Skip to content

Security1 publisher2 min readPublished

Microsoft's record 964-CVE Patch Tuesday includes two exploited zero-days

Tenable's tally for September 2026 is the largest Patch Tuesday on record. It shipped with two bugs already exploited in the wild. The other 962 sit on the calendar as a scheduling problem, and the severity ratings do not sort them by urgency.

The Watch · Security desk

Illustration accompanying Microsoft's record 964-CVE Patch Tuesday includes two exploited zero-days

What happened

  • Tenable counts 964 CVEs in Microsoft's September 2026 Patch Tuesday, a record for a single release.
  • The severity breakdown is 104 critical and 860 important, with nothing placed in the moderate or low buckets.
  • Two of the 964 were exploited in the wild before the fixes shipped, according to Tenable's write-up of the release.
  • Tenable's title carries CVE-2026-81963 and CVE-2026-85880, and the published text does not say which identifiers belong to the exploited pair or what they affect.
  • The affected-component list runs to at least 137 entries, including Windows ALPC, Exchange Server, Hyper-V and Kerberos, before the published version cuts off mid-line.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint With no CVE rated below important, the vendor rating gives a change board no defensible ground for deferring any single item, so every deferral decision and its audit trail lands on the operator.
  • decision Sizing the month by CVE count books several change windows; sizing it by exploitation evidence books two out-of-band patches and leaves the rest on the normal calendar.
  • exposure Estates that regression-test the whole release before deploying any of it carry the two exploited bugs for the full length of that test cycle.
  • precedent A record set in July and broken in September makes a bigger release the working assumption for the next quarter, which means headcount-based triage keeps losing ground.

One in 482 of this month's Microsoft advisories is known to be in use by an attacker [13]. That ratio is the number that maps to anything happening on a network today.

The severity field cannot do the sorting. About 89 percent of the release is rated important and 10.8 percent critical [11][12], with the bottom two buckets empty [10], so nothing arrives pre-deprioritised by the vendor's own rating. Working the criticals first still leaves 104 patches to stage, more than one maintenance window absorbs in most estates. At one minute of reading per advisory, a generous rate for an entry with a product name and a vector string, the queue is about 16 hours of screen time before the first reboot [14].

Triage by exploitation evidence needs the evidence to be legible. Tenable's post says two of the 964 were exploited in the wild [4] and puts CVE-2026-81963 and CVE-2026-85880 in its title [5], and the published text stops there: no impact class, no component, no mapping from either identifier to either zero-day [6]. Windows ALPC is in the affected-component list [8]. So are Exchange Server, Hyper-V, Kerberos, OpenSSH for Windows and SQL Server [9]. The list breaks off mid-entry after Windows Management Instrumentation, and no Windows Update Stack entry appears in the portion that was published [17][18]. On this material an operator cannot tell whether the two live bugs are local elevation of privilege, which needs a foothold first, or something an unauthenticated caller can reach. That distinction decides whether the emergency is tonight or next window.

That gap is what decides whether September's release is workable, more than its size does. A 964-item release with two known-exploited entries is workable if the vendor and the trackers say which two and what they touch; it is unworkable if the only usable field is a severity label attached to everything.

Tenable puts July 2026 as the previous largest Patch Tuesday, beaten two months later [7]. A triage process calibrated on July's number is already short of capacity, and more reviewers do not change which two patches have to ship first.

What to watch

  • Whether Microsoft or Tenable ties CVE-2026-81963 or CVE-2026-85880 to the exploited pair and names the component and impact class for each.
  • Public proof-of-concept or exploit code for either named CVE, which would move the rest of the criticals down the queue.
  • Whether October's release stays near 900 CVEs after records in July and September 2026.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories