Change language to
0:00

Microsoft’s September 2026 Patch Tuesday release fixes 974 Microsoft CVEs, including 723 vulnerabilities across Windows. Microsoft’s release notes list two Windows flaws as having exploitation detected, giving users and IT teams a reason to move the update up the queue rather than leave it for the next convenient restart.

The scale also continues a summer of unusually large Microsoft security releases. The Verge reports that security-focused AI models have helped Microsoft discover vulnerabilities at a faster rate, with the company’s September Windows total passing 650 fixes. The Record’s report adds that AI-assisted discovery has contributed to successive record-sized Patch Tuesday cycles.

Windows logo graphic representing Microsoft security updates

What September 2026 Patch Tuesday fixes

The official Microsoft Security Update Guide lists 974 Microsoft CVEs in the September release. Windows accounts for 723 of them, followed by 111 in Office, 62 in SQL Server, 22 in Developer Tools, and 16 in SharePoint Server. The release was published on 8 September 2026.

Microsoft flags CVE-2026-85880, an elevation-of-privilege flaw in the Windows Advanced Local Procedure Call system, and CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack, as having exploitation detected. The release notes do not say that every affected Windows machine has been compromised, but exploited vulnerabilities should be treated as a priority for patching.

Why Microsoft’s patch counts keep rising

Microsoft’s August release contained 457 CVEs, while September’s total more than doubled. The increase follows June and July releases that were also much larger than Microsoft’s usual monthly patch volume, as AI tools help security teams identify and validate flaws that might otherwise take longer to find.

That does not make the updates optional. UAE organisations running Windows fleets should test the release against their usual business applications, then deploy it through supported update channels as quickly as their change process allows. Microsoft’s earlier use of AI to find Windows flaws is covered in our previous report, while Windows 11 search is also being rebuilt around local results.

NEWSLETTERS

Subscribe to our Newsletters

Two newsletters. Zero noise. Pick what lands in your inbox.

Unsubscribe anytime. We don’t share your email.

How many vulnerabilities are in September 2026 Patch Tuesday?

Microsoft lists 974 CVEs in the September 2026 release, including 723 affecting Windows.

Which September 2026 Windows flaws are marked as exploited?

Microsoft flags CVE-2026-85880 and CVE-2026-81963 as having exploitation detected.

Should UAE Windows users install the update?

Yes. Users and IT teams should test the release against their normal software and deploy it through supported update channels promptly.