Microsoft Issues Record Security Update Addressing Nearly One Thousand Software Flaws

Microsoft fixed 723 vulnerabilities in Windows and 222 in Office, while also addressing flaws in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10) and Exchange Server (9).
The 966-flaw count used by BleepingComputer excludes 204 vulnerabilities patched earlier in September across services including Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Microsoft Fabric and Power Automate.
Of the 105 critical vulnerabilities, 81 were remote-code-execution flaws, 20 involved privilege escalation, two involved information disclosure and one was a security-feature bypass.
Security researchers noted that the Windows Advanced Local Procedure Call flaw was only the second zero-day fixed in that component in nearly four years, while the Windows Update Stack issue was the first zero-day among seven flaws found in that component over the past five years.
Microsoft attributed the Windows Update Stack vulnerability to Romain Deperne and the Microsoft Threat Intelligence Center, but did not initially disclose how the flaw was being exploited.
Microsoft released its largest security update ever in September 2026, patching nearly 1,000 vulnerabilities across Windows, Office, Azure and other products. CyberScoop reported that two flaws were already being actively exploited in the wild as zero-days: one in Windows Advanced Local Procedure Call and another in Windows Update Stack, both allowing local attackers to gain full system control.
The patch batch included 105 critical vulnerabilities, with 81 of them enabling remote code execution that could let attackers take over machines from afar. Security Brief noted this marks the highest number of CVEs Microsoft has ever published in a single month.
Windows accounted for 723 of the roughly 966 vulnerabilities patched in September. Technobezz reported the update addressed flaws across multiple Microsoft products, with Office receiving 222 fixes and SQL Server getting 62 patches. Smaller product lines like Azure, SharePoint Server and Exchange Server rounded out the remaining critical updates across the Microsoft ecosystem.
The Windows Advanced Local Procedure Call zero-day marked only the second active exploit in that component in nearly four years, according to security researchers. The Windows Update Stack vulnerability was even more unusual—it was the first zero-day found among seven total flaws in that component over five years. Both flaws could grant attackers SYSTEM-level privileges with just local access to a machine.
Beyond security fixes, Microsoft delivered new customization options in Windows 11, including the ability to move and resize the taskbar—a feature users had requested for years. The update also lets users adjust Start menu layout and visibility, gain better Windows Search controls, and enjoy improved touch scrolling in File Explorer. These features will roll out gradually and are more limited on Windows 11 version 26H1.
Microsoft also fixed crashes affecting Teams and Outlook on Arm-based PCs, addressing a pain point for users running Microsoft's software on newer ARM processors. Earlier September updates had already patched 204 vulnerabilities across Azure AI Language, Azure Cosmos DB, Copilot Studio and other cloud services, Security Brief reported.
Of the 105 critical vulnerabilities, 81 were remote-code-execution flaws—the most dangerous type because they let attackers run malicious code without needing access to a machine first. Another 20 critical flaws involved privilege escalation, while two caused information disclosure and one bypassed a security feature. Microsoft attributed the Windows Update Stack vulnerability to researcher Romain Deperne and its own Threat Intelligence Center, though it did not initially detail how attackers were exploiting it in the wild.
Publishers
32
Articles
17
Reach
49