← Back to Feed
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
CVE-2026-81963CVE-2026-85880
September 8, 2026 · Tenable Blog · Severity: CRITICAL
This article summarizes Microsoft's record-breaking September 2026 Patch Tuesday, which patches 964 CVEs across numerous products, including two zero-days that have been exploited in the wild. The update addresses vulnerabilities in critical components such as Windows, Azure, Office, and Exchange Server, with 104 rated critical and 860 important. 📌 **Analyst Note:** The unprecedented number of patches this month, combined with active exploitation of two zero-days, demands immediate prioritization of deployment for CVE-2026-81963 and CVE-2026-85880. Organizations should also focus on the 104 critical vulnerabilities, particularly those affecting widely used serv
Key Takeaways
- Microsoft's September 2026 Patch Tuesday is the largest on record, addressing 964 CVEs, including 104 critical and 860 important, with patches for two zero-days exploited in the wild.
- The update covers a wide range of products, including .NET, Azure, Exchange Server, Office, SQL Server, and Windows components, reflecting the broad scope of vulnerabilities addressed.
- Two zero-days, CVE-2026-81963 and CVE-2026-85880, were actively exploited before patches were available, highlighting the urgency of applying these updates to mitigate ongoing attacks.