Microsoft ships record 973 patches; CISA flags two actively exploited flaws
One of the two actively exploited bugs lives in the Windows update stack: the very component defenders rely on to verify they're patched.
TL;DR
Microsoft's September Patch Tuesday landed at 973 vulnerabilities, the fourth consecutive record-breaking month. CISA added two of them, CVE-2026-81963 and CVE-2026-85880, to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 22 to patch under BOD 22-01. CVE-2026-81963 is the more alarming of the two: it lives in the Windows update stack, the mechanism that installs patches. As Automox engineer Serena DiPenti put it, "an attacker who owns the update stack owns the thing you'd use to evict them."
Microsoft's September Patch Tuesday shipped 973 vulnerability fixes, a new record that shattered July's previous high of 622 and pushed the year's total past 2,600, more than double the entire 2020 tally. Within that flood, CISA flagged two for immediate action: CVE-2026-81963 and CVE-2026-85880, both under active exploit, with a Binding Operational Directive 22-01 deadline of September 22 for federal civilian agencies.
CVE-2026-81963 is the one that should command attention beyond the federal deadline. It lives in the Windows update stack, the component that installs and tracks patches. Automox engineer Serena DiPenti described the problem bluntly: "An attacker who owns the update stack owns the thing you'd use to evict them. If you can't say when the update stack last ran, you can't say whether it's patched." The bug is the kind of privilege-escalation vector that slots into ransomware chains: phish one user, exploit this flaw, gain system-level access, deploy payload. But its location inside the patching mechanism itself makes post-remediation verification unusually difficult.
CVE-2026-85880 affects a Windows messaging component. Tenable's Satnam Narang confirmed both bugs are being actively exploited.
The surge isn't a spike
September's 973 follows 419 in August, 622 in July, and 206 in June, four consecutive months that each would have been an all-time record before this year. Microsoft acknowledged in May that its internal AI tool, MDASH, is driving the surge in discovered flaws, and Britain's NCSC separately warned organizations to prepare for a faster patching tempo. The volume is a structural shift, not a one-off. Meanwhile, Nightwing's Nick Carroll noted that more than 22,000 corporate Exchange servers remain unpatched against weaponized exploit code, a reminder that even when patches ship, enterprise deployment lags badly.
For federal defenders, the immediate task is the two KEV CVEs by September 22. For everyone else, the update-stack bug demands priority: patch it, then verify the patching mechanism itself is intact. On a Patch Tuesday of 973 fixes, that's a narrower to-do list than the headline number suggests.
Published ·Deep Fathom