In a fresh development, that’s more than twice as many as last month and a fresh record. Yesterday was September Patch Tuesday, which means Microsoft dropped security updates addressing 973 fresh security vulnerabilities.
Industry observers note that microsoft classifies 113 of the 973 vulnerabilities as critical, including 83 remote code execution (RCE) issues. The remaining vulnerabilities are classified as high risk, and two are already being exploited in the wild. Along with Windows and Office, other products have been revised, including Defender, Exchange Server, Hyper-V, Skype for Business, Visual Lab, and Microsoft’s cloud services.
According to the latest update, the next Patch Tuesday is scheduled for October 13th, 2026.
As part of the ongoing story, windows security vulnerabilities.
Industry observers note that a large number of the vulnerabilities—over 700 this time—are spread across the various Windows versions (10, 11, Server) for which Microsoft still provides security updates.
Industry observers note that the CVE-2026-81963 vulnerability in the Windows Revision stack allows attackers to gain elevated privileges, enabling them to execute code with system privileges by combining this exploit with an RCE vulnerability. This month, two Windows vulnerabilities classified as high risk are already being exploited in the wild.
The report highlights that in this case, the exploit code must be concealed within a document so that a user can trigger it. For both zero-days, it’s unclear how widespread the attacks are. The second zero-day vulnerability, CVE-2026-85880 , is in Windows Advanced Local Procedure Call (ALPC) and it’s also an elevation of privilege (EoP) vulnerability.
Industry observers note that critical Windows vulnerabilities.
In a fresh development, these include CVE-2026-69525 in the Windows Remote Desktop Service, a use-after-free (UAF) vulnerability that an attacker could exploit to remotely execute injected code without authentication or user interaction. Microsoft has classified 77 Windows vulnerabilities as critical, including 56 RCE vulnerabilities.
The report highlights that microsoft had to patch 64 vulnerabilities in the biometric service, most of them very similar to one another and following the same pattern. In 56 cases, there are buffer overflows. CVE-2026-69727 allows elevated privileges over the network, while CVE-2026-73008 exposes personal data—hardly what one would want or expect from a biometric service. Windows Hello also has nine vulnerabilities, eight of which are EoP vulnerabilities classified as critical.
The report highlights that microsoft Office security vulnerabilities.
The report highlights that these include 22 RCE vulnerabilities classified as critical, five of which are in Excel alone. In the case of critical RCE vulnerabilities in Office, the preview pane is often an attack vector—a user doesn’t need to open a malicious file for an attack to succeed. Microsoft has fixed 137 vulnerabilities in its Office products, slightly more than in August.
In a fresh development, in SharePoint, Microsoft has patched 16 vulnerabilities, six of which are RCE vulnerabilities. Meanwhile, RCE vulnerabilities classified as high risk can be exploited when a user opens a malicious file in a vulnerable Office product (called “open-and-own”).
In a fresh development, microsoft Exchange Server vulnerabilities.
Industry observers note that these include two RCE vulnerabilities: CVE-2026-55007 and CVE-2026-69355 . This month, Microsoft has fixed nine vulnerabilities in Exchange Server, all of which are classified as high risk.
According to the latest update, the exploit is triggered when the email is processed, without the need for a preview pane. In the case of CVE-2026-55007, an attacker need only send an email containing a malicious Visio file.
In a fresh development, microsoft Edge security vulnerabilities.
As part of the ongoing story, it addresses one zero-day vulnerability as well as other Chromium vulnerabilities that aren’t included in the total number of vulnerabilities mentioned above. The most recent security patch to Edge 152.0.4191.66 is dated September 4th and is based on Chromium 152.0.7977.83.