September 2026 Patch Tuesday Was Microsoft's Biggest Ever: What Perth Businesses Should Check

Microsoft's September 2026 Patch Tuesday fixed a record 966 flaws, including two zero-days already under attack — one inside Windows Update itself. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

XanderXander · Web Developer & IT Technician
9 September 2026
5 min read
Cybersecurity
Patch Management
Windows
Perth Business

Microsoft's September 2026 Patch Tuesday, released on 8 September, fixed a record 966 vulnerabilities — more than double what it patched across July and August combined — including two zero-day flaws that were already being exploited before the fix existed. The part worth paying attention to isn't just the size of the update: one of those two zero-days sits inside the Windows Update mechanism itself, the exact system your computers rely on to receive this month's fix. If your business runs Windows, the practical takeaway is straightforward — check that updates are actually installing this week, don't put off the restart, and don't assume this is a month you can quietly skip.

What landed this time

This is Microsoft's largest single Patch Tuesday on record. Of the 966 fixes, 105 are rated Critical, and 81 of those are remote code execution flaws — the kind that can let an attacker run their own code on a machine, not just view or corrupt data. Most of the rest are elevation-of-privilege and information-disclosure fixes, spread across Windows, Office, and the underlying components both rely on.

Scale alone isn't the story every month, but it's worth understanding why it matters even if you'll never read a single one of those 966 advisories yourself. A bigger release means a bigger window between "patch published" and "every machine in your business actually has it installed." Attackers know this too — it's common for exploit code targeting a freshly disclosed flaw to appear within days, aimed squarely at the businesses that are slower to roll updates out. The number itself isn't something an owner or office manager needs to track; what matters is whether whoever manages your computers has a process that closes that window quickly, every month, without you having to ask.

Two details in this particular release are worth knowing regardless.

The two zero-days already under attack

Two flaws were confirmed as actively exploited in the wild before Microsoft even shipped the patch:

  • CVE-2026-81963 — an elevation-of-privilege flaw in the Windows Update Stack, the component that manages how updates are downloaded, verified and installed.

  • CVE-2026-85880 — an elevation-of-privilege flaw in Windows Advanced Local Procedure Call (ALPC), a core piece of how Windows processes talk to each other.

Neither is a wide-open front door on its own — both require an attacker to already have some low-level foothold on a machine, typically from a phishing email, a malicious attachment, or a previously compromised account. What they're good for is turning that small foothold into full administrative control. That's exactly the kind of second-stage flaw ransomware crews look for: get a user to open something, then use a bug like this to go from "one ordinary account" to "the whole machine, and often the network beyond it."

The irony worth sitting with is that one of the two lives inside Windows Update itself. It doesn't stop the patch from working, but it's a reminder that even the plumbing responsible for keeping you safe is a target in its own right — which is exactly why deferring updates on the grounds that "the update system will always be there when we're ready" isn't a safe assumption to make.

The Office fixes matter just as much

Alongside the Windows-level flaws, this release also patches critical remote code execution bugs across Excel, Word, Outlook and PowerPoint, plus the Windows Graphics Component, Windows Media Foundation and Web Media Extensions. In practice, that means a booby-trapped document or media file — the kind that arrives as an ordinary-looking email attachment — is a realistic way in for several of these, no exotic hacking required on the attacker's part.

What Perth businesses should actually do this week

  • Confirm the update has actually installed, not just downloaded. Windows can sit at "ready to restart" for weeks if nobody actually reboots the machine.

  • Don't defer the restart. A pending reboot means the fix is sitting on disk but not protecting anything yet.

  • If you have a managed IT provider, ask them to confirm rollout status across your fleet this week, not "eventually." A provider running proper managed IT services should be able to tell you exactly how many of your machines are patched, right now.

  • Treat unexpected attachments with more suspicion than usual this month, given how many of the critical fixes are in everyday Office apps.

  • Enforce multi-factor authentication and least-privilege access wherever you haven't already — it's the single best defence against a privilege-escalation bug being chained into something worse, and it's one of the core controls in the ASD Essential Eight.

What we do

Patch management shouldn't depend on someone remembering to click "restart now" on 40 different machines. Our IT security solutions push critical updates like this one out on a managed schedule, confirm they've actually installed (not just downloaded), and flag any machine that's fallen behind — so a record-breaking Patch Tuesday like this one is a non-event for our clients rather than a scramble.

If you're not sure whether your business's computers are fully patched this month, that's worth checking today rather than later. Get in touch or call (08) 9325 1196 — we've been keeping Perth businesses patched and protected since 1997.

Xander
Written by
Xander
Web Developer & IT Technician · 2+ years in IT

Xander builds fast, SEO-friendly websites and handles hands-on IT and computer-repair work — from Next.js builds and local search optimisation through to hardware fixes, OS reinstalls and helpdesk support. He covers the full stack, from the rack to the browser.

Meet the IT Support Perth team →
Xander
9 September 2026
5 min read
Cybersecurity
Patch Management
Windows
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts

Reports of SIM-swap and phone port-out fraud are climbing in Australia, and the target is usually the SMS codes protecting your business banking and email. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

The SMS Sender ID Register Is Mandatory: What Perth Businesses Need to Do

Australia's SMS Sender ID Register became mandatory on 1 July 2026. Here's what Perth businesses that send appointment reminders, invoices or marketing texts need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Microsoft 365 Prices Went Up: What to Check Before Your Perth Business Renews

Microsoft 365 Business Standard is now $21/user/month in Australia, up 12%, while Business Premium is unchanged. Here's what Perth businesses should check before renewal. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do
Cybersecurity
Patch Management

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do

Microsoft's August 2026 security update patched a Windows flaw that was already being exploited to seize full control of machines, plus a critical SharePoint hole. Here's what Perth businesses need to check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/12/2026
Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Call us