Lessons from Microsoft's September 2026 Patch Tuesday

ManageEngine Patch Manager Plus banner featuring the headline “Lessons from Microsoft’s September 2026 Patch Tuesday” alongside a calendar marked Patch Tuesday, critical patches, and a blue security shield.

This month's Patch Tuesday just became the largest security release in Microsoft's history (so far), and it's tempting to let that record stand as the headline. However, the volume isn't the highlight. What a cycle this size exposes is how most patching processes are built, and exactly where they buckle.

Here's what this month actually taught us, and what we need to change before the next record-breaking cycle arrives.

By the numbers

Vulnerability

Impact

Total Microsoft CVEs

974

Critical vulnerabilities

113

Elevation of Privilege (EoP)

438

Remote code execution (RCE)

258

Information disclosure

173

Denial of Service (DoS)

56

Security feature bypass

19

Spoofing

16

Tampering

14

Actively exploited zero-days

2 (CVE-2026-81963, CVE-2026-85880)

Third-party vendors ship their own updates in the same window, and none of those CVEs appear in the count above.

The two actively exploited zero-days demand close attention: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (Windows Advanced Local Procedure Call [ALPC] EoP). While EoP flaws lack the headline impact of remote code execution bugs, they are the second move in most intrusion chains. Once an attacker gains an initial foothold via a phishing email or browser flaw, an EoP vulnerability like either of these grants them access to the SYSTEM account on that machine, which is the position from which credential theft and lateral movement toward domain admin actually start.

July set the previous record. August fell back to roughly 400 CVEs, and September more than doubled it. The pattern points in the same direction: patch volume is climbing faster than most patching processes were built to handle. A team that could comfortably review every advisory a few years ago is now facing a release nearly six times the historical monthly average. That gap between volume and process is where this month's real lessons live.

Lesson 1: Manual CVE analysis is formally dead

At nearly 1,000 CVEs in one release, reading through advisory notes one at a time isn't a viable process for any team, regardless of headcount. It was already a stretch at a few dozen patches a month. At this scale, it guarantees something important gets missed, because no one got to it in time.

The fix now is a different starting point. Instead of parsing raw advisories, teams need a tool that has already done the sorting: every patch tagged by severity as it's ingested; systems classified by exposure so you can see at a glance which ones are Healthy, Vulnerable, or Highly Vulnerable; and that classification updating automatically as new patches land. Patch Manager Plus builds this view by default, so the starting point for triage is a prioritized list.

Lesson 2: Severity labels do not convey urgency

Both of this month's actively exploited zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, are rated Important, not Critical, with a CVSSv3 score of 7.8 each. A process that filters patches by Critical tags alone would have pushed both of those actively exploited vulnerabilities further down the queue, behind patches with a higher tag but no exploitation happening at all.

Exploited status deserves its own priority tier, separate from severity. Patch Manager Plus' default system health policy marks a machine Highly Vulnerable when it is missing patches rated Critical or Important; in this instance, both zero-days are already considered top-tier priorities rather than falling into a second-class bucket. Beyond that, the critical vulnerabilities tab surfaces zero-day patches for immediate deployment, which is where these two belong on day one.

Lesson 3: Speed matters, but stability still counts  

Patching fast and patching effectively to not break anything in production are often two forces at odds, and September's volume makes that tension sharper than usual. Zero-days and anything landing on known exploited vulnerabilities (KEV) need a response measured in days, not weeks. The other 900-plus patches in this release don't carry that urgency, and pushing all of them out at the same pace raises the odds of an outage more than it reduces risk.

Flowchart illustrating Patch Tuesday release management, divided into zero-days and KEV flaws requiring emergency response, and standard updates requiring staged rollout. Includes key actions for each approach.

A staged approach handles both. Start with a pilot group—IT team devices or a non-critical department—and validate the patch before it touches production. Move the broader rollout into scheduled maintenance windows, with the rollback path documented before deployment starts. Then track success and failure rates as patches land, and follow up on any outliers immediately rather than waiting for the next reporting cycle to surface them.

Lesson 4: The threat landscape extends beyond the OS

This month alone brought 111 vulnerabilities in Office, 62 in SQL Server, 22 in developer tools, 16 in SharePoint Server, and 9 in Exchange Server. Roughly a quarter of the release sits outside the core OS, in products your patching process may or may not cover. And that is before the browsers, PDF readers, and other third-party applications patching on their own schedules.

Unify OS and third-party patching cycles, and treat them as one patching workflow rather than several disconnected ones. Inventory the critical applications running across the fleet and prioritize the applications most commonly used for initial access or lateral movement.

Building an adaptable patching architecture

The biggest takeaway from this Patch Tuesday is that triage, prioritization, staged rollout, and full-stack coverage all have to keep pace with disclosure volume. Patch Manager Plus is built to support exactly that workflow, from first scan to final compliance report. If September's release stretched your process, now's a good time to see how it holds up against the next one. The next cycle is three weeks out.