Microsoft’s September 2026 Patch Tuesday has shattered all previous records, with
security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities
. For UK SMEs already stretched thin managing routine security updates, this unprecedented volume represents a fundamental challenge to traditional patch management approaches.
The scale of this release isn’t just large—it’s historic.
This release represents a 70% increase over the previous single-month record of 569 Microsoft-only CVEs, previously set in July 2026
. Even more remarkably,
Microsoft has patched 2,760 security flaws year-to-date in 2026, already exceeding 2020’s previous annual record of 1,245 vulnerabilities with three months still remaining in the year
.
Understanding the September 2026 Patch Tuesday Record Scale
The September 8th release affects virtually every Microsoft product UK SMEs depend upon daily.
The release spans Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure, and developer tools, requiring organizations to coordinate remediation across endpoints, servers, and enterprise application environments
.
Breaking down the vulnerability distribution:
- 723 vulnerabilities affect Windows, 111 affect Office, 62 affect SQL Server, 22 affect developer tools, 16 affect SharePoint Server, and nine affect Exchange Server
- 105 vulnerabilities are rated “Critical,” with 81 being remote code execution flaws, 20 elevation of privilege vulnerabilities, two information disclosure issues, and one security feature bypass
- Elevation of Privilege vulnerabilities dominated Microsoft’s September 2026 Patch Tuesday release, accounting for nearly half of all listed issues, followed by Remote Code Execution flaws
Particularly concerning are the high-impact vulnerabilities:
over 110 flaws assigned Critical severity include high-impact remote code execution vulnerabilities affecting Windows DNS Server, Remote Desktop Services, DHCP Server, Windows Shell, Exchange Server, SharePoint, and SQL Server
.
The Two Actively Exploited Zero-Day Vulnerabilities Kent SMEs Must Patch Immediately
This month’s Patch Tuesday fixes two actively exploited zero-day vulnerabilities
that demand immediate attention:
CVE-2026-81963: Windows Update Stack Elevation of Privilege
Microsoft has patched an actively exploited elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges
.
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges, and CISA added CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026
.
CVE-2026-85880: Windows Codecs Library Buffer Overflow
CISA added CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026. The heap-based buffer overflow flaw in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code locally
.
Both zero-day vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, and Federal Civilian Executive Branch (FCEB) agencies are required to apply fixes by 22 Sep 2026. At this time there has been no public disclosure of proof of concept (PoC) exploit code for CVE-2026-85880 or CVE-2026-81963; however, both are confirmed as actively exploited in the wild
.
Why the Unprecedented Scale Creates Operational Strain for UK SMEs
The sheer volume of this release fundamentally changes patch management from a routine monthly task to a complex operational challenge.
The unprecedented scale of the September 2026 update will create significant operational strain and increase the risk of delayed or incomplete remediation
.
For Kent SMEs with limited IT resources, this presents several practical problems:
- Testing burden: With 966 fixes affecting multiple product families, comprehensive pre-deployment testing becomes extraordinarily time-consuming
- Deployment coordination: Updates spanning Windows, Office, Exchange, SQL Server, and SharePoint require careful sequencing to avoid service disruptions
- Bandwidth constraints: Simultaneously deploying updates to multiple systems can saturate network connections, particularly for businesses with limited internet bandwidth
- Reboot requirements: Many critical updates require system restarts, necessitating careful scheduling to minimise business disruption
- Compatibility risks: As demonstrated by recent issues like the Windows Server 2025 KB5122871 update that broke Remote Desktop Services, large update volumes increase the statistical likelihood of encountering breaking changes
What Kent SMEs Must Do About Record Patch Tuesday Volumes
Given the scale and complexity, Kent businesses need a structured, prioritised approach rather than attempting to deploy everything simultaneously.
1. Prioritise the Actively Exploited Zero-Days First
Prioritize patching the actively exploited zero-days first. Apply the Sept 8, 2026 Microsoft security updates for all affected Windows systems as a top priority. Use the Microsoft Security Update Guide to identify the correct KBs for CVE-2026-85880 and CVE-2026-81963
.
These two vulnerabilities are confirmed as exploited in the wild and should be deployed this week, ahead of the broader rollout.
2. Use Staged Deployment for the Broader Update Set
Use representative test and pilot groups, then expand deployment while monitoring application health. Microsoft Intune update rings support staged rollouts, installation deadlines, and restart settings
.
For businesses without Intune, establish manual pilot groups:
- Deploy to a small test group (5-10 systems representing different roles) first
- Monitor for 24-48 hours for application compatibility issues
- Expand to departmental rollouts
- Complete full deployment within the three-day window Microsoft now recommends, as discussed in our article on why UK SMEs can no longer delay patching in 2026
3. Prioritise Systems Running High-Risk Services
Organizations running SQL Server, DHCP Server, or biometric authentication at scale should also fast-track testing and deployment for those product lines given the sheer concentration of fixes affecting them this month
.
Prioritise updates for:
- Internet-facing systems (web servers, VPN gateways, email servers)
- Domain controllers and DHCP servers
- SQL Server instances, particularly those accessible from application servers
- Exchange Server environments (see our guidance on Exchange Server Extended Security Updates if you’re running 2016 or 2019)
- SharePoint servers with external user access
4. Monitor and Confirm Deployment Success
Confirm successful installation and required restarts, and investigate failed or offline devices
.
Don’t assume deployment succeeded. Actively verify:
- Update installation status through Windows Update or management tools
- Systems that failed to install updates or went offline during deployment windows
- Application functionality post-patching, particularly line-of-business software
- Any error messages or event log entries indicating problems
The Broader Context: AI-Driven Vulnerability Discovery Drives Record Patch Volumes
This record-breaking Patch Tuesday isn’t an isolated incident.
This massive patch follows the recent Microsoft update on artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase
.
As we’ve discussed in our analysis of AI-powered vulnerability discovery driving record patch volumes in 2026, this trend will continue. UK SMEs need patch management processes capable of handling consistently higher update volumes, not treating September 2026 as a one-off anomaly.
When Patch Management Becomes Overwhelming: Knowing When to Seek Help
If your internal team is struggling to test, deploy, and verify 966 security fixes across your Windows estate whilst maintaining normal operations, you’re not alone. The operational strain created by this unprecedented release is precisely why many Kent SMEs work with managed IT service providers who can:
- Maintain dedicated patch testing environments that identify compatibility issues before they affect your production systems
- Deploy updates in carefully staged rollouts with proper monitoring and rollback capabilities
- Maintain update deployment tracking and reporting for compliance requirements, particularly important given the technical controls UK insurers now demand from SMEs in 2026
- Respond quickly when updates cause unexpected issues, minimising business disruption
- Manage the increasing complexity of coordinating updates across Windows, Office, Exchange, SQL Server, and other Microsoft products
The September 2026 Patch Tuesday represents a watershed moment in Windows patch management—the volume and complexity now exceed what many small internal IT teams can effectively manage alongside their other responsibilities.
If you’re concerned about managing this unprecedented update volume or want to discuss how to strengthen your patch management processes for the consistently high volumes we’re seeing in 2026, Meridian Micro can help. We work with SMEs throughout Kent and the South East to maintain robust, efficient patch management that protects your business without overwhelming your team. Call us on 01303 883111 to discuss your specific requirements.
