Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

MediumBleepingComputer · Lawrence Abrams·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
Microsoft
Reported by
2 outlets

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.

When BleepingComputer reports on Patch Tuesday security updates, we only count vulnerabilities released by Microsoft on Patch Tuesday itself.

Therefore, today's total does not include 204 flaws fixed earlier this month, including vulnerabilities in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge (Chromium-based), Microsoft Fabric, and Power Automate.

This month's Patch Tuesday fixes two actively exploited zero-day vulnerabilities.

Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.

The actively exploited zero-day vulnerabilities addressed during this the September 2026 Patch Tuesday are:

Microsoft has patched an actively exploited elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges.

"Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.," warns Microsoft.

The flaws were credited to Romain Deperne and the Microsoft Threat Intelligence Centre (MSTIC).

No details have been shared on how the flaw was exploited in attacks.

Microsoft has fixed a Windows Advanced Local Procedure Call (ALPC) flaw that was exploited in attacks to gain SYSTEM privileges.

"Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally," explains Microsoft.

Microsoft has not shared any details on how this flaw was exploited in attacks.

The flaw were discovered by Volexity and Mark Kelly, David Galazin, Jeremy Hedges with Proofpoint

Below is the complete list of resolved vulnerabilities in the September 2026 updates. Note, this report does include the flaws fixed earlier this month.

To access the full description of each vulnerability and the systems it affects, you can view the full report here.

Reproduced in full under licence from BleepingComputer. © BleepingComputer. Written by Lawrence Abrams.

Read at bleepingcomputer.comReported by 2 independent outlets

Coverage

2 outlets carried this story. Agreement across independent sources is the strongest signal on the site, and the hardest to fake.

  1. BleepingComputerEstablished SourceFirst reported

    2026-09-08 18:18 UTC

  2. Hacker NewsAggregated Source

    2026-09-08 20:03 UTC

Related stories