< Back to all clusters
[TECHNOLOGY] · 24 sources

started · updated

Microsoft releases record September security updates

Microsoft has issued its largest security update on record for September 2026, addressing approximately 974 vulnerabilities across its software ecosystem. The release includes 104 critical and 860 important security patches. A significant portion of these fixes, totaling 723, targets the Windows operating system, while 222 address the Microsoft Office suite. Other affected products include SQL Server, Exchange Server, SharePoint, and Azure.

Of particular concern are two zero-day vulnerabilities that were already being actively exploited in the wild: CVE-2026-81963, located in the Windows Update Stack, and CVE-2026-85880, affecting the Windows Advanced Local Procedure Call (ALPC). Both flaws are local elevation-of-privilege vulnerabilities that could allow an attacker with an existing foothold to gain SYSTEM-level privileges. Additionally, researchers identified roughly 20 potentially wormable vulnerabilities capable of spreading across networks without user interaction.

Separately, Microsoft disclosed CVE-2026-69836, a remote code execution flaw in its Entra ID cloud identity service with a maximum CVSS score of 10.0. This vulnerability was mitigated server-side by Microsoft, meaning no direct action is required from customers, though security teams are advised to monitor for anomalous identity-plane behavior.

Entities

.NET · Adobe · CISA · Entra ID · Google · Microsoft · Windows · Zero Day Initiative · windows

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

2 days ago