Just Shy of 1,000: The Record Raised Again and Proof Becomes a Priority.
by Brad Hibbert, COO & CSO//26 min read/

September 2026 Patch Tuesday arrived today with 966 CVEs, a new all-time record that nearly lapped July’s and stopped just short of one thousand. Two zero-days are under active exploitation, and neither is rated Critical: both are Important-rated elevation of privilege flaws, one in the Windows update machinery itself and one an ALPC sandbox escape that fits a component attackers have quietly favored for years. The year-to-date count now stands at roughly 2,674, past the full-year projection that sounded aggressive in July. The pattern this series has tracked since April held again: record discovery, flat exploitation, and the two flaws that matter carrying scores that a severity filter would bury on page nine. We updated our monthly analysis with verified September data, and this edition also covers what Brinqa’s acquisition of PlexTrac means for programs facing exactly this math.
This is the sixth edition of the Brinqa Research Team monthly vulnerability landscape analysis. For new readers, the background: on April 7, Anthropic announced Project Glasswing and Claude Mythos Preview, a model capable of autonomously finding and chaining zero-day vulnerabilities at a scale that previously required elite human researchers. Vendors responded by industrializing AI discovery themselves. Microsoft confirmed its MDASH pipeline in July, Oracle shipped the largest quarterly update in its history, and Adobe split into a twice-monthly cadence. The releases followed: April tied the old record, June broke it, July tripled it, August delivered the second-largest month ever and had the industry calling it quiet, and September just posted 966.
Last month we made two predictions. We said the volume was the new normal rather than a spike, and September confirmed it emphatically. We also said to keep room for the overdue Glasswing disclosure wave, and for the third straight month the promised report did not appear, while the record fell anyway on the strength of vendor pipelines alone. The more important development for defenders happened between the releases, and it is one this series has been building toward all year: if the only signal that separates 966 findings from the two that matter is validated exploitability, then validation is no longer a nice-to-have on the side of an exposure management program. It is the center of one. That is the reasoning behind Brinqa’s acquisition of PlexTrac, announced August 19, and we cover it below in the context of this month’s data.
Here is the verified monthly data and what it means for your exposure management program.
The Numbers: Nine Hundred Sixty-Six
Each month we pull vendor advisory data and cross-reference it against independent analysis from BleepingComputer, Tenable, Qualys, SecurityWeek, Action1, and the Zero Day Initiative. The methodology spread continues. BleepingComputer counts 966 CVEs released on the day, with 105 rated Critical, of which 81 are remote code execution, 20 elevation of privilege, 2 information disclosure, and 1 security feature bypass. That count excludes 204 flaws Microsoft fixed earlier in the month across cloud and browser products, including Azure AI Language, Copilot Studio, Entra ID, Microsoft Fabric, and Edge. SecurityWeek and ZDI count 974. Action1 counts 995 with 121 critical, and other trackers reach 996. Wherever you land inside that spread, this is the largest security release any vendor has ever shipped, and the third time in four months that sentence has appeared in this series.
SecurityWeek’s analysis flags 20 of this month’s flaws as potentially wormable, and Microsoft itself rates 58 vulnerabilities as more likely to be exploited, which is the working triage tier inside the mountain. Elevation of privilege and remote code execution again dominate the release by category.
The trendline through nine months of 2026, now shown against exploitation:

Core counts follow BleepingComputer’s day-of-release methodology for month-over-month consistency. September counts from SecurityWeek and ZDI (974), Action1 (995), and other trackers (996) reflect differing inclusion rules. Exploited zero-day counts reflect flaws confirmed under active attack at release.
September runs 11.5 times the Q1 monthly baseline of 84. The year-to-date total of roughly 2,674 core CVEs passed Microsoft’s previous full-year record of 1,245 back in July and has now passed the two thousand mark that Tenable’s Satnam Narang projected for the entire year, with a quarter of the calendar remaining. His outer projection of three thousand, which read as a provocation in July, now looks like the base case.
966 CVEs patched in September. Only two are under active exploitation. Neither is rated Critical.
Finding the Fires
The most useful column in this month’s table is not the core count. It is the one next to it. Across the six releases since the Glasswing announcement, monthly volume ran 167, 120, 200, 570, 400, and now 966, while actively exploited zero-days in those same releases ran two, zero, one, two, one, and two. Discovery has grown more than elevenfold against the Q1 baseline. Exploitation has not budged. VulnCheck’s first-half report found the same thing from independent telemetry, with roughly 200 CVEs reaching the KEV catalog within 31 days of publication, steady against prior periods, and nothing in September’s release changes that picture.

Core CVE counts follow BleepingComputer’s day-of-release methodology. Exploited zero-day counts reflect flaws confirmed under active attack in each release.
The standing caution from last month still applies. The capability to weaponize these flaws exists even where the usage does not, as Anthropic’s own red team demonstrated by building working exploits for 13 of 14 flaws Microsoft had rated unlikely to be exploited. The flat trend reflects attacker adoption lag, not attacker inability. But six months of consistent data now support a planning conclusion the work of a modern program is not processing 966 findings. It is proving, quickly and continuously, which two of them are fires in your environment, and demonstrating that the fixes for those two actually held.
Two Exploited Zero-Days, and Neither Is Rated Critical
Both of this month’s exploited flaws are elevation of privilege vulnerabilities rated Important, both were exploited privately before anyone knew they existed, and both would be missed entirely by an emergency process that keys on Critical severity. One analysis of the release put the lesson plainly: limiting emergency deployment to Critical-rated vulnerabilities would overlook both confirmed zero-days.
- CVE-2026-85880: A heap buffer overflow in Windows Advanced Local Procedure Call, the inter-process communication layer deep inside Windows. Microsoft’s advisory explains that an attacker running code in a low-privilege AppContainer can use it to “escape the sandbox and elevate privileges on the affected system” with no user interaction. Tenable’s Satnam Narang notes the history that makes this one stand out: Microsoft has not patched an ALPC flaw since April 2023, and this is only the second ALPC zero-day in nearly four years, a component with a long pedigree in sophisticated post-compromise tradecraft. Sandbox escapes are chain links by definition. This flaw exists to be paired with a browser or document exploit, which is exactly how it was likely used.
- CVE-2026-81963: A link-following flaw in the Windows Update Stack, the machinery that installs Windows updates, allowing a local attacker to reach SYSTEM privileges. Credit goes to researcher Romain Deperne and the Microsoft Threat Intelligence Center, and an MSTIC credit means the same thing it has meant all year in this series: the flaw was found inside real attacks. Narang points out it is the first of seven Update Stack flaws patched over five years to be flagged as a zero-day.
Neither flaw was publicly disclosed before today. The pattern is now six months deep and unbroken: the flaws that get exploited are almost never the flaws with the frightening scores. They are mid-severity elevation of privilege bugs on universal components, discovered by incident responders, and their value to an attacker lies in what they chain with, not what they score in isolation.
Notable Vulnerabilities Beyond the Zero-Days
- The server-side set. ZDI’s Dustin Childs singles out five flaws deserving special attention: a remote code execution flaw in Exchange Server (CVE-2026-55007), a SharePoint remote code execution flaw (CVE-2026-69465), an elevation of privilege flaw in SQL Server (CVE-2026-65669), a Remote Desktop Services remote code execution flaw (CVE-2026-69525), and an elevation of privilege flaw in Microsoft Authenticator (CVE-2026-80097). Exchange, SharePoint, and remote access have hosted most of this year’s real exploitation, so this set is your second ring after the zero-days, and SharePoint’s presence should need no argument after the August chain.
- The document attack surface. Critical remote code execution fixes land in Excel (CVE-2026-81959, CVE-2026-81953) and Word (CVE-2026-81952), alongside a PowerPoint use-after-free (CVE-2026-69678) that can trigger from the preview pane, meaning a crafted file can execute code without ever being consciously opened. Document flaws are the front half of exactly the kind of chain the ALPC sandbox escape completes, which is why the two belong in the same mental model and the same deployment wave.
- The Important-rated RCEs on core plumbing. Print Spooler (CVE-2026-85877), Message Queuing (CVE-2026-83997), and Remote Desktop Client (CVE-2026-83998) all take remote code execution fixes rated Important. The rating understates the audience: these services are everywhere, and the 20 potentially wormable flaws in this release cluster on exactly this kind of ubiquitous network-reachable surface.
- Legacy lifecycle. Microsoft shipped fresh Servicing Stack Updates for Windows Server 2012, 2012 R2, and Windows 10 version 1607 and Server 2016, a reminder that extended-support estates still carry this volume too, on infrastructure least equipped to absorb it.
What the Security Industry Is Saying
Computer Weekly (September 8, 2026): Computer Weekly’s coverage captured the operational mood, writing that Microsoft has once again smashed its record and that human security teams’ capacity to keep up with AI-assisted discovery is falling away, “leaving organisations around the world painfully exposed.” That is a mainstream technology publication describing the baseline state of enterprise patching, not a worst case.
Tenable, Satnam Narang, Senior Staff Research Engineer (September 8, 2026): Narang’s analysis focused on the component history behind both zero-days: the first ALPC fix since April 2023 and only the second ALPC zero-day in nearly four years, and the first Update Stack flaw ever flagged as a zero-day among seven patched in that component over five years. Attackers returning to old, quiet components while defenders drown in new volume is its own kind of signal.
Zero Day Initiative, Dustin Childs (September 8, 2026): Childs’ review, which counts 974, walks the same beats his August review did at 421, because the new normal he named last month needed exactly one month to double. His short list of flaws deserving special attention, led by the Exchange and SharePoint remote code execution bugs, looks strikingly conventional: at nearly a thousand CVEs, the flaws that matter still live where they always have.
Action1 (September 8, 2026): Action1, counting 995, wrote that at this scale the challenge is not getting through the patch list but knowing what needs attention first, and structured its entire analysis around separating immediate action from normal cadence. The patch management industry has spent 2026 converging on the position this series started with.
The commentary has stopped debating whether the volume is real or AI-driven and moved entirely to what to do about it. The answer emerging across vendors, analysts, and this series is the same: prioritize by validated exploitability and environmental context, automate everything that does not need human judgment, and prove the small set of fixes that matter actually worked.
The Last Four Weeks
The window between August 11 and today was quieter on the vendor calendar than the July window, and the biggest verified developments were structural. Rapid7’s thirty-day embargo on the SharePoint chain expired in mid August as scheduled, putting the complete technical write-up of the year’s most instructive attack chain into the public record, and turning any unpatched on-premises SharePoint farm into a target with documentation. Adobe continued its twice-monthly cadence, and its next fourth-Tuesday installment lands September 22.
Anthropic has said it plans to release Mythos-class models to all customers once additional safeguards are in place, and has acknowledged that comparable models will likely exist from multiple vendors within six to twelve months. OpenAI has shipped a cyber-focused model aimed at similar vulnerability discovery work, and independent analysis notes a Chinese lab’s model approaching similar detection capability at lower cost. The discovery engine that produced this year’s elevated results is stopping being a single company’s restricted asset and becoming general infrastructure.
Oh, and on August 19, Brinqa acquired PlexTrac. We cover what that means for customers in its own section below.
The Glasswing Watch
Anthropic’s promised 90-day public summary report has now missed its original early July window, the close of the expanded disclosure period at Black Hat in early August, and the month that followed. We will keep the entry short this month because the operational conclusion has stopped depending on it. September’s 966 arrived with no help from a coordinated Glasswing wave, entirely from vendor pipelines that now run AI discovery natively. Whenever the held-back findings do land, and the program’s own disclosure policy of 90 days after discovery or 45 days after a patch ships guarantees they keep coming, they land on top of a monthly baseline that just brushed one thousand.
The Instinct to Add More Scanners Is Still Wrong
Your scanners tell you what vulnerabilities exist. This month, that answer is 966. What you actually need to know is much narrower: which of these can hurt your business right now? This month, only two are being actively exploited, and both are rated Important, not Critical. If your emergency process only kicks in for Critical flaws, you would have rushed out 105 patches and left both real threats sitting in the monthly queue. Severity ratings also undersell other flaws that need fast attention: the 58 that Microsoft says attackers are likely to exploit soon, the 20 that could spread on their own, and the server flaws ZDI called out. Deciding what to fix first comes down to four questions:
- Is it being attacked?
- Can attackers reach it?
- Is it part of a known attack chain?
- Does it sit on something the business depends on?
If your emergency process only kicks in for Critical flaws, you'd have rushed out 105 patches and left both real threats sitting in the monthly queue.
Closing the Loop: What PlexTrac Means for This Math
On August 19, Brinqa acquired PlexTrac, the platform offensive security teams use to validate exposures, run penetration testing and red team workflows, and report what they proved. The acquisition makes Brinqa the largest standalone vendor in Unified Exposure Management, serving more than 3,000 customers across 57 countries, including over a quarter of the Fortune 500, and it brings together two companies independently recognized in the Gartner Magic Quadrant for Exposure Assessment Platforms. PlexTrac founder Dan DeCloss joins Brinqa’s executive team and board to lead the combined offensive security practice, and PlexTrac’s products continue as standalone offerings for existing customers.
Here is why we are covering an acquisition in a Patch Tuesday analysis. Every edition of this series has ended on the same conclusion from a different direction: at AI-era volume, the scarce and decisive signal is validated exploitability. September made the case in its purest form yet, with 966 findings, two confirmed fires, and both fires invisible to a severity filter. Brinqa’s platform has always answered the first half of the resulting problem, consolidating findings from 260+ tools into the Cyber Risk Graph™ and prioritizing them by exploitation activity, reachability, business criticality, and compensating controls. PlexTrac answers the second half. Offensive security teams prove which exposures are actually exploitable in your environment and through scheduled retesting can prove whether the fix held once implemented. As Brinqa CEO Dan Pagel put it, PlexTrac brings depth from “practitioners who have spent years proving exactly how attackers get in.”
Every confirmed exploit and every validated fix from PlexTrac can now flow into Brinqa’s data layer, strengthening the graph and sharpening every AI agent that runs on it, whether Brinqa’s own agents or models customers bring through the Bring Your Own AI program. In practical terms, the loop closes. Discovery and consolidation tell you what exists. Context and exploitation intelligence tell you what matters. Automated routing drives the fix. And validated retesting proves the fix worked, which is the difference between a ticket marked closed and evidence you can put in front of a board, an auditor, or an insurer.
Thomas Krane of Insight Partners summarized the reasoning in one sentence: “Exposure management only matters if teams can prove the fix worked.” In a month where the entire industry’s challenge was separating 966 findings from two fires and confirming those two were extinguished, that is not a vendor talking point. It is the job description.
Five Recommendations Before the October Window
1. Patch both zero-days first, and do not let severity ratings route them.
CVE-2026-85880 and CVE-2026-81963 are being exploited now, both reach SYSTEM privileges, and both are rated Important, so make sure your emergency process keys on exploitation status rather than severity. Because both are post-compromise flaws, pair the patching with a hunt: review endpoints for signs of privilege escalation activity, since exploitation of these bugs means an attacker was already inside.
2. Treat the server set as your second ring.
The Exchange, SharePoint, SQL Server, and Remote Desktop Services flaws that ZDI flagged sit on the same infrastructure where this year’s real exploitation has concentrated. Deploy them on an accelerated schedule, and verify your SharePoint farms also carry the July and August fixes, since the full technical details of that attack chain have been public since mid August.
3. Deploy the Office fixes with the zero-days in mind.
The Excel, Word, and PowerPoint remote code execution flaws are the front half of a chain that a sandbox escape like the ALPC zero-day completes. The PowerPoint flaw can trigger from the preview pane, with no conscious opening of the file. Patch the document surface and the escalation surface in the same wave, because attackers use them in the same attack.
4. Make validation a standing step, not an annual event.
At 966 findings a month, the questions that matter are which exposures are actually exploitable in your environment and whether the fixes for those actually held. Annual penetration tests answer that once a year against a snapshot that is eleven releases stale by the next test. Build continuous validation into the program: confirm exploitability before you burn emergency capacity, retest after remediation, and track the measure we have recommended since May, the time from a confirmed exploitable exposure appearing to its validated closure. Validated closure means retested, not ticket-closed.
5. Plan October around the calendar you can see.
Windows 11 version 24H2 reaches end of servicing on October 13, putting migration work on the same teams absorbing record volume, and Oracle’s quarterly update lands the same month, following a July edition that was the largest in its history. Adobe’s next installment arrives September 22. The Glasswing report remains outstanding, and Mythos-class discovery models are headed toward general availability across multiple vendors. Nothing on that calendar suggests a lighter quarter. Build the capacity plan for a thousand-CVE month, because September came within 34 of it.
April tied the record. May confirmed the floor. June broke the record outright. July tripled it and made the cause official. August proved 400 could feel quiet. September posted 966, passed the full-year projection with a quarter to spare, and delivered its two real threats in packaging that a severity filter would have ignored. The lesson of six editions has converged into one sentence: find everything, but prove what matters, fix that first, and confirm the fix held. That discipline is what separates the programs that will operate calmly at one thousand CVEs a month from the programs that will drown at half that. It is also, as of August 19, exactly the loop the combined Brinqa and PlexTrac platform closes.
We will publish the October edition on the next Patch Tuesday.
If you’re working through what AI-driven CVE volume means for your program, or what validated exposure management looks like in practice, speak with a Brinqa Expert about where it stands today.
FAQs
It is the largest security release ever shipped, at 966 CVEs, yet only two flaws are confirmed under attack and both are rated Important rather than Critical. The month confirms that programs must prioritize by exploitation evidence and environmental context, automate the bulk of the volume, and validate that the fixes for the flaws that matter actually held.
Vulnerability prioritization this month starts with the two actively exploited zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack, both of which reach SYSTEM privileges. Follow with the Exchange, SharePoint, SQL Server, and Remote Desktop Services flaws that ZDI flagged, then the Excel, Word, and PowerPoint remote code execution fixes, which pair naturally with sandbox escape flaws in real attack chains.
Because exploitation is evidence and severity is an estimate. Both zero-days were used in real attacks before patches existed, while none of the Critical flaws has confirmed exploitation. An emergency process that triggers only on Critical severity would have missed both of the month’s genuine threats entirely.
Not proportionally. Monthly volume has grown more than elevenfold against the first quarter baseline while actively exploited zero-days per release have stayed between zero and two all year. Independent tracking from VulnCheck shows early exploitation holding steady. The capability to weaponize flaws exists, so the gap reflects attacker adoption lag, but the practical challenge today is separating a small number of real fires from a very large number of findings.
Still unpublished, now three months past its original early July window. September’s record volume came entirely from vendor discovery pipelines, and the held-back Glasswing findings remain queued behind coordinated disclosure clocks, which is why capacity planning should assume heavy months continue.
Brinqa acquired PlexTrac on August 19 to add offensive security validation to its exposure management platform, closing the loop from discovery and prioritization through remediation to validated proof that a fix held. The combined company is the largest standalone vendor in Unified Exposure Management with more than 3,000 customers across 57 countries, PlexTrac products continue as standalone offerings, and validated exploit and fix data now strengthens Brinqa’s Cyber Risk Graph and AI agents.
Brinqa consolidates findings from more than 260 security tools into unified exposure records, prioritizes them by exploitation activity, reachability, business criticality, and compensating controls, routes them automatically to owners with deadlines and escalation, and, with PlexTrac, validates both exploitability and remediation. The result is a short, defensible priority list and evidence that the fixes held.
SOURCES AND REFERENCES (UPDATED SEPTEMBER 8, 2026)
Good — here's the finalized list with #15 corrected, formatted to match the Sources section style in the doc:
- BleepingComputer, Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days, September 8, 2026. bleepingcomputer.com
- SecurityWeek, Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days, September 8, 2026. securityweek.com
- Action1, Patch Tuesday September 2026, September 8, 2026. action1.com
- Computer Weekly, Patch Tuesday: Microsoft Updates Address Almost 1,000 Flaws, September 8, 2026. computerweekly.com
- Security Online, September 2026 Patch Tuesday Fixes 2 Exploited Windows Zero-Days, September 8, 2026. securityonline.info
- Cybersecurity News, Microsoft Patch Tuesday Update September 2026, September 8, 2026. cybersecuritynews.com
- Zero Day Initiative, The September 2026 Security Update Review, Dustin Childs, September 8, 2026. zerodayinitiative.com
- Brinqa, Brinqa Acquires PlexTrac to Close CTEM Loop, August 19, 2026. brinqa.com/news-room
- Help Net Security, Brinqa Acquires PlexTrac to Bring Validated Remediation to Exposure Management, August 19, 2026. helpnetsecurity.com
- Rapid7, CVE-2026-55040 disclosure series. Initial advisory (July 14): rapid7.com; technical breakdown (August 11): rapid7.com
- VulnCheck, State of Exploitation 1H-2026, August 2026. vulncheck.com
- KrebsOnSecurity, July 14, 2026. krebsonsecurity.com; CyberScoop, July 14, 2026. cyberscoop.com
- Help Net Security, Anthropic Expands Project Glasswing, June 3, 2026. helpnetsecurity.com
- Anthropic, Project Glasswing: An Initial Update, May 22, 2026. anthropic.com/research
- Secure in Seconds, Project Glasswing Find-Fix Gap Analysis, July 2026. secureinseconds.comHelp Net Security, August 2026 Patch Tuesday Forecast, Todd Schell (Ivanti), August 7, 2026. helpnetsecurity.com


