Microsoft shipped 974 security fixes at once. Two were already being used against people.
Microsoft & Cloud

Microsoft shipped 974 security fixes at once. Two were already being used against people.

September's Patch Tuesday is the biggest Microsoft has ever released. For a business with a handful of PCs and a server in the corner, the job is not getting through all 974. It is knowing which ones matter this week.

14 September 20265 min read

Microsoft's September security update fixes 974 separate vulnerabilities. The Register and Infosecurity Magazine both put the figure at 974 and both called it a record for a single Patch Tuesday.

Infosecurity Magazine's breakdown puts 119 of them at critical severity, with 723 in Windows and 111 in Office. The Register counted 20 vulnerabilities it described as wormable and nine in Exchange Server. Adobe added 172 CVEs across ten bulletins the same day.

The two that were already being used

Two of the 974 were under active attack when the fixes shipped. CVE-2026-85880 is a heap based buffer overflow in Windows ALPC, rated CVSS 7.8 by Infosecurity Magazine, which lets an attacker escape a sandbox and raise their privileges to SYSTEM. CVE-2026-81963 is an improper link resolution flaw in the Windows Update Stack that also ends in SYSTEM level access. Dustin Childs of the Zero Day Initiative said of the second one: "Patch this one quickly."

Neither of those gets an attacker into your network on its own. Both are the kind of flaw that turns a foothold into full control of a machine, which is the step between somebody clicking the wrong link and an attacker owning your domain. That is why they go first, ahead of things with scarier scores.

Where the rest of the list actually lands

Most small businesses will never see 974 updates, because you only receive patches for the products you run. A five person office on Windows 11 laptops and Microsoft 365 gets a Windows cumulative update and an Office update, and Windows Update applies them. The number that matters there is not 974, it is how many machines have not been restarted since.

The exposure sits elsewhere. Infosecurity Magazine listed remote code execution flaws in Windows DNS Server at CVSS 9.8, Windows DHCP Server at 8.8 and Windows Deployment Services at 9.8. Those are server roles. If you still run a domain controller, a file server, or anything handling DNS and DHCP on your own network, that is where this month's real work is, and those are exactly the machines nobody wants to restart during working hours.

Exchange, again

The Register counted nine Exchange Server flaws this month, and Dustin Childs picked out CVE-2026-55007, a remote code execution issue triggered through a malicious Visio attachment, as the most important patch in the release. That lands in the same fortnight Microsoft began throttling and then blocking mail from Exchange 2016 and 2019 servers not patched to the October 2025 update, which we covered last week. If you have an Exchange server on site, those two jobs are one job, and it moved from pending to overdue on Tuesday.

Adobe deserves a look too

Adobe's 172 CVEs included CVE-2026-75650, nicknamed StyleSmuggler, an unauthenticated remote code execution flaw in Magento and Adobe Commerce affecting versions 2.4.4 through 2.4.9. The Register reported it had been used in attacks since 4 September. If you sell online through Magento, that one is not a scheduling question.

How to triage a list this size

Jack Bicer, director of vulnerability research at Action1, put the problem to Infosecurity Magazine plainly: "At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first." The order that works for a small business is the same every month and gets more valuable the larger the release. Anything under active exploitation first. Then anything facing the internet. Then servers, then workstations. Then everything else on the normal cycle.

The failure mode here is not being slow. It is having no list at all, so that nobody can say which machines took this month's update and which were switched off in a drawer that week. A patch report nobody reads still beats a patch process nobody has written down.

What this means for your business

The headline number is not your problem. Microsoft only sends fixes for what you run, and on a fleet of laptops using Microsoft 365 the September update amounts to a restart. The work sits on machines with server roles, because the serious remote code execution flaws this month are in Windows DNS, DHCP and Deployment Services, and on any Exchange server still on site, where nine more flaws landed in the same week Microsoft started blocking mail from unpatched servers. Two flaws were already being exploited when the patches shipped, so those go first whatever else is queued. If you cannot get a straight answer to how many of your machines took this month's update and when, that gap deserves more attention than the 974 does.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.