Leadership1 publisher3 min readPublished
Microsoft's record 964-fix Patch Tuesday overwhelms with sheer volume
A record count that Microsoft's own AI bug-hunting produced arrives with two flaws already under attack, and the affected-product lists an operator would use to scope them are the part of the record two vendors read differently.
The Board Room · Leadership desk

What happened
- Microsoft's September Patch Tuesday carried 964 vulnerabilities requiring customer action, a record the roundup attributes to the company's mid-year adoption of AI to find bugs.
- One of the two zero-days, CVE-2026-85880, is a Windows ALPC heap overflow already under exploitation, letting code in a low-privilege AppContainer escape the sandbox and elevate privileges.
- The other, a link-following flaw in the Windows Update Stack, yields System privileges and has no workaround other than the fix, and Action1 says exploitation has been detected.
- Dustin Childs of the Zero Day Initiative put about 20 of the month's fixes in the possibly wormable category and called a new Windows DNS flaw the spiritual successor to SigRed.
- Separately, Onapsys flagged a CVSS 10.0 flaw in the Extended Passport Processing component used with SAP's ABAP in S/4Hana and NetWeaver deployments.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- contradiction Whether the first remediation wave covers a legacy subset or every Windows machine depends on which reading of the ALPC advisory an operator trusts, and choosing the smaller one is only safe if the vendor table is complete.
- constraint Finding the entries that need action inside 1,170 disclosed CVEs is now the scarce step, so a cycle that reads the whole list once a month has to give up either completeness or speed.
- decision The SAP flaw does not queue behind Microsoft's calendar, so someone has to decide which system owner gets the first available change window this month.
- precedent If Fortra is right that the dynamic is not confined to Microsoft, comparable counts will arrive from other vendors' pipelines without a fixed monthly date to schedule the reading around.
Volume is the least useful number in this release. Add the 174 third-party and open-source CVEs, the 23 Chromium and Edge items and the nine cloud-side issues Microsoft mitigated without customer action [2][3], and the roundup accounts for 1,170 CVEs, of which the 964 requiring action are about 82 percent [15]. That is a figure a change calendar has to absorb, and it carries no information about sequence.
Sequence comes from the affected-products field, which is where this month's record stops agreeing with itself. Microsoft lists certain versions of Windows Server 2012, Windows Server 2016 and Windows 10 Desktop as affected by CVE-2026-85880, the ALPC heap overflow already under exploitation [5], while Ivanti's Chris Goettl said the flaw affects the entire Windows fleet [6]. For the second exploited bug in the Windows Update Stack, Microsoft names Windows 11 Desktop and Windows Server 2025 [7]; Action1 says the specific affected versions cannot be confirmed from available data, and neither can the severity or the CVSS score [8]. An operator scoping from the vendor table gets a materially smaller job than one scoping from Goettl's reading, and only one of those jobs is the right size.
A skeptic would say the count is an artifact of the discovery method, and that both exploited flaws are privilege escalations, which matter only once an intruder is already resident. Both points hold, and both explain why the expense has moved from applying fixes to reading them. Tenable's Satnam Narang notes that CVE-2026-81963 is the first of seven Windows Update Stack privilege escalation flaws found since 2022 to be exploited [9], the kind of signal that a monthly total cannot surface. Fortra's Tyler Reguly said it directly: while Microsoft is playing catch-up on patching, the numbers have lost all meaning [13].
Time can still be bought on the pre-exploitation set, which is roughly 2 percent of the customer-action list on Dustin Childs's wormable count [16]. The DNS flaw in that group is reachable by an unauthenticated attacker sending a crafted packet, and Microsoft says it has not been exploited yet but expects it will be [11]. Action1's Jack Bicer points to two more that need neither authentication nor user interaction, in Windows Deployment Services TFTP and in Routing and Remote Access, which he says could spread quickly across a network if affected systems go unpatched [12]. Those are the entries where a patch still lands ahead of an attacker rather than behind one.
The distinction worth holding is between this week and this decade. This week is two exploited privilege escalations with contested scoping, one DNS bug the vendor expects to be attacked, and an SAP component scored 10.0 sitting outside Microsoft's cycle. Whether 964 becomes the ordinary monthly shape is not settled by one month, and the record here offers no earlier Microsoft monthly totals to measure the jump against [17]. What this quarter decides is whether triage capacity grows alongside vendor-side discovery, because a team that can read the full list only once a month inherits its ordering from the affected-products field, and that field is this month's least dependable line.
What to watch
- Whether Microsoft revises the affected-products list for CVE-2026-85880 to cover current Windows versions, which would settle its advisory against Ivanti's reading.
- A confirmed version list and CVSS score for CVE-2026-81963, which Action1 says the available data does not support.
- Any confirmed exploitation of CVE-2026-69730, the Windows DNS flaw Microsoft says it expects to be attacked.