# Microsoft Windows security update cycle

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-windows-security-update-cycle
> Updated: 2026-09-09T08:10:34.000Z. Sources: 28. Developments: 2.

Microsoft announced that Windows devices enrolled in hotpatching programs will undergo forced restarts during September and October 2026. This requirement stems from technical needs for security component fixes in the September update and the quarterly hotpatching cycle in October. Microsoft advised IT administrators to manage maintenance windows to avoid business disruptions.

In September 2026, Microsoft released a record-breaking security update addressing between 964 and 974 vulnerabilities, including 104 critical and 860 important patches. A significant portion of these fixes, approximately 723, target the Windows operating system, including Windows 11, 10, and various Server versions. The release addressed two zero-day vulnerabilities that were being actively exploited, specifically local elevation-of-privilege flaws: CVE-2026-81963, affecting the Windows Update Stack, and CVE-2026-85880, affecting the Windows Advanced Local Procedure Call (ALPC). Both could allow attackers to gain SYSTEM-level privileges.

The updates also covered high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, alongside patches for Exchange Server, SharePoint, SQL Server, Office, and .NET. Industry analysts have suggested that the surge in vulnerability discovery may be driven by the rise of “AI-assisted bug hunting tools,” noting a trend of record-breaking patch volumes that places increased pressure on IT administrators to prioritize remediation. 

Additionally, security researchers identified approximately 20 vulnerabilities that are potentially “wormable,” meaning they could spread across networks without user interaction. Following the discovery of the two exploited zero-days, CISA added them to its Known Exploited Vulnerabilities list, establishing a deadline for federal agencies to apply the necessary patches. 

Beyond the Windows ecosystem, Microsoft disclosed CVE-2026-69836, a remote code execution flaw in its Entra ID cloud identity service with a maximum CVSS score of 10.0. Microsoft has mitigated this vulnerability server-side, requiring no direct action from customers, though security teams are advised to monitor for anomalous identity-plane behavior.

## Claims

- Microsoft released patches for 974 CVEs in September 2026. (disputed by 17 sources)
- The release addresses two zero-day vulnerabilities that were being exploited in the wild. (corroborated by 13 sources)
- The zero-day vulnerabilities are local elevation-of-privilege flaws. (corroborated by 8 sources)
- 723 of the vulnerabilities affect the Windows operating system. (corroborated by 5 sources)
- The update includes 20 potentially wormable vulnerabilities. (corroborated by 2 sources)
- Retail versions of .NET 10.0.12, 9.0.20, and 8.0.31 each received eight security fixes. (single source)
- Vulnerability CVE-2026-69522 affects multiple versions of .NET Framework. (single source)
- CVE-2026-69836 is a remote code execution flaw in Entra ID. (single source)
- The Entra ID flaw was mitigated server-side with no customer action required. (single source)

## Timeline

### 2026-09-09: Microsoft releases record September security updates

Microsoft's September 2026 Patch Tuesday is its largest ever, fixing nearly 1,000 vulnerabilities, including two actively exploited Windows zero-days and a critical CVSS 10.0 flaw in Entra ID.

24 sources. https://clstr.news/cluster/microsoft-releases-record-964-security-patches-in-september-2026

### 2026-08-29: Microsoft to implement forced Windows restarts in September and October

Microsoft will require forced restarts for Windows hotpatching-enabled devices in September and October to apply essential security component fixes.

5 sources. https://clstr.news/cluster/microsoft-to-implement-forced-windows-restarts-in-september-and-october

---
Cite as: Microsoft Windows security update cycle. CLSTR, https://clstr.news/situations/microsoft-windows-security-update-cycle
