
Microsoft Discloses Record 973 Vulnerabilities in September 2026 Patch Tuesday With Two Under Active Exploitation
Record Patch Tuesday volume and confirmed exploitation of update and messaging components reveal systemic remediation gaps. Data shows 22,000 Exchange servers exposed and year totals already surpassing prior records. Patterns indicate AI-assisted discovery accelerating attacker chaining of low-severity issues into ransomware footholds.
Microsoft's September release set a new record with 973 fixes, exceeding the prior July high of over 600. CISA mandated federal patching of the two exploited flaws by September 22. CVE-2026-81963 targets the update stack used for installation while CVE-2026-85880 impacts Windows messaging, enabling initial access followed by privilege escalation in ransomware operations. Over 22,000 unpatched Exchange servers remain exposed per Nightwing data.
Procurement and incident patterns show consistent lag between disclosure and remediation. Tenable analysis links CVE-2026-81963 to supply-chain style persistence where control of the update mechanism prevents eviction. Nightwing telemetry indicates attackers chain these with phishing to reach domain-level access before defenders detect anomalies in update logs.
Year-to-date disclosures now exceed 2,600, more than double 2020 totals, aligning with researcher warnings on AI code-review tools surfacing minor flaws that chain into critical paths. Adobe's concurrent critical Commerce bug adds cross-vendor exposure. Unpatched systems create measurable dwell time advantages for operators.
Federal agencies face the September 22 deadline while enterprise patching rates for similar prior flaws averaged below 60 percent within 30 days. Continued growth in volume will strain prioritization without telemetry confirming last successful update execution on critical assets.
CISA: Fewer than 40 percent of federal agencies will report full remediation of CVE-2026-81963 by October 1.
Sources (3)
- [1]The Record(https://therecord.media/microsoft-patch-tuesday-september-2026)
- [2]Tenable Research Advisory(https://tenable.com/research)
- [3]Nightwing Threat Report(https://nightwing.com/reports)