9/9/2026
Barry

Microsoft Just Dropped 974 Patches in One Day. The Two Zero-Days Are the Real Story.

Here's the version of this story that got the headlines: Microsoft shipped a record 974 patches in a single Patch Tuesday. It's true, and it's the wrong way to read the day.

The number is staggering on its own. Tenable was quick to point out that 974 CVEs in one month is not far off the 1,130 Redmond issued across all of 2025. September's drop follows 421 fixes in August and 622 in July. The "new normal" isn't a phrase anymore — it's a quarterly cadence, and it's accelerating.

But the volume is the mirage. The real story is what's hiding inside it.

Two zero-days, already in the wild

Microsoft confirmed two bugs are already being exploited before the patch shipped. Both are privilege escalation flaws that end in SYSTEM.

The first, CVE-2026-85880, lives in Windows Advanced Local Procedure Call (ALPC). An attacker who can execute code in a low-privilege AppContainer can escape the sandbox and elevate to SYSTEM — and Redmond notes no additional user interaction is required. That's the kind of chain that turns a foothold into full domain compromise in a single hop.

The second, CVE-2026-81963, is in the Windows Update Stack. Same destination — SYSTEM — via a component that every Windows machine runs by default. The US Cybersecurity and Infrastructure Security Agency has already added both to its Known Exploited Vulnerabilities Catalog and set a September 22 deadline for federal agencies to patch.

The wormable count is the part nobody should ignore

Beyond the two zero-days, researchers flagged roughly 20 wormable bugs — remote code execution flaws that need no authentication and no user interaction to spread. That's an unusually high number for a single Patch Tuesday, and it's the number that should worry anyone running a fleet.

There's also a critical Exchange Server RCE that can be triggered simply by sending an email with a malicious Visio attachment. No click required. For mid-market organizations still running on-prem Exchange, that's the one to prioritize first.

The strategic tension nobody wants to talk about

Here's the uncomfortable part. A 974-CVE month is not a sign that Microsoft is getting worse at security. It's a sign that the attack surface has grown faster than any single vendor can defend, and that the industry has normalized shipping fixes at a volume that mid-market IT teams were never built to absorb.

The math is brutal. A team of two or three people responsible for patching a fleet now faces nearly a thousand CVEs a month, with two already-exploited zero-days and twenty wormable bugs buried in the pile. Prioritization isn't a nice-to-have anymore — it's the entire job. Patch everything and you break production. Patch nothing and you're a target. The organizations that survive this era are the ones that stop treating patching as a chore and start treating it as a triage discipline.

What this means for the industry

The record Patch Tuesday is a forcing function. It's pushing the conversation away from "how many CVEs did Microsoft fix" and toward "how does a mid-market team decide what to fix first." That's a strategic reset for the whole security stack — vulnerability management, asset inventory, and the tooling that tells you which of those 974 actually touch your environment.

The supply chain complexity behind keeping a production fleet patched in the middle of a thousand-CVE month is the kind of problem that doesn't show up in a spec sheet. At DMC, we work with companies navigating exactly these constraints — infrastructure strategy, security posture, and the operational planning that keeps a business running when the patch treadmill never stops. Need help stress-testing your patching and security roadmap? Let's talk.