Nearly 1,000 Windows Fixes in One Month: Two Zero-Days Already Being Exploited

Microsoft's September 2026 Patch Tuesday sets a new record with 964 security fixes, including two flaws criminals are already using against real targets and roughly 20 bugs that could spread automatically across networks.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial image of a darkened office workstation showing a Windows-style login screen glowing on the monitor, with a faint blue reflection on the
Share

Key points

  • Microsoft issued 964 security fixes on September Patch Tuesday 2026, the largest single-month total since the company began using artificial intelligence to find flaws.
  • Two zero-days, meaning flaws that were already being exploited before a fix existed, are confirmed in active use against Windows systems.
  • A Windows DNS vulnerability, tracked as CVE-2026-69730, has not yet been exploited but Microsoft expects it will be, and security researchers warn it could spread like a self-replicating worm.
  • SAP also patched a perfect-score critical flaw (10.0 out of 10) in software used by large enterprises worldwide.
  • Adobe, Fortinet, Cisco, and Red Hat each released urgent fixes for vulnerabilities that criminals are already exploiting.

What just happened?

Microsoft released fixes for 964 security flaws on its regular monthly update day, known as Patch Tuesday, shattering previous records. The company credits artificial intelligence tools, which it began using mid-year, with finding flaws faster than human researchers ever could alone.

Not every organisation will be exposed to every flaw. But two of those vulnerabilities are already being used by criminals right now, and that makes this month's update unusually urgent.

Which vulnerabilities are being exploited right now?

Two zero-days are confirmed. Both let attackers gain elevated control over a Windows machine.

CVE ID What it affects What attackers can do Actively exploited?
CVE-2026-85880 Windows ALPC (an internal messaging system letting programs talk to each other) Escape a restricted software environment and gain higher-level control Yes
CVE-2026-81963 Windows Update Stack (the mechanism that delivers software updates) Gain full system-level privileges Yes
CVE-2026-69730 Windows DNS (the system that translates website names into addresses) Run malicious code remotely with no password or user action Not yet, but expected
CVE-2026-62893 Windows Deployment Services Spread automatically across a network Not confirmed
CVE-2026-69590 Windows Routing and Remote Access Spread automatically across a network Not confirmed

CVE-2026-85880 affects Windows Server 2012, Windows Server 2016, and Windows 10. Ivanti's vice-president of product management Chris Goettl said it "affects the entire Windows fleet." CVE-2026-81963 targets Windows 11 and Windows Server 2025.

Could any of these spread on their own?

Yes, and that is the detail keeping security teams up at night. Dustin Childs, head of threat awareness at the Zero Day Initiative, counted roughly 20 vulnerabilities in this batch that could be "wormable," meaning a piece of malicious software could use them to copy itself from machine to machine across a network without anyone clicking anything.

The DNS flaw, CVE-2026-69730, is the one drawing the most concern. An attacker could send a single crafted network packet and execute code on a target machine, with no password required and no action from the victim. Childs described it as a spiritual successor to SigRed, a 2020 DNS worm vulnerability that alarmed the industry at the time.

What about software beyond Windows?

Several other major vendors also pushed urgent fixes this month, first reported across the industry including by CSO Online.

SAP patched a flaw scoring 10.0 out of 10 on the standard severity scale in its Extended Passport Processing component, used inside large enterprise software suites like SAP S/4HANA. Three SAP fixes this month require no valid login credentials at all for an attacker to exploit them.

Adobe fixed an actively exploited zero-day in Adobe Commerce and Magento, the popular online shop software, tracked as CVE-2026-75650 and rated 10.0. Researchers named it StyleSmuggler; it plants hidden back-doors on Linux servers. Adobe called it "Urgent Action."

Fortinet confirmed criminals are actively using two older authentication bypass flaws in FortiOS, meaning attackers can take over edge firewalls, the devices that sit between an organisation's network and the internet, without a password. Cisco warned of active exploitation of a denial-of-service flaw in its Secure Firewall product, tracked as CVE-2026-20349.

Should ordinary people worry?

If you use a Windows PC at work, your IT team needs to apply this month's updates as soon as possible. If you shop on a website powered by Adobe Commerce or Magento, the store's operator needs to patch immediately. Watch your bank statements and email for anything unusual over the coming weeks.

For everyone else: keep your devices updated and do not ignore prompts to restart after an update. That restart is often what actually applies the fix.

© 2026 Threat Vectr