
Microsoft's September 2026 Patch Tuesday, released on 8 September, fixed a record 966 vulnerabilities — more than double what it patched across July and August combined — including two zero-day flaws that were already being exploited before the fix existed. The part worth paying attention to isn't just the size of the update: one of those two zero-days sits inside the Windows Update mechanism itself, the exact system your computers rely on to receive this month's fix. If your business runs Windows, the practical takeaway is straightforward — check that updates are actually installing this week, don't put off the restart, and don't assume this is a month you can quietly skip.
What landed this time
This is Microsoft's largest single Patch Tuesday on record. Of the 966 fixes, 105 are rated Critical, and 81 of those are remote code execution flaws — the kind that can let an attacker run their own code on a machine, not just view or corrupt data. Most of the rest are elevation-of-privilege and information-disclosure fixes, spread across Windows, Office, and the underlying components both rely on.
Scale alone isn't the story every month, but it's worth understanding why it matters even if you'll never read a single one of those 966 advisories yourself. A bigger release means a bigger window between "patch published" and "every machine in your business actually has it installed." Attackers know this too — it's common for exploit code targeting a freshly disclosed flaw to appear within days, aimed squarely at the businesses that are slower to roll updates out. The number itself isn't something an owner or office manager needs to track; what matters is whether whoever manages your computers has a process that closes that window quickly, every month, without you having to ask.
Two details in this particular release are worth knowing regardless.
The two zero-days already under attack
Two flaws were confirmed as actively exploited in the wild before Microsoft even shipped the patch:
CVE-2026-81963 — an elevation-of-privilege flaw in the Windows Update Stack, the component that manages how updates are downloaded, verified and installed.
CVE-2026-85880 — an elevation-of-privilege flaw in Windows Advanced Local Procedure Call (ALPC), a core piece of how Windows processes talk to each other.
Neither is a wide-open front door on its own — both require an attacker to already have some low-level foothold on a machine, typically from a phishing email, a malicious attachment, or a previously compromised account. What they're good for is turning that small foothold into full administrative control. That's exactly the kind of second-stage flaw ransomware crews look for: get a user to open something, then use a bug like this to go from "one ordinary account" to "the whole machine, and often the network beyond it."
The irony worth sitting with is that one of the two lives inside Windows Update itself. It doesn't stop the patch from working, but it's a reminder that even the plumbing responsible for keeping you safe is a target in its own right — which is exactly why deferring updates on the grounds that "the update system will always be there when we're ready" isn't a safe assumption to make.
The Office fixes matter just as much
Alongside the Windows-level flaws, this release also patches critical remote code execution bugs across Excel, Word, Outlook and PowerPoint, plus the Windows Graphics Component, Windows Media Foundation and Web Media Extensions. In practice, that means a booby-trapped document or media file — the kind that arrives as an ordinary-looking email attachment — is a realistic way in for several of these, no exotic hacking required on the attacker's part.
What Perth businesses should actually do this week
Confirm the update has actually installed, not just downloaded. Windows can sit at "ready to restart" for weeks if nobody actually reboots the machine.
Don't defer the restart. A pending reboot means the fix is sitting on disk but not protecting anything yet.
If you have a managed IT provider, ask them to confirm rollout status across your fleet this week, not "eventually." A provider running proper managed IT services should be able to tell you exactly how many of your machines are patched, right now.
Treat unexpected attachments with more suspicion than usual this month, given how many of the critical fixes are in everyday Office apps.
Enforce multi-factor authentication and least-privilege access wherever you haven't already — it's the single best defence against a privilege-escalation bug being chained into something worse, and it's one of the core controls in the ASD Essential Eight.
What we do
Patch management shouldn't depend on someone remembering to click "restart now" on 40 different machines. Our IT security solutions push critical updates like this one out on a managed schedule, confirm they've actually installed (not just downloaded), and flag any machine that's fallen behind — so a record-breaking Patch Tuesday like this one is a non-event for our clients rather than a scramble.
If you're not sure whether your business's computers are fully patched this month, that's worth checking today rather than later. Get in touch or call (08) 9325 1196 — we've been keeping Perth businesses patched and protected since 1997.



