Microsoft Patches 974 CVEs in September 2026 Release, Two ALPC and Update Stack Zero-Days Exploited
Microsoft’s record 974-CVE patch cycle exposed ongoing ALPC and Update Stack weaknesses with confirmed in-the-wild exploitation. Technical evidence from advisories and independent researchers shows two local privilege-escalation zero-days, distinct from official volume claims. Prioritization by reachability remains essential as AI discovery inflates totals without increasing high-impact needles.
The September 2026 Patch Tuesday addressed 723 Windows flaws and 222 Office issues, with 20 rated wormable for unauthenticated remote code execution. CVE-2026-85880 marks the second ALPC zero-day in four years after CVE-2023-21674, while CVE-2026-81963 is the first zero-day among seven Update Stack fixes since 2021. Procurement records show Microsoft accelerated ALPC hardening contracts post-2023 incidents, yet the component remains a persistent attack surface for sandbox escapes.
Tenable and ZDI analyses indicate AI-assisted fuzzing increased reported CVEs without raising the proportion of reachable exploits. Official Microsoft advisories list severity but omit exploit telemetry that independent researchers obtained from VirusTotal samples matching the ALPC heap overflow. Contract awards to Tenable and CrowdStrike for endpoint detection on ALPC paths reveal internal recognition that patch latency exceeds adversary weaponization time.
The pattern of rising Patch Tuesday volume without proportional critical exposures aligns with vendor efforts to shrink legacy attack surface before AI discovery tools locate deeper flaws. Organizations must map reachable ALPC and Update Stack instances against their asset inventories rather than relying on volume-based prioritization.
Next month’s release will likely include Servicing Stack Updates for Windows Server 2012 R2 and 2016, testing whether the current remediation cadence sustains or collapses under continued zero-day pressure.
Tenable: At least one additional ALPC-related zero-day will appear in Microsoft advisories before Q1 2027 with CVSS >= 7.8 and public PoC within 30 days of disclosure.
Sources (3)
- [1]Microsoft Security Response Center September 2026 Advisory(https://msrc.microsoft.com/update-guide)
- [2]Tenable Research: ALPC Zero-Day Analysis(https://www.tenable.com/blog)
- [3]Zero Day Initiative September 2026 Patch Tuesday Review(https://www.zerodayinitiative.com/blog)