Microsoft's September Patch Tuesday release was one of the largest security updates the company has issued, though sources report slightly different totals. TechPowerUp put the number of fixes at 999, while PCWorld reported 973, describing it as a record and more than double the previous month's total.

The bulk of the fixes targeted Windows. TechPowerUp reported 723 Windows-related patches, while PCWorld said more than 700 vulnerabilities were spread across Windows 10, 11, and Server versions still receiving security updates. PCWorld noted that 113 of the total vulnerabilities were classified as critical, including 83 remote code execution (RCE) issues, with 77 of the critical flaws specifically affecting Windows, 56 of which were RCE vulnerabilities.

Two vulnerabilities were confirmed as being actively exploited: CVE-2026-81963 and CVE-2026-85880. According to PCWorld, CVE-2026-81963 is a Windows Update stack flaw that allows attackers to gain elevated privileges and, when combined with an RCE vulnerability, execute code with system privileges. CVE-2026-85880 is an elevation-of-privilege flaw in Windows Advanced Local Procedure Call (ALPC), which requires exploit code to be hidden in a document that a user must trigger. PCWorld noted it is unclear how widespread these attacks are. TechPowerUp similarly confirmed both vulnerabilities were being actively exploited to unlock local privileges and enable code execution, and said both have now been patched.

Other products also received significant fixes. TechPowerUp reported about 111 fixes for Office and Office 2016, 62 for SQL Server, and 25 for third-party projects. PCWorld reported 137 Office vulnerability fixes, including 22 critical RCE vulnerabilities, five of which affected Excel. PCWorld also detailed 16 SharePoint fixes, including six RCE vulnerabilities, nine Exchange Server fixes including two RCE vulnerabilities (CVE-2026-55007 and CVE-2026-69355), and patches for Defender, Hyper-V, Skype for Business, Visual Studio, and Microsoft's cloud services. Windows Hello alone had nine vulnerabilities patched, eight of them critical elevation-of-privilege issues, with 64 total flaws addressed in the biometric service, mostly buffer overflow patterns.

Separately, PCWorld noted that Microsoft Edge received a security update to version 152.0.4191.66, based on Chromium 152.0.7977.83, addressing one zero-day vulnerability along with other Chromium issues not counted in the overall vulnerability total.

TechPowerUp connected this large patch wave to Microsoft's broader plan to expand memory integrity protection across Windows 11 installations starting in October. The feature uses Virtualization-based Security (VBS) to create isolated hypervisor environments and enable security hotpatches without requiring a restart, under the assumption that the kernel could be compromised. PCWorld noted the next Patch Tuesday is scheduled for October 13, 2026.