Microsoft fixes 960-plus flaws in its largest Patch Tuesday yet
Trackers counted 964 to 974 fixes in September, Microsoft's largest batch yet, with two Windows zero-days already being exploited.
Microsoft released its September 2026 security updates on 8 September, fixing 966 vulnerabilities by BleepingComputer's count, the largest monthly release the company has ever made. Two of the flaws were already being used by attackers. Both let someone who already has limited access to a Windows computer take full control of it.
- 966flaws fixed on 8 September, by BleepingComputer's count
- 105flaws rated critical, by BleepingComputer's count
- 438elevation-of-privilege flaws, the largest group
- 570 / 400flaws fixed in July and in August 2026
- 7.8severity score of each of the two zero-days
What happened
Microsoft publishes security fixes on the second Tuesday of each month, a routine known as Patch Tuesday. The September 2026 release was far larger than usual. BleepingComputer counted 966 flaws released on the day itself, not counting 204 cloud and browser fixes published earlier in the month. Malwarebytes counted 964 that customers need to install, out of 974 listed by Microsoft, because Microsoft fixes 10 of them in its own cloud services. Both outlets called it a record.
The growth has been fast. According to BleepingComputer, Microsoft fixed 570 flaws in July 2026 and 400 in August. In September, about 105 of the flaws were rated critical, most of them allowing remote code execution, which means an attacker can run their own program on someone else's machine. By type, the largest group was elevation of privilege, at 438 flaws, followed by 258 remote code execution flaws and 173 information disclosure flaws. Malwarebytes listed fixes for the Windows DNS Server, Remote Desktop Services, Exchange Server, SharePoint, SQL Server and Office.
BleepingComputer linked the jump in numbers to Microsoft's use of an AI-powered system for finding vulnerabilities across its products. The report did not name the system or say how many of the 966 flaws it found. Malwarebytes did not discuss the cause. Microsoft also released non-security updates for Windows 11 and an extended security update for Windows 10 in the same cycle, so home users received the fixes through the normal Windows Update screen.
The engineering behind it
Microsoft calls a flaw a zero-day if it was made public or used by attackers before a fix existed. Both September zero-days were being exploited. The first, CVE-2026-81963, is in the Windows Update Stack. Windows could be tricked into following a link, a pointer to another file, without checking where it leads, so it opened or changed the wrong file. Malwarebytes gives it a severity score of 7.8 out of 10.
The second, CVE-2026-85880, is in ALPC, short for Advanced Local Procedure Call, an internal messaging system that lets programs on the same computer talk to each other. It is a heap-based buffer overflow, where a program writes more data into a memory area than it can hold. According to Malwarebytes, an attacker running code inside a restricted sandbox could use it to escape and gain higher rights. It also scores 7.8. BleepingComputer says it was reported by Volexity and researchers at Proofpoint.
Neither flaw lets an attacker in from outside on its own. Both are local privilege escalation bugs, which raise an intruder's rights to SYSTEM, the highest level in Windows. An attacker first needs a foothold, for example through a phishing email or a stolen password. Malwarebytes explains that SYSTEM access then lets an intruder switch off security tools, read protected data, stay hidden and move to other machines on the network.
BleepingComputer did not describe how Microsoft's AI system works. In general, automated bug finding has two older forms. Static analysis reads source code and looks for risky patterns, such as copying data without a size check. Fuzzing runs a program millions of times with random or malformed input and records every crash. AI models can add a third step: reading the code around a warning, judging whether it is a real flaw, and suggesting a fix. More flaws found before attackers find them is good, but each one still has to be fixed and shipped.
What it means in Nepal
The sources say nothing about Nepal, but the work they describe is the same in every office that runs Windows. If AI tools help vendors find hundreds of extra flaws each month, the people who look after computers must test and install many more updates. A system administrator cannot apply every patch at once on every server. They have to decide what to fix first, test that the fix does not break important software, and plan when to restart machines.
That decision uses a few basic signals. One is the severity score. Another is whether the flaw is already being exploited, which is why the two zero-days come first even though their scores are not the highest. A third is exposure, meaning whether the affected system faces the internet. Learning to read a monthly security release this way, and to keep a list of which machines run which software, is a practical skill for anyone who will manage computers.
The zero-days also show why basic computer science still matters. A buffer overflow is one of the oldest kinds of programming error. It happens when code copies data without checking its size. Link-following bugs come from trusting a file path without checking it. Both are taught in early programming and operating-systems courses, and both still appear in one of the most widely used operating systems in the world.
What to study if this interests you
Computer Programming, ENCT 101, in the first semester of BCT, teaches C, including arrays, pointers and memory, which is where buffer overflows come from. The course has a full guide on this site. Operating System, ENCT 254, in the fourth semester, explains processes, memory management, file systems and privilege levels, the background for understanding how SYSTEM access is protected.
Network and Cyber Security, ENCT 463, in the eighth semester of BCT, covers attack types, access control and security practice, including how organisations respond to new vulnerabilities. A useful exercise during the degree is to read one month of Microsoft's security release notes, sort the flaws by type and exploitation status, and decide in what order to patch a small office network. That turns the theory from these courses into a habit.
Words in this story
- Zero-day
- A security flaw that attackers know about or use before the maker has released a fix.
- Privilege escalation
- An attack that raises a user's or program's rights, for example from a normal user to full system control.
- Buffer overflow
- A bug in which a program writes more data into a memory area than it can hold, overwriting nearby memory.
- Remote code execution
- A flaw that lets an attacker run their own program on another computer, often over a network.
Where this comes from
- BleepingComputer, 8 Sep 2026
- Malwarebytes, 9 Sep 2026
Written in our own words; no sentence is copied from these reports. Researched with AI assistance on 11 October 2026; no member of faculty has reviewed it yet. If you spot a mistake, call 01-5091616 and we will correct it and say so.




