Microsoft’s latest Patch Tuesday tackles 964 vulnerabilities, with two actively exploited zero-days, amid rising disclosure rates and increasing pressure on security teams to manage escalating patch workloads. The update underscores ongoing enterprise risks beyond Microsoft, including critical flaws in SAP systems.
Microsoft’s September Patch Tuesday has landed with an unusually heavy workload for administrators, as the company moved to close 964 vulnerabilities across Windows and related products. Among them are two zero-day flaws already exploited in the wild, making this release one that security teams are likely to prioritise over routine maintenance. The update also sits within a broader rise in disclosed issues that Microsoft and outside researchers have been surfacing more aggressively in recent months.
The two actively exploited vulnerabilities are CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, and CVE-2026-81963, an elevation-of-privilege weakness in the Windows Update Stack. According to coverage from Action1 and other security digests, the flaws affect multiple Windows versions and have no practical workaround, which leaves patching as the main defence. One report placed the total at 995 patches, while others cited 973 or 974 vulnerabilities overall, reflecting differences in how Microsoft counts bundled fixes, third-party components and mitigated issues.
Computer Weekly said the volume of disclosures is adding pressure to already stretched security teams, particularly as Microsoft’s use of AI-assisted discovery appears to be increasing the number of flaws found before attackers do. The company’s figures exclude third-party and open-source CVEs, Chromium and Edge issues, and several Microsoft mitigations in services such as Azure, Entra and Copilot Studio where customers do not need to take action. Even so, the scale of the release reinforces how patch management has become a continuous operational task rather than a monthly housekeeping exercise.
Beyond Microsoft, SAP administrators were also urged to act quickly on a separate critical issue in the Extended Passport Processing component used in ABAP environments. Researchers at Onapsys said the flaw carries a CVSS score of 10.0 and could severely affect confidentiality, integrity and availability if abused, with potential impact on systems such as SAP S/4HANA and NetWeaver. In practice, that makes this month’s patch cycle a reminder that enterprise risk rarely stops at one vendor’s ecosystem.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





