Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
Security· 2 min read

Record Patch Tuesday: 966 Microsoft flaws, two zero-days exploited

On 8 September 2026, Microsoft shipped the largest batch of security fixes in its history, including two vulnerabilities already under attack. The sheer volume changes how teams must prioritise deployment.

A patch management dashboard showing a very large batch of pending Microsoft security updates, with two entries flagged as actively exploited

A record for the September edition

On Tuesday 8 September 2026, Microsoft released its monthly batch of security fixes, the recurring event known as Patch Tuesday. According to Bleeping Computer, which published the information the same day, this edition patches 966 vulnerabilities, a record for a Patch Tuesday, including two zero-day flaws that are being actively exploited.

At this stage, this information rests on a single source. We report it as it was published by that outlet on 8 September 2026, without adding to it: the list of affected products, the breakdown by severity level and the identification of the two exploited flaws are not part of what we have been able to verify.

Two zero-days that reorder your priorities

In a batch of this size, the two vulnerabilities flagged as actively exploited are not simply two lines out of 966: they are the only ones for which attacks are already under way at the moment the fix arrives. The rest of the batch closes flaws where the defender still holds, in theory, a head start on the attacker. For those two, that head start does not exist.

That is the operational distinction that matters on Monday morning: a patch released is not a patch applied, and in most estates the gap between the two is measured in days or weeks. On a flaw that is already being exploited, that gap is a window of exposure, not an administrative delay.

A workload measured in maintenance windows

For administrators, the raw number has a very concrete consequence: the triage work that comes before deployment. Every monthly cycle means identifying what actually applies to your estate, assessing possible side effects on business applications, planning reboots and sequencing the deployment waves. That work only automates in part, because it depends on what is installed and on who uses it.

An unprecedented volume mechanically lengthens that phase, at the precise moment when two flaws demand immediate treatment. The difficulty is not only applying 966 fixes: it is separating, in a short space of time, what has to go out now from what can wait for the next scheduled window. Small teams, the ones without dedicated estate management tooling, absorb that load with no margin.

What remains to be established

Several elements are still missing before the real scope of this batch can be judged: the exact nature of the two exploited flaws, the versions affected, and whether temporary mitigations exist for systems that cannot reboot straight away. That information is usually set out in the vendor’s advisories and in the analyses published over the following days.

In the meantime, the one action that depends on none of those details is to identify the two fixes covering the exploited vulnerabilities and handle them separately from the rest of the batch. The September 2026 record will be remembered for its number; it is two lines out of 966 that determine the urgency.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.