Skip to content
Auto-CTI
Back to all deep dives
RAPID7 CYBERSECURITY BLOG

Patch Tuesday - September 2026

KEV CRITICAL Patch Tuesday Windows EoP zero-day
Patch Tuesday - September 2026

Strategic summary

On September 2026 Patch Tuesday, Microsoft published 999 vulnerabilities total: 974 in its own products including 723 Windows vulnerabilities, plus fixes for 25 non-Microsoft CVEs. This is the largest single-day CVE release ever. Microsoft confirmed active exploitation for two zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack, both enabling privilege escalation to SYSTEM. Windows 11 and Server 2025 do not receive patches for CVE-2026-85880, likely due to Rust-based memory safety improvements.

Key findings

  • Record Patch Tuesday with 999 CVEs, including 974 Microsoft product vulnerabilities and 723 Windows vulnerabilities.
  • Two actively exploited zero-days: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), both leading to SYSTEM privileges.
  • CVE-2026-85880 is a buffer overflow allowing out-of-bounds write; it does not affect Windows 11 or Server 2025, suggesting Rust memory safety benefits.
  • CVE-2026-81963 affects all supported Windows versions with CVSS v3 base score 7.8 and involves improper link resolution.
  • Microsoft does not expect Patch Tuesday volumes to return to lower pre-2026 levels.

Relevance for you

Two Windows EoP zero-days (ALPC, Update Stack) with active exploitation are addressed in Microsoft Patch Tuesday September 2026; CVSS 7.8 may understate operational risk for systems vulnerable to locally-exploitable privilege-escalation vectors.

Mentioned CVEs

Risk score

95
cvss base
78.00
kev bonus
20.00
epss bonus
0.00
poc bonus
15.00
raw before weight
113.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-5.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • VENDOR_MISMATCH Vendor not found in alert title −5
Consensus penalty:
−5.0
Total penalty:
−5.0
ESC