Microsoft's Record Patch Tuesday: 974 Fixes, 2 Live Zero-Days
aop3d techShare
Microsoft's Record Patch Tuesday: 974 Fixes, 2 Live Zero-Days, and the Patch That Needed a Patch
The wizard just watched Windows swallow the largest security update in its history — then saw Microsoft rush out emergency fixes a week later when the mega-patch broke a few things of its own. Here's what actually happened, why it happened, and what you should do about it.
1. The biggest update in Windows history
On September 8, Microsoft dropped its monthly Patch Tuesday — and this one was a monster. Per Microsoft's own release notes, it closed 974 vulnerabilities across the company's products, utterly smashing the previous record of 570 set just two months earlier in July.
For perspective: Microsoft patched 909 vulnerabilities in all of 2023. This single Tuesday beat an entire year. The haul broke down to roughly 723 Windows flaws, 111 in Office, with analysts counting 113 rated Critical and about 860 rated Important. (Counts vary slightly by tracker — most put it between 964 and 974 — but whichever way you slice it, this is the largest Patch Tuesday on record.)
2. Why the flood? Blame the AI bug hunters
This surge didn't come from nowhere. Microsoft warned customers back in July to expect a tidal wave of security updates, because its security teams are now using agentic AI tools to discover zero-day vulnerabilities at a pace no human team could match.
Look at the trajectory: 164 CVEs in April, 120 in May, 200 in June, then 570 in July, 400 in August, and 974 in September. AI has supercharged vulnerability reporting — finding holes faster — which is genuinely good news for security. But it also means patch day is about to get much heavier for everyone, forever.
3. The scary part: two bugs were already being exploited
Volume alone wouldn't be terrifying — but two of September's flaws were zero-days already under active attack. Both were elevation-of-privilege bugs that let an attacker climb to full SYSTEM control of a machine, and both landed in CISA's Known Exploited Vulnerabilities catalog the same day:
| Vulnerability | What it is | Impact |
|---|---|---|
| CVE-2026-81963 | Windows Update Stack improper link resolution | Local privilege escalation to SYSTEM |
| CVE-2026-85880 | Windows ALPC heap-based buffer overflow | Sandbox escape + privilege escalation to SYSTEM |
On top of those, researchers flagged roughly 20 wormable remote-code-execution bugs — the kind that can spread machine to machine without a user clicking a thing. If you've been postponing updates, this is the month to stop doing that.
4. The twist: the mega-patch broke things, so Microsoft patched the patch
Here comes the irony, my friend. An update this enormous, tested against this many configurations, was bound to rattle a few cages. On September 15, Microsoft pushed out-of-band emergency fixes after the record rollout caused real-world breakage:
- Remote Desktop Services (RDS) started misbehaving
- Hyper-V virtual machines hit unexpected side effects
- Certain USB audio devices went sideways
As one security chief put it: expect this risk to grow as patch volumes grow — every extra dependency expands the testing matrix until reproducing every real-world setup is nearly impossible. Translation: gigantic updates can fix 974 holes and punch a few new dents at the same time. The lesson isn't "don't patch" — it's "patch, then pay attention."
5. Your action spell — do these today
You don't need to read 974 advisories. You need exactly this:
- Install the updates now. Settings → Windows Update → Check for updates. Then restart — yes, actually restart.
- Check what Windows you're running. Windows 11 22H2 is out of support and gets none of these fixes. If you're still on it, upgrade — you're standing outside the castle while the dragon's loose.
- Back up first if you're nervous. With mega-patches occasionally breaking things (see point 4), a quick backup before updating is cheap insurance.
- If you run Hyper-V or Remote Desktop, grab the follow-up emergency fixes from September 15 too — the first round wasn't the whole story.
- Keep auto-updates on. AI is finding bugs faster than ever, which means the window between disclosure and exploitation keeps shrinking.
The wizard's summary
- Microsoft's September 2026 Patch Tuesday fixed a record 974 vulnerabilities — more than all of 2023 combined.
- AI-driven bug hunting is why the flood came, and it's not slowing down.
- Two flaws were already being exploited — these updates aren't optional.
- The record patch broke RDS, Hyper-V, and some USB audio; Microsoft shipped emergency fixes on September 15.
- Update now, restart for real, and if you're on Windows 11 22H2 — it's time to move on.
The tide rolls on, my friend — stay patched, stay curious, and the wizard will see you at the next one.