Microsoft's September 2026 security update addresses 1186 vulnerabilities: 119 rated Critical, 913 Important. 2 are already exploited in the wild and 0 were publicly disclosed before today.
This is a big patch batch — 1,186 CVEs total — but the real story is three vulnerabilities already in CISA's KEV catalog, two of them zero-days actively exploited before today's release. Neither of the exploited Windows bugs was publicly disclosed ahead of the patch, so there's no advance warning you missed, but that also means attackers had a head start you didn't.
Prioritize the KEV-listed items below over the raw volume of Important-rated EoP and RCE bugs padding out the rest of this month's release.
Patch these first
CVE-2026-81963 (Important, CVSS 7.8) — Windows Update Stack: Elevation of Privilege — exploited in the wild, CISA KEV












