Microsoft has released its largest September security patch, addressing nearly 970 vulnerabilities, two of which are actively exploited zero-days affecting Windows and other Microsoft products, prompting urgent application by cybersecurity teams.
Microsoft has issued its September security update for Windows, and the scale is unusually large. The package, identified as KB5124008, covers build 26200.9445 and 26100.9445 for supported versions of the operating system. The update folds in changes previously delivered in August’s KB5120998 and, according to reports on the release, represents the company’s biggest monthly security effort to date. Coverage of the patch varies slightly across sources, with counts ranging from 964 to 974 flaws depending on whether Windows-only issues or Microsoft-wide vulnerabilities are included. The update affects multiple Windows versions through the normal servicing channels. According to El Diario and security reporting from Malwarebytes, DataComm and the UK’s NHS cyber alert service, the release also includes fixes already marked as actively exploited.
Microsoft says two zero-day vulnerabilities are part of the package. The first, CVE-2026-81963, affects the Windows Update Stack and is an elevation-of-privilege flaw linked to incorrect link resolution before file access. The second, CVE-2026-85880, affects Windows Advanced Local Procedure Call, or ALPC, and involves a buffer overflow. Security analysts cited by DataComm, Security.io and the NHS say both bugs could allow an attacker with local access to gain SYSTEM-level privileges. Each has been rated important, with a CVSSv3 score of 7.8.
Beyond those zero-days, the September release is broad. El Diario reported 105 critical issues among 966 fixes, including remote code execution, privilege escalation, information disclosure and security feature bypass bugs. Other coverage puts the critical count at 104 and the total at 964 or higher, reflecting differences in how Microsoft groups product families and platform-specific issues. WindowsLatest reported that Microsoft’s wider September security release spans vulnerabilities across Office, SQL Server, Azure, Exchange, SharePoint and developer tools, while some products that run on Windows are tracked separately from the Windows family itself.
Microsoft also made non-security changes in the same update. El Diario said the company altered how new secure boot certificates are distributed automatically, widening the set of devices eligible to receive them. It also added quality improvements to the Windows servicing stack, the component responsible for installing updates. The patch is now available through the standard update mechanisms, and cyber security teams, including the NHS, have urged organisations to apply it promptly because the two zero-days are already reported as being exploited in the wild.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





