Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes
computerworld.com Sep 14, 2026

Microsoft’s Patch Tuesday updates: Keeping up with the latest fixes

AI-summarised brief · reviewed before publication

Microsoft’s September 2026 Patch Tuesday release addresses 963 CVEs, marking the largest security update of the year. The patch cycle includes fixes for two vulnerabilities already under active exploitation: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. No flaws in this specific release were publicly disclosed prior to the patch. IT administrators are advised to prioritize immediate updates for Windows, Office, SQL Server, and developer tools, while scheduling standard releases for Exchange. This update follows a similarly heavy August cycle that resolved 751 CVEs, including an exploited elevation of privilege in the Windows WinSock driver. The July release also saw record-breaking activity, addressing 722 CVEs and two actively exploited flaws in Active Directory Federation Services and SharePoint Server. These consecutive high-volume releases underscore the persistent threat landscape facing enterprise environments.

💡 Why It Matters

  • · The sheer volume of critical fixes demands immediate triage to prevent lateral movement.
  • · Delaying deployment leaves exposed systems vulnerable to known, actively exploited attack vectors.