Security & Risk5 minNewsroom

Microsoft's Patch Tuesday Fixes 974 CVEs, AI Boost Revealed

Mesa de CISO em centro de operações de segurança bancária europeu à noite, com três monitores exibindo lista de avisos CVE do Windows e agenda impressa marcada em vermelho.

Microsoft corrected 974 vulnerabilities in September, 5.6x the pre-2026 monthly average. Two zero-days in Windows were already listed in CISA's KEV catalog before the patch.

The Largest Patch Tuesday in History


Microsoft released 974 security fixes on Tuesday, September 9, marking the highest number ever disclosed in a single monthly cycle. This volume is 5.6 times the historical average of around 175 CVEs per month prior to 2026 and exceeds the previous record of 570 vulnerabilities set in July of this year. Windows accounts for 723 advisories, followed by Office (111), SQL Server (62), development tools (22), SharePoint (16), Azure (12), Skype for Business (10), and Exchange Server (9).


Two of the advisories were already being exploited before the patch. CVE-2026-85880 is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC), CVSS 7.8, which allows a local attacker to escape the AppContainer sandbox and escalate to SYSTEM. According to Tenable, this is the first ALPC vulnerability in Patch Tuesday in over three years, since April 2023, and the second exploited as a zero-day since January of that same year. CVE-2026-81963 is a link resolution flaw in the Windows Update Stack, also CVSS 7.8, allowing similar escalation to SYSTEM from a local foothold. It affects Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2025 and Server Core. CISA added CVE-2026-81963 to the Known Exploited Vulnerabilities catalog on September 8, with a correction deadline for federal agencies set for September 22. This is the first privilege escalation vulnerability in the Windows Update Stack to be exploited as a zero-day since 2022.


The Jump is Named and It’s Agentic


In July, Microsoft informed customers that the patch queue would grow due to its internal use of agentic AI tools for discovering zero-days. The September cycle is the first comprehensive reading of this pipeline in production. The Zero Day Initiative also highlighted 20 bugs categorized as wormable in this batch, a category that propagates without user interaction and is particularly hazardous in heterogeneous corporate networks.


The practical effect falls on the company's security team. A tripled volume of triage work in a cycle where the window for exploitation remains the same. A mid-sized European bank CISO operating two dozen Windows Server images, Office 365 tools spread across five geographies, and a legacy SharePoint must prioritize 974 advisories in days, not weeks. Automated patch management tools can handle volume, but exceptions, compatibility testing, and maintenance windows still require manual intervention.


The International Ricochet


The September cycle impacts IT infrastructure in three distinct areas. In the U.S., CISA's September 22 deadline applies only to the federal government, but it sets the baseline timeframe that managed service providers use to prioritize regulated financial clients. In Europe, the NIS2 directive increases pressure on critical infrastructure operators running Windows, with member states already demanding response plans within comparable windows. In India, home to Global Capability Centers responsible for patch management for half of the Fortune 500 companies, the volume will test limits on contracted hours and on-call shifts.


Brazilian companies running SAP on Windows Server, backed by SQL Server and SharePoint, fall under the same cycle. The difference is that the average security team in the country operates with fewer personnel per endpoint than their counterparts in Frankfurt or Boston, widening the gap between disclosure and actual patch application, now around 45 days according to industry surveys.


The Signal for Software Buyers


Microsoft’s use of agentic AI to hunt for bugs is a rare case where discourse and numbers align. Not every platform will disclose the multiplier derived from this approach, but those building SDLC with agentic AI need to do the math: if the discoverer can find five times as many vulnerabilities, the remediator on the other side must achieve equivalent productivity, or the gap between discovery and correction will only widen. For corporate software buyers, the key metric to watch over the next two quarters is the average time between CVE publication and the arrival of the fix in environments managed by MSPs. No one on the board will ask about 974 patches. They will ask how many of those advisories were still open when the next incident occurred.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk