Microsoft security update • September 2026
Microsoft Releases an Unprecedented Number of Patches: What Law Firms Need to Know
Microsoft’s September 2026 Patch Tuesday approached the company’s full 2025 patch volume and included two vulnerabilities already being exploited. Law firms now face a shorter window to test and deploy security updates without disrupting critical systems.
966–974
Reported vulnerabilities, depending on counting method
2
Vulnerabilities already exploited in the wild
Days
Microsoft’s direction for staged deployment, rather than weeks
A release close to an entire year of 2025 patch volume
Microsoft’s September 2026 Patch Tuesday was unlike any previous monthly security release.
Published totals vary because security researchers use different rules for including cloud services, third-party components, and republished vulnerabilities. Major trackers reported between 966 and 974 vulnerabilities. Regardless of methodology, September set a new monthly record.
The comparison with 2025 puts that scale into perspective. Tenable counted 1,130 vulnerabilities across Microsoft’s twelve Patch Tuesday releases in 2025. September 2026 alone approached that full-year total.
Already exploited
Two vulnerabilities demand immediate attention
September’s release included two vulnerabilities that Microsoft said were already being exploited.
CVE-2026-81963
An elevation-of-privilege vulnerability in the Windows Update Stack.
CVE-2026-85880
An elevation-of-privilege vulnerability in Windows Advanced Local Procedure Call.
Both could allow an attacker with the required existing access to gain SYSTEM-level privileges on an affected Windows device. Known exploitation makes these fixes an immediate priority, while the wider release still demands risk-based sequencing.
Cornerstone.IT operational support
Test and deploy critical patches within days
Cornerstone.IT’s 24/7 Network Operations Center helps small and mid-sized law firms test and roll out critical patches quickly while keeping their networks safe and operational.
24/7 NOC
Operational support around the clock
Patch within days
Test and roll out critical updates faster
Keep the network safe and running
Reduce exposure without disrupting the firm
Patch deployment
Microsoft is pushing patching from weeks to days
Microsoft now recommends shorter quality-update deferrals and faster enforcement. Its documented Autopatch model keeps staged testing but compresses the timeline.
1. Test ring
Receive the quality update on release day and validate early deployment signals.
2. Early production
Move to a broader representative group after a short deferral.
3. Final ring
Complete broad deployment within the remaining deadline and grace period.
Important
This is not a universal three-day mandate. Microsoft still recommends staged deployment. Its current policy guidance says the complete deferral, deadline, and grace-period sequence should not exceed seven days for normal quality updates.
Faster patching still requires testing
Moving faster does not mean deploying every update to every device at once. Microsoft’s own model retains test and production rings so IT teams can review early results before expanding deployment.
The September release demonstrated why this caution matters. Microsoft issued an out-of-band update on September 14 to correct problems affecting Remote Desktop Services, host-folder sharing with some Hyper-V Linux virtual machines, and certain multichannel USB audio configurations after the September security updates were installed.
The lesson is not to delay every security update. It is to build a process that can test quickly, detect problems early, and continue deployment without relying on a weeks-long waiting period.
What this means for law firms
Law firms need to protect sensitive information while keeping the systems used by attorneys and staff available. An update that reduces security exposure but disrupts a critical application creates a different business risk.
Risk-based prioritization
Identify actively exploited vulnerabilities and the systems where exposure is greatest.
Representative testing
Use devices and applications that reflect the firm’s actual production environment.
Deployment monitoring
Track update success, failures, restarts, and emerging compatibility problems.
Exception management
Document delayed systems, owners, reasons, review dates, and compensating controls.
Supporting context
AI is changing how vulnerabilities are found
Microsoft says advanced AI models can discover weaknesses, connect lower-severity issues into working attack paths, and produce proof-of-concept code. These capabilities can help defenders identify and correct problems earlier. They can also shorten the time needed to analyze a weakness and determine how it could be exploited.
Microsoft’s own systems
Microsoft’s MDASH platform coordinates more than 100 specialized AI agents across multiple models. Microsoft reported that it helped researchers find 16 Windows networking and authentication vulnerabilities in May 2026.
Industry partnerships
Microsoft is also working with Anthropic and other partners through Project Glasswing to test Claude Mythos Preview for defensive security research.
Where Anthropic fits into the story
Microsoft’s AI security program includes internal systems and work with outside model providers. Through Project Glasswing, Microsoft has said it is testing Claude Mythos Preview to identify and mitigate vulnerabilities earlier and improve defensive coordination.
What is not confirmed
Microsoft has not publicly identified which, if any, vulnerabilities in the September 2026 Patch Tuesday release were discovered through Claude Mythos. The record release should not be attributed to Anthropic without that evidence.
The confirmed point is broader. Microsoft is investing in AI-assisted vulnerability research through its own systems and selected partnerships. That changes the speed at which software weaknesses can be identified, evaluated, and remediated.
Talk with Cornerstone.IT
Can your firm test and deploy critical patches within days?
Review how your firm prioritizes, tests, deploys, and monitors security updates while keeping the network safe and operational.
Sources
- Microsoft: AI-powered defense for an AI-accelerated threat landscape
- Microsoft: Defense at AI speed with MDASH
- Qualys: September 2026 Patch Tuesday review
- Cisco Talos: September 2026 Patch Tuesday
- Tenable: Microsoft Patch Tuesday 2025 year in review
- Microsoft Learn: Autopatch group policies
- Microsoft Learn: Update compliance policies
- Microsoft Support: September 14 out-of-band update