September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows
Summary
Microsoft released nearly 1,000 security fixes in September 2026, including two zero-day vulnerabilities (CVE-2026-85880, a buffer overflow in Windows messaging that allows privilege escalation, and CVE-2026-81963, a flaw in Windows Update that lets attackers gain system-level access) that are already being exploited. The large number of patches reflects Microsoft's use of AI to find bugs, and security experts warn that about 20 vulnerabilities could potentially spread as worms (self-replicating malware) across many systems.
Solution / Mitigation
For CVE-2026-85880 and CVE-2026-81963: "There is no workaround other than installing the fix" (Microsoft's September 2026 Patch Tuesday update). Microsoft recommends immediate installation, especially since exploitation has been detected. For the SAP ABAP vulnerability: developers and SAP administrators should apply patches to the Extended Passport Processing (EPP) component, though the source does not specify the exact patch details.
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4219846/september-2026-patch-tuesday-roundup-plugs-for-two-zero-day-holes-among-almost-1000-fixes-in-windows.html
First tracked: September 9, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 65%