Microsoft shipped 970 fixes this month, 113 of them rated Critical. A further 216 entries in the same document are third-party CVEs Microsoft republishes or Edge/Chromium updates, carrying 6 Critical — counted separately here, because that total tracks Microsoft's role as a CNA rather than the size of Patch Tuesday. 3 are already under active attack and should be patched today; 0 publicly disclosed zero-days should be closed this week. Everything else fits the normal monthly cycle.
As of 2026-09-09 15:42 UTC, this cycle’s MSRC document lists 1,186 CVEs
— 970 Microsoft-authored, plus 24 Edge/Chromium and
192 Linux/other entries that are republished third-party fixes patching through
their own vendors. That figure is a reading at a timestamp, not a fixed total for the month:
Microsoft revises this document in place, and it is currently at
revision 222 (last revised 2026-09-09 15:09 UTC).
The two Critical lines above are kept separate for the same reason — the third-party total
moves with Microsoft’s CNA scope, not with the size of Patch Tuesday.
Patch today
Confirmed in CISA KEV and flagged as exploited by Microsoft. Treat as active
incidents, not routine patching.
CVE-2026-81963ExploitedCVSS 7.8Windows Update Stack Elevation of Privilege
in CISA KEV (added 2026-09-08); MSRC Exploited; ⬆ HCL: flagged dangerous. Owner routes to the Other / general Windows team.
Owner: Other / general Windows
CVE-2026-85880ExploitedCVSS 7.8Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege
in CISA KEV (added 2026-09-08); MSRC Exploited. Owner routes to the Other / general Windows team.
Owner: Other / general Windows
CVE-2026-85046ExploitedCVSS —Chromium: CVE-2026-85046 Type confusion in V8
in CISA KEV (added 2026-09-04). Owner routes to the Browser (Edge auto-update) team.
Owner: Browser (Edge auto-update)
Close this week
Publicly disclosed but not yet observed in the wild — a zero-day on a
countdown. Schedule ahead of the normal cycle.
None this month.
Who owns what
This month's priority items grouped by the team that patches them.
Ordered by a composite priority that weights active exploitation and disclosure
above raw CVSS. Showing the sharp end; the full ranked set of 1,186 CVEs is in the index.
↑ Corroborated — HCL BigFix field analysts independently flagged this item in their published briefing.
Sources & method
Authoritative counts and exploitation flags come from Microsoft's MSRC Security Update Guide
and CISA's Known Exploited Vulnerabilities catalog. Independent reporting and analyst
commentary corroborate and add context but do not set priority.
Ranking is a composite score that weights active exploitation and public disclosure above raw
CVSS, adjusted for network-reachable / no-authentication attack profiles and field-analyst
judgment — which is why a low-CVSS vulnerability under active attack can outrank an
unexploited 9.8.