September 2026 Patch Tuesday Was Microsoft's Biggest Ever: What Perth Businesses Should Check

Microsoft's September 2026 Patch Tuesday fixed a record 966 flaws, including two zero-days already under attack — one inside Windows Update itself. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

XanderXander · Web Developer & IT Technician
9 September 2026
5 min read
Cybersecurity
Patch Management
Windows
Perth Business

Microsoft's September 2026 Patch Tuesday, released on 8 September, fixed a record 966 vulnerabilities — more than double what it patched across July and August combined — including two zero-day flaws that were already being exploited before the fix existed. The part worth paying attention to isn't just the size of the update: one of those two zero-days sits inside the Windows Update mechanism itself, the exact system your computers rely on to receive this month's fix. If your business runs Windows, the practical takeaway is straightforward — check that updates are actually installing this week, don't put off the restart, and don't assume this is a month you can quietly skip.

What landed this time

This is Microsoft's largest single Patch Tuesday on record. Of the 966 fixes, 105 are rated Critical, and 81 of those are remote code execution flaws — the kind that can let an attacker run their own code on a machine, not just view or corrupt data. Most of the rest are elevation-of-privilege and information-disclosure fixes, spread across Windows, Office, and the underlying components both rely on.

Scale alone isn't the story every month, but it's worth understanding why it matters even if you'll never read a single one of those 966 advisories yourself. A bigger release means a bigger window between "patch published" and "every machine in your business actually has it installed." Attackers know this too — it's common for exploit code targeting a freshly disclosed flaw to appear within days, aimed squarely at the businesses that are slower to roll updates out. The number itself isn't something an owner or office manager needs to track; what matters is whether whoever manages your computers has a process that closes that window quickly, every month, without you having to ask.

Two details in this particular release are worth knowing regardless.

The two zero-days already under attack

Two flaws were confirmed as actively exploited in the wild before Microsoft even shipped the patch:

  • CVE-2026-81963 — an elevation-of-privilege flaw in the Windows Update Stack, the component that manages how updates are downloaded, verified and installed.
  • CVE-2026-85880 — an elevation-of-privilege flaw in Windows Advanced Local Procedure Call (ALPC), a core piece of how Windows processes talk to each other.

Neither is a wide-open front door on its own — both require an attacker to already have some low-level foothold on a machine, typically from a phishing email, a malicious attachment, or a previously compromised account. What they're good for is turning that small foothold into full administrative control. That's exactly the kind of second-stage flaw ransomware crews look for: get a user to open something, then use a bug like this to go from "one ordinary account" to "the whole machine, and often the network beyond it."

The irony worth sitting with is that one of the two lives inside Windows Update itself. It doesn't stop the patch from working, but it's a reminder that even the plumbing responsible for keeping you safe is a target in its own right — which is exactly why deferring updates on the grounds that "the update system will always be there when we're ready" isn't a safe assumption to make.

The Office fixes matter just as much

Alongside the Windows-level flaws, this release also patches critical remote code execution bugs across Excel, Word, Outlook and PowerPoint, plus the Windows Graphics Component, Windows Media Foundation and Web Media Extensions. In practice, that means a booby-trapped document or media file — the kind that arrives as an ordinary-looking email attachment — is a realistic way in for several of these, no exotic hacking required on the attacker's part.

What Perth businesses should actually do this week

  • Confirm the update has actually installed, not just downloaded. Windows can sit at "ready to restart" for weeks if nobody actually reboots the machine.
  • Don't defer the restart. A pending reboot means the fix is sitting on disk but not protecting anything yet.
  • If you have a managed IT provider, ask them to confirm rollout status across your fleet this week, not "eventually." A provider running proper managed IT services should be able to tell you exactly how many of your machines are patched, right now.
  • Treat unexpected attachments with more suspicion than usual this month, given how many of the critical fixes are in everyday Office apps.
  • Enforce multi-factor authentication and least-privilege access wherever you haven't already — it's the single best defence against a privilege-escalation bug being chained into something worse, and it's one of the core controls in the ASD Essential Eight.

What we do

Patch management shouldn't depend on someone remembering to click "restart now" on 40 different machines. Our IT security solutions push critical updates like this one out on a managed schedule, confirm they've actually installed (not just downloaded), and flag any machine that's fallen behind — so a record-breaking Patch Tuesday like this one is a non-event for our clients rather than a scramble.

If you're not sure whether your business's computers are fully patched this month, that's worth checking today rather than later. Get in touch or call (08) 9325 1196 — we've been keeping Perth businesses patched and protected since 1997.

Xander
Written by
Xander
Web Developer & IT Technician · 2+ years in IT

Xander builds fast, SEO-friendly websites and handles hands-on IT and computer-repair work — from Next.js builds and local search optimisation through to hardware fixes, OS reinstalls and helpdesk support. He covers the full stack, from the rack to the browser.

Meet the IT Support Perth team →
Xander
9 September 2026
5 min read
Cybersecurity
Patch Management
Windows
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Critical Flaw in Check Point's Small-Business Firewall: What to Patch This Week

Check Point has patched two critical, unauthenticated RCE flaws (CVSS 9.8) in its VPN gateways, including the Spark Firewall used by many small offices. Here's what Perth businesses should check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check

September's Patch Tuesday fixed a critical, unauthenticated Remote Desktop flaw — then the same update broke RDS on Windows Server, forcing hard reboots. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Passkeys Are Now Default in Microsoft 365: What Perth Businesses Must Check

Microsoft has switched Entra ID to passkeys by default and is retiring SMS and voice sign-in codes by February 2027. Here's what Perth businesses need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check
Cybersecurity
Patch Management

September Patch Broke Remote Desktop on Windows Server: What Perth Businesses Must Check

September's Patch Tuesday fixed a critical, unauthenticated Remote Desktop flaw — then the same update broke RDS on Windows Server, forcing hard reboots. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/18/2026
Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do
Cybersecurity
Patch Management

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do

Microsoft's August 2026 security update patched a Windows flaw that was already being exploited to seize full control of machines, plus a critical SharePoint hole. Here's what Perth businesses need to check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/12/2026
Two Chrome Zero-Days in a Week, Plus a Firewall Alert: What to Check Now
Cybersecurity
Browser Security

Two Chrome Zero-Days in a Week, Plus a Firewall Alert: What to Check Now

Google patched two actively exploited Chrome zero-days within a week, while CISA flagged actively exploited flaws in Cisco, Citrix and Fortinet security gear. Here's what Perth businesses should check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/14/2026
Call us