while the CVSS network score reads broader. Tenable’s exploitability line is Exploitation More Likely. Childs’s advice was to treat it as urgent, test, and ship, because RDP is everywhere in enterprise estates.
URGENT NETWORK CVES IN THIS PACKET
| CVE | Component | Rating |
|---|---|---|
| CVE-2026-69730 | Windows DNS Server | CVSS 9.8, Critical, SigRed comparison |
| CVE-2026-69525 | Remote Desktop Services | CVSS 9.8, Exploitation More Likely |
| CVE-2026-69524 | Active Directory Domain Services | Wormable RCE, no login |
| CVE-2026-69510 | Windows DHCP Server | Wormable RCE, no login |
| CVE-2026-72936 | Windows SMB Client | Wormable RCE, no login |
| CVE-2026-72982 | Windows Netlogon | Wormable RCE, no login |
The rest of Childs’s wormable set includes a second DHCP bug, two more DNS RCEs, RRAS, NFS ONCRPC, IP Helper, ICS, SSTP, two Message Queuing RCEs, three RMCAST transport bugs, and two failover-cluster RCEs. None of those need a user to open a file. They need a reachable service and a packet.
WORMABLE SERVICE FAMILIES
- Name services: DNS Server, including CVE-2026-69730, CVE-2026-69858, and CVE-2026-72987, which sit on domain controllers.
- Directory and login: Active Directory Domain Services and Netlogon, the pair that turns one unpatched DC into a forest problem.
- Address and file: DHCP Server, SMB Client, and NFS ONCRPC, which are easy to forget because they feel like plumbing.
- Remote access: RRAS, SSTP, ICS, and IP Helper, plus the separate RDP 9.8 that Microsoft will not call wormable in the same breath.
A global worm has not shown up in years, and Childs has not seen the exploit spike that a 974-CVE month might imply. DNS at 9.8 is still the kind of bug that changes that sentence if someone writes a reliable trigger.
SharePoint, SQL Copilot, and Android Token Theft
Internet-facing collaboration servers are the other queue that cannot wait for a desktop ring. Childs counted four SharePoint remote code execution bugs in the release, including CVE-2026-69465, where an authenticated user submits a page that skips a safety check and makes the server load code from a filesystem the attacker controls. Microsoft listed 16 SharePoint Server CVEs. SharePoint has already been a live target in 2026, which is why Childs told anyone with those servers on the internet to test and deploy fast.
THREE MORE QUEUES THAT SKIP THE DESKTOP WAVE
- SQL Server, 62 CVEs: Childs singled out CVE-2026-65669, which needs a user to feed crafted instructions to SQL Copilot in SQL Server Management Studio, after which the attacker inherits that user’s database rights. Patching SQL this month is slow, so internet-reachable instances go first.
- Android Microsoft Authenticator: CVE-2026-80097 lets a malicious app collect valid access tokens after the user finishes an auth step. Childs called it the worst kind of elevation because it lives in the login path itself.
- Office on the endpoint: The 111 Office CVEs include a long list of document-based code execution bugs in Word, Excel, and PowerPoint. Those can wait behind KEV, Exchange, DNS, and RDP only if mail gating is actually on.
Narang’s line is the one that keeps this from becoming a panic about every row in the MSRC table. AI-assisted discovery in 2026 is creating larger haystacks, he said, but it is not finding more needles, and shops still have to know which bugs they actually run and which of those are reachable. The haystack is Microsoft’s. The needles this month are named.
Federal Agencies Have Until September 22
CISA’s KEV listing does not rank Exchange, DNS, or RDP. It ranks the two bugs someone is already using. Binding Operational Directive 22-01 is what turns that listing into a date for U.S. federal civilian agencies, and the date is September 22, 2026. Private-sector teams copy that list because it is the closest thing the industry has to a public “do this first” order, even when the rest of the packet is 972 items longer.
The kinder argument about MDASH is that a program with a finite number of lines cannot hide an infinite number of holes, so this flood is a backlog being drained. That may even be true over a few years. It is not a plan for a domain controller that still speaks DNS on September 21, or for an Exchange box that still indexes Visio on the way in.
Microsoft’s next Patch Tuesday is October 13, 2026. The September 22 KEV clock runs out first. The 20 wormable server bugs, CVE-2026-55007, CVE-2026-69525, and the two SYSTEM elevations are the work that has to finish before either date, because the other 900 fixes will still be there when the next packet arrives.
-
NEWS4 weeks agoMicrosoft 365 Auth Fault Took Down Exchange and Teams
-
GAMING4 weeks agoXbox Caps Game Pass Cloud Gaming at 15 Hours
-
NEWS4 weeks agoOpenClaw 2.0 Ships a Team Workplace With Host-Trust Defaults
-
NEWS4 weeks agoSony and Warner Sue Anthropic Over Torrented Song Lyrics
-
BUSINESS4 weeks agoChargePoint Stock Rally Prices Wilmer’s Three-Year Cash Plan
-
NEWS4 weeks agoIFA 2026’s Weird Gadgets Are Building a Sensor Home
-
BUSINESS4 weeks agoDiesel Breaks Its Record as the White House Claims Credit
-
NEWS4 weeks agoOpenAI Unveils GPT-6 Astra With a Critical Cyber Label
