966 Fixes in One Tuesday. Two of Them Are the Point.

If we manage your systems, this went out this week. If we don't, the check above is the whole job.

On Tuesday, September 8, Microsoft published the largest batch of security fixes in its history. It was 966 or 972, depending who's counting — the tallies differ over whether browser items belong. Either way it more than doubles July, itself a record. We manage Windows machines for a living, so a month like this is our workload, not somebody else's. A number that size invites the wrong reaction. It isn't evidence Windows fell apart in August. Here is what actually changed. In July, Microsoft's Windows chief said it plainly: "As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release." Microsoft now runs automated systems that hunt through its own code, filter out the false alarms, and hand what survives to engineers. They found a lot. The count went up because the searching got better — not because the software got worse. Which makes the headline number close to meaningless for you. Two of the fixes aren't. The technical part — you can skip this box Microsoft's September 8, 2026 security release: 966 fixes including 105 rated Critical by BleepingComputer's count; 972 Microsoft CVEs plus 25 third-party and Chromium items, 114 Critical, by the Zero Day Initiative's. Two are listed by CISA, the Cybersecurity and Infrastructure Security Agency, as under active exploitation. Both were added to that list on September 8 with a federal remediation deadline of September 22. CVE-2026-81963, a Windows Update Stack elevation-of-privilege flaw scored CVSS 7.8, affects Windows 11 versions 23H2, 24H2, 25H2 and 26H1, and Windows Server 2025. CVE-2026-85880, a heap-based buffer overflow in Windows ALPC (Advanced Local Procedure Call) also scored 7.8, affects Windows 10 versions 1607, 1809, 21H2 and 22H2, and Windows Server 2012, 2012 R2, 2016, 2019 and 2022. Both require an attacker who already has an authorized account on the machine; neither can be triggered remotely on its own. What that actually means "Elevation of privilege" is the dullest-sounding category on the list and one of the most useful to an attacker. Neither gets anybody in the door. They turn a small foothold — one stolen password, one bad attachment — into control of the whole machine. Step two, where a nuisance becomes a bad week. A CVE number is a catalog number, like a case number, so everyone is talking about the same flaw. What matters is that the US government keeps a second, much shorter list: flaws criminals are already using. Both went onto it the day they were published, and federal agencies have until September 22 to fix them. That list is the filter. Nine hundred and sixty-six is noise. Two is a work order. "7.8" is the severity score both carry, out of 10 — high, not maximum. It matters less than the fact that both are already being used. And look at which machines. One hits current Windows 11 and Windows Server 2025. The other hits Windows 10 and Windows Server going back to 2012 — the box in the closet running the one application nobody wants to touch. Old equipment isn't sitting this one out. It's the target. What to do, and it takes about ten minutes Open Settings, go to Windows Update, then Update history, and check that something dated September 8 or later is listed. Then restart the machine. An update that has downloaded but not rebooted is not installed. The wording moves around between Windows versions — on some it's Settings, then Update & Security, then Windows Update, and the link reads "View update history." If the names don't match, look for whichever screen lists updates by date. Same list. Then find the machines nobody logs into. They never report a problem, because nobody is looking at them. If we manage your systems, this went out this week. If we don't, the check above is the whole job.