VORANT. Threat Intelligence Sign in Get the full feed

Microsoft's record Patch Tuesday: 973 flaws, 2 exploited

high vulnerability technology

Microsoft's September 2026 Patch Tuesday fixes a record 973 vulnerabilities, including two actively exploited Windows privilege escalation flaws and critical unauthenticated RCEs in Skype for Business, MSMQ, and RRAS.

Microsoft's September 2026 Patch Tuesday is the largest on record, addressing 973 vulnerabilities (113 critical), surpassing the previous high of 664 set in July 2026. Two flaws are confirmed exploited in the wild by Microsoft, though neither was publicly disclosed prior to release: CVE-2026-81963, a Windows Update Stack elevation-of-privilege bug (CVSS 7.8) allowing a local low-privileged attacker to abuse link-following behavior to gain SYSTEM on Windows 11 and Windows Server 2025; and CVE-2026-85880, a Windows ALPC heap-based buffer overflow (CVSS 7.8) allowing an attacker running code in a low-privilege AppContainer to escape the sandbox and gain SYSTEM, with no user interaction required, affecting Windows 10 and Server 2012/2016/2019/2022. Neither is yet listed in CISA's KEV catalog.

Separately, four critical unauthenticated RCEs (all CVSS 9.8) were patched with no evidence of in-the-wild exploitation: CVE-2026-66302 in Skype for Business Server (2015 CU13, 2019 CU8, Subscription Edition CU1), where a crafted network request can write an attacker-controlled file to an arbitrary server location; CVE-2026-69579, a use-after-free in Windows Message Queuing (MSMQ) exploitable via a crafted packet with no authentication; and CVE-2026-69590 in Windows Routing and Remote Access Service (RRAS), exploitable via a crafted network packet against supported Windows 10/11 and Server releases.

Defenders should prioritize the two exploited EOP bugs first, then patch or mitigate exposed Skype for Business, MSMQ, and RRAS deployments. Where these services aren't required, disabling them or restricting network access (e.g., blocking MSMQ's TCP port 1801, firewalling RRAS) reduces exposure until updates are applied. Given the sheer volume of fixes this month, organizations should use vendor dashboards to triage the full list against their environment.

Mentioned in this report

Vulnerabilities CVE-2026-66302CVE-2026-69579CVE-2026-69590CVE-2026-81963KEVCVE-2026-85880KEV

Source reporting: https://isc.sans.edu/diary/rss/33320

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free