AntiMalwareSeptember 9, 2026🇷🇺Translated from Russian

Microsoft Releases Record 966 Patches in Largest Patch Tuesday Ever, Including Two Actively Exploited Zero-Days

Microsoft has delivered its largest-ever monthly security update, releasing patches for a record 966 vulnerabilities in the September Patch Tuesday cycle. This marks the biggest single-month fix count in the company's history and significantly exceeds the 570 issues addressed in July and the 400 resolved in August.

The update closes two actively exploited zero-day vulnerabilities. The first, CVE-2026-81963, resides in the Windows Update stack and stems from improper link handling. An authenticated local attacker could leverage it to escalate privileges to SYSTEM level. The second zero-day, CVE-2026-85880, affects the Windows ALPC mechanism through a buffer overflow that similarly grants attackers SYSTEM privileges. Microsoft has not disclosed details on the attack campaigns or the threat actors behind the exploitation.

Of the total fixes, 105 vulnerabilities carry a critical severity rating. The largest categories are privilege-escalation issues (438) and remote-code-execution flaws (258). Additional problems allow security-feature bypasses, information disclosure, denial-of-service conditions, and data tampering.

The 966 patches do not include another 204 vulnerabilities fixed earlier in September in products such as Azure, Copilot Studio, Entra ID, Edge, Microsoft Fabric, and Power Automate. The sharp increase in volume aligns with Microsoft's recent adoption of an AI-powered system designed to identify security bugs in its own software.

Selected Patched Vulnerabilities

  • .NET – Multiple Elevation of Privilege and Information Disclosure issues (CVE-2026-69805, CVE-2026-58649, CVE-2026-69806)
  • Active Directory Certificate Services (AD CS) – Several Elevation of Privilege and Tampering vulnerabilities (CVE-2026-69821, CVE-2026-69624)
  • Azure AI Language and Azure Cosmos DB – Critical Elevation of Privilege and Spoofing flaws
  • Graphic Fonts – Critical Remote Code Execution vulnerabilities (CVE-2026-72986, CVE-2026-73018)

Administrators are strongly advised to apply the updates immediately, especially on systems exposed to the internet or handling sensitive workloads.

Related articles

HabrVulnerabilities & Exploits

Asset and Vulnerability Management in Practice: Building a Working Process with MaxPatrol VM and NetBox

This detailed guide explains how organizations can implement effective asset and vulnerability management by focusing on reliable infrastructure data, IT collaboration, and automation. It draws from real-world projects using MaxPatrol VM, NetBox, and 1C:ERP to demonstrate dynamic grouping, webhook-driven asset onboarding, and deviation-based control. The approach emphasizes eight core principles including minimizing human dependency, just-in-time awareness, maximum data accuracy, and embedding security into existing IT workflows. Technical flows cover automatic scanning initiation upon asset creation in NetBox, categorization against unacceptable events, and priority-based patching cycles aligned with Patch Tuesday. Self-control mechanisms and PDQL queries enable ongoing validation of subnets, asset freshness, and compliance without excessive manual oversight. The framework is designed to be adaptable to any mature vulnerability management platform beyond the specific tools demonstrated.

Security NEXTVulnerabilities & Exploits

Google Releases Chrome 153 Fixing 230 Vulnerabilities Including Zero-Day Exploit

Google has released Chrome 153 for Windows, macOS, and Linux, addressing a total of 230 security vulnerabilities. The update includes fixes for five critical-severity issues and one confirmed zero-day vulnerability already exploited in the wild. Among the critical flaws are use-after-free bugs in WebGL tracked as CVE-2026-87464 and CVE-2026-87488, an out-of-bounds write CVE-2026-87438, a buffer overflow CVE-2026-87527, and a use-after-free in the Cast component identified as CVE-2026-87628. A medium-severity out-of-bounds write in the V8 JavaScript engine, CVE-2026-87491, was reported on August 6, 2026 and has seen active exploitation. The company is rolling out the patches gradually over the coming days and weeks across all supported platforms.

Security NEXTVulnerabilities & Exploits

Microsoft Addresses 973 Vulnerabilities in September Security Update

Microsoft released its monthly security updates on September 8, 2026, fixing 973 vulnerabilities tracked by CVE identifiers. The release coincided with Patch Tuesday and also resolved four third-party software flaws. Affected products span Windows, Office, SQL Server, Azure, Microsoft Dynamics, SharePoint Server, and various development tools. Among the issues, 258 allow remote code execution and 438 enable privilege escalation. A total of 113 vulnerabilities received the highest severity rating of Critical, while the remaining 860 were rated Important. Several of the flaws have already been observed in active exploitation.

Security NEXTVulnerabilities & Exploits

Adobe Issues Critical Security Updates for ColdFusion Fixing Nine CVEs Including Eval Injection Flaws

Adobe has released security updates for Adobe ColdFusion to address nine vulnerabilities, urging users to apply the patches immediately. The update coincides with Patch Tuesday on September 8, 2026, and covers issues such as Eval injection, SQL injection, cross-site scripting, and access control weaknesses. Six of the vulnerabilities are rated Critical, with the highest CVSS v3.1 base score reaching 9.9 for CVE-2026-48273. The remaining three vulnerabilities are classified as Important. Adobe ColdFusion users are advised to update without delay to mitigate risks of code injection and unauthorized access. The advisory also references related security issues in other products including Canva, BIG-IP, and Dell SCG.