What happened
A security weakness in Windows is being tracked as CVE-2026-81963. CVE-2026-81963 is a newly disclosed security weakness in Windows. Microsoft's Patch Tuesday September 2026 rollout has broken previous records, with the company addressing 974 CVEs across its product lineup in a single release.
It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. 104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical.
Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. This month’s updates include patches for two zero-days that were exploited in the wild. This month’s update includes patches for:.
Attackers are already using this issue in real-world attacks, so exposed systems may need both remediation and investigation for earlier compromise.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What security teams should do now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-81963 and validate the affected path after remediation.
What is not yet confirmed
- Who was responsible has not yet been confirmed publicly.