Microsoft just shipped its biggest security update ever. The Patch Tuesday September 2026 rollout fixes 966 flaws in Windows and related products, and two of them are zero-days that attackers are already using against real PCs. If you’ve been putting off that “Restart to update” nag, this is the week to stop.
- 966 vulnerabilities patched — Microsoft’s largest single Patch Tuesday release on record, beating July’s 570 and August’s totals easily.
- 2 zero-days under active attack: CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC).
- 105 critical bugs, including a 9.8-severity Windows DNS Server flaw (CVE-2026-69730) that needs no password to exploit.
- Released September 8, 2026, covering Windows 10, Windows 11, Windows Server, Edge, Azure, and Entra ID.
- Fix takes under 5 minutes: Settings > Windows Update > Check for updates > Restart.
What Actually Happened to Your Windows PC This Week
Every month, Microsoft bundles its security fixes into one release known as Patch Tuesday. This month’s batch is unusually large. Security firms tracking the numbers counted 966 individual CVEs, a jump that dwarfs the 570 fixed in July and the several hundred typical for August.
Most of those bugs won’t ever touch your daily life. A big chunk are elevation-of-privilege issues (438 of them) that need an attacker to already have some access to your machine, usually through a separate trick like a phishing link or a bundled malicious app. But 258 are remote code execution flaws, the kind that can let someone run code on your PC without you clicking anything obvious. And 105 are rated critical, Microsoft’s top severity tier, meaning successful exploitation could hand an attacker deep control over the system.
Why This Patch Tuesday September 2026 Update Matters More Than Usual
What separates this month from a routine patch cycle is that two of the fixed bugs were already being exploited before Microsoft released a fix. That’s the definition of a zero-day: attackers found it first. Both affect core parts of Windows that most people never think about, but both let a hacker who’s already gotten a small foothold on your machine jump up to full SYSTEM-level control.
Here’s how the two stack up against each other.
| CVE | Affects | CVSS | What an Attacker Gains |
|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | 7.8 | SYSTEM privileges via a file-link resolution flaw |
| CVE-2026-85880 | Windows ALPC | 7.8 | SYSTEM privileges via a heap overflow and replay attack |
Neither one lets an attacker break into your PC from across the internet on its own. They’re the second stage of an attack — the part that turns a small crack (a malicious download, a compromised app) into full control of your machine. That’s exactly why security researchers flagged them as urgent instead of routine.
The Other Bugs Worth Knowing About
The zero-days get the headlines, but a couple of the non-exploited bugs in this batch are arguably scarier on paper. CVE-2026-69730, a Windows DNS Server flaw, scores 9.8 out of 10 and needs no login at all — it’s rated “exploitation more likely” by Microsoft’s own team. It mostly threatens businesses and IT admins running Windows Server as a DNS host, not typical home PCs.
Closer to home, CVE-2026-69676 is a Kerberos authentication bypass rated 8.8, also flagged as likely to be exploited soon. A pair of Graphics Fonts flaws and an IP Helper remote code execution bug round out the list of critical fixes, both the kind of low-level Windows component most people have never heard of but every PC relies on. If you’ve already dealt with the Chrome zero-day from earlier this month, this is the same idea applied to Windows itself: patch first, ask questions later.
How to Update Safely Without Repeating Last Month’s Headache
Installing this update is simple: open Settings, go to Windows Update, click Check for updates, and restart when it asks. Most PCs will grab it automatically within a few days if you haven’t already.
The one wrinkle: recent cumulative updates haven’t had a clean track record. KB5124008 shipped with a VPN bug that broke connections for some users right after it patched other issues. Before you roll a big Patch Tuesday update out across a whole office or family of devices, it’s worth installing it on one machine first and using it normally for a day.
Frequently Asked Questions
Do I need to do anything besides restart my PC?
No. Windows Update handles the download and install automatically for most home users. A restart is the only step you have to take yourself.
What actually makes a bug a “zero-day”?
It means attackers were already using the flaw before a fix existed — Microsoft had zero days of advance warning. That’s different from a bug that’s discovered and patched before anyone exploits it.
Is my PC in immediate danger if I wait a few days?
The two zero-days need an attacker to already have some access to your device, so a typical home PC isn’t at instant risk. Still, the longer you wait, the more time attackers have to build the exploit into wider malware campaigns.
Does this update affect Windows 10?
Yes, Windows 10 systems still under extended support received fixes too, alongside Windows 11 and Windows Server. Check your update history to confirm which build you’re on.
Where can I see the full list of patched CVEs?
Microsoft publishes the complete list in its Security Update Guide, and security vendors like Tenable and the Zero Day Initiative post plain-language breakdowns within a day or two of release.


Leave a Reply