By:-Satnam Narang, Sr. Staff Research Engineer, Tenable
“September’s Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026. To put it into context, this month’s Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year’s total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go. This month, there were two vulnerabilities exploited in the wild as a zero-day: CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, the component used to install Windows updates, and CVE-2026-85880, an elevation of privilege in Windows Advanced Local Procedure Call (ALPC), a message passing utility in Windows operating systems. Since 2022, there have been seven privilege escalation flaws in Windows Update Stack, but this is the first zero-day and the first to be exploited. There have been 16 in ALPC patched since 2022, but this is the first to be included in Patch Tuesday in more than three years (April 2023) and the second to be exploited as a zero-day since CVE-2023-21674 (January 2023). One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low. AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”


