How To Respond As Microsoft Confirms 973 Security Vulnerabilities
Since October 2003, Microsoft has rolled out security updates on the second Tuesday of every month, covering all products in one fell swoop. The September Patch Tuesday, however, is different: it’s the biggest ever, with no fewer than 973 vulnerabilities disclosed, 119 of which have been rated critical, and two are known to have been exploited in the wild. The good news is that all vulnerabilities, including the two Windows zero-days, CVE-2026-85880 and CVE-2026-81963, have updates that resolve their respective security issues. The less good news is that with so many vulnerabilities announced in one go, enterprises could find it problematic to follow the “just patch it” advice that often accompanies such disclosures. Here’s what cybersecurity experts recommend your response should look like.
How To Manage The Record-Breaking September Microsoft Patch Tuesday Update Cycle
First things first, don’t get too carried away by that headline number of 973 Microsoft security vulnerabilities . Sure, it’s a record-breaking number and could all too easily be interpreted as a major problem for users of Microsoft products and services. But letting fear, uncertainty and doubt get the better of you is never conducive to good security hygiene. “We need to remember that these large CVE counts are a good thing,” Tyler Reguly, associate director, of security research and development at Fortra, said, “as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities.”
The bad thing, however, cannot be ignored and that’s the pressure this level of patch releases puts on security teams. “Right now, if you are in charge of teams managing patches,” Reguly said, “you are probably struggling with what to do.” And that’s the problem, as Jack Bicer, director of vulnerability research at Action1 told me. At this kind of scale, the challenge that organizations face “is not simply getting through the patch list but knowing what needs attention first.” With almost 1,000 updates to take into account, quickly disentangling those vulnerabilities that demand immediate action from “those that can follow the normal deployment cycle” is not just helpful, but critical to your organization’s security posture.
Bicer highlighted both the CVE-2026-81963 Windows update stack elevation of privilege and the CVE-2026-85880 Windows advanced local procedure call elevation of privilege vulnerabilities as belonging in the “deployed urgently” category. CVE-2026-81963 could allow an authorized attacker to exploit improper handling of links during local file access and elevate their privileges to SYSTEM, while CVE-2026-85880, a heap-based buffer overflow vulnerability , could allow an authorized local attacker to also elevate privileges, potentially leading to “complete control of an affected Windows endpoint."
No matter what the source of the patch tsunami, as Mayuresh Dani, security research manager at Qualys Threat Research Unit, said, consider the use of the CISA Known Exploited Vulnerabilities catalog or a Likely Exploited Vulnerabilities model, rather than relying upon Common Vulnerability Scoring System severity scores alone. “Graduate to a tiered patching SLA mechanism,” Dani said , “a KEV-listed CVE should be patched within 24-36 hours,” with the next tier being internet-facing high-privilege infrastructures. Severity scores alone are not going to cut it; you need to put everything into the context of risk to your enterprise alone.
“The ebb and flow of the ‘Patch Apocalypse’ continues with no sign of slowing yet,” Todd Schell, principal product manager at Ivanti, said. Like Dani, Schell advised that “patches need to be triaged to identify those CVEs that require immediate attention, including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities.”