Skip to main content
Home/Blog/974 Patches. Two Zero-Days Already in the Wild. One Wormable Bug Microsoft Hopes You Fix Fast.
Cybersecurity

974 Patches. Two Zero-Days Already in the Wild. One Wormable Bug Microsoft Hopes You Fix Fast.

Microsoft's September 2026 Patch Tuesday broke every record — 974 vulnerabilities in a single update, including two actively exploited zero-days and a nearly-wormable Windows DNS flaw. Here's what every business leader needs to know.

September 9, 2026·6 min read

This morning, Microsoft released its September 2026 Patch Tuesday update. The headline number: 974 vulnerabilities patched in a single release. To put that in context — in May, they patched 161. In June, 220. In July, a then-record 663. In August, 457.

Now 974. In one day.

If that number feels absurd, that's because it is. And the reason it keeps climbing tells you something important about where cybersecurity is heading — and what your business needs to do about it.

Two Zero-Days Were Already Being Used Against Real Targets

Before we talk about scale, let's talk about urgency. Of the 974 vulnerabilities patched today, two were already being actively exploited in the wild before Microsoft released a fix.

The first, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). An attacker who can run code in a low-privilege application container can use this flaw to escape the sandbox and gain SYSTEM privileges — the highest level of access on a Windows machine. CISA added it to the Known Exploited Vulnerabilities catalog today and gave federal agencies until September 22 to patch.

The second, CVE-2026-81963, sits in the Windows Update Stack itself. The component responsible for keeping your systems secure has a vulnerability that allows an attacker to traverse the file system, read files they shouldn't, and overwrite unexpected locations — all to escalate to SYSTEM.

Both flaws are locally exploitable, meaning an attacker needs some foothold first — a phishing email, a stolen credential, a compromised application. But in 2026, that first foothold is the easy part. The hard part is stopping what happens next.

The Bug That Worries Security Researchers Most

Beyond the two zero-days, researchers flagged a third vulnerability as particularly dangerous: CVE-2026-69730, a remote code execution flaw in Windows DNS Server with a CVSS score of 9.8.

Here's what makes it different: an unauthenticated attacker can send a specially crafted network packet to an affected DNS server and execute code on it — no credentials required, no user interaction needed. Microsoft hasn't seen exploitation yet, but they've flagged it as likely to be exploited. Researchers have called it potentially wormable — capable of self-propagating across networks, the way WannaCry did in 2017.

Every organization running Windows DNS Server on-premises should be treating this as a priority-one patch. Not a this-week patch. Not a next-Patch-Tuesday patch. Today.

Why the Numbers Keep Breaking Records

Here's the uncomfortable truth behind the record-breaking patch volumes: Microsoft, like most major technology companies, has deployed AI to find security vulnerabilities internally. It works. The same AI-driven code analysis that's helping defenders find flaws faster is generating lists of bugs that now number in the hundreds per month.

The Tenable research team put it plainly: "September's Patch Tuesday marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month — another new record set in 2026."

This is good news and bad news simultaneously. Good news: flaws are being found and patched before attackers discover them independently. Bad news: your IT and security teams are now expected to evaluate, prioritize, and remediate nearly 1,000 vulnerabilities — every single month. That's not a patch cycle problem. That's a structural challenge that most organizations aren't built to handle.

The Patch That Shouldn't Be Overlooked: Microsoft Authenticator

One patch in today's release deserves a mention that most coverage is skipping: CVE-2026-80097, an improper authentication vulnerability in Microsoft Authenticator — the app millions of users rely on for MFA.

An unauthenticated attacker can exploit this locally to elevate privileges. If your employees use Microsoft Authenticator on their phones (and most Microsoft 365 organizations do), that app is now in your patch inventory whether you realize it or not. Mobile app updates don't happen on your schedule — they happen when users remember to update their phones.

This is a good reminder that your patch surface extends well beyond Windows servers. It includes every endpoint, every mobile device, and every application your workforce uses.

Three Questions Every Business Leader Should Be Asking

The September Patch Tuesday story isn't really about one month's patch count. It's about whether your organization has the capability to keep pace with a threat environment that now moves faster than most patch cycles can accommodate.

Ask yourself:

Do you have visibility into what's patched and what isn't — across your entire environment? Not just servers. Not just desktops. Mobile devices, cloud workloads, remote endpoints, vendor-managed systems. If you can't answer "yes" with confidence, your patch intelligence has blind spots.

How long does it take your organization to act on a CISA Known Exploited Vulnerability? CISA gave federal agencies until September 22 to patch today's two zero-days — 13 days. Most enterprises take 44 days on average to patch critical vulnerabilities. The math isn't favorable.

What's your plan when a wormable vulnerability goes active before you've patched? DNS servers are foundational infrastructure. If CVE-2026-69730 is weaponized at scale before your DNS servers are patched, what happens? Do you have network segmentation that limits spread? Detection capabilities that catch lateral movement? An isolation playbook that doesn't bring business operations to a halt?

These aren't hypotheticals. They're the questions that separate organizations that contain incidents from organizations that spend months recovering from them.

The Bottom Line

Almost 1,000 patches in a single month. Two zero-days already exploited. One wormable bug that researchers are watching carefully. And a Microsoft Authenticator vulnerability sitting quietly on every employee's phone.

Patch Tuesday used to be an IT calendar item. In 2026, it's a monthly operational event that demands executive awareness. If your security posture relies on catching up eventually, eventually is running out of runway.

At TrustPoint Cyber, we help business leaders understand what's critical, what can wait, and what requires immediate action — without drowning your team in a list of 974 CVEs. If you want to know where your organization stands, let's talk.

Get Protected

Ready to strengthen your security?

TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.