Microsoft security update • September 2026

Microsoft Releases an Unprecedented Number of Patches: What Law Firms Need to Know

Microsoft’s September 2026 Patch Tuesday approached the company’s full 2025 patch volume and included two vulnerabilities already being exploited. Law firms now face a shorter window to test and deploy security updates without disrupting critical systems.

966–974

Reported vulnerabilities, depending on counting method

2

Vulnerabilities already exploited in the wild

Days

Microsoft’s direction for staged deployment, rather than weeks

A release close to an entire year of 2025 patch volume

Microsoft’s September 2026 Patch Tuesday was unlike any previous monthly security release.

Published totals vary because security researchers use different rules for including cloud services, third-party components, and republished vulnerabilities. Major trackers reported between 966 and 974 vulnerabilities. Regardless of methodology, September set a new monthly record.

The comparison with 2025 puts that scale into perspective. Tenable counted 1,130 vulnerabilities across Microsoft’s twelve Patch Tuesday releases in 2025. September 2026 alone approached that full-year total.

Already exploited

Two vulnerabilities demand immediate attention

September’s release included two vulnerabilities that Microsoft said were already being exploited.

CVE-2026-81963

An elevation-of-privilege vulnerability in the Windows Update Stack.

CVE-2026-85880

An elevation-of-privilege vulnerability in Windows Advanced Local Procedure Call.

Both could allow an attacker with the required existing access to gain SYSTEM-level privileges on an affected Windows device. Known exploitation makes these fixes an immediate priority, while the wider release still demands risk-based sequencing.

Cornerstone.IT operational support

Test and deploy critical patches within days

Cornerstone.IT’s 24/7 Network Operations Center helps small and mid-sized law firms test and roll out critical patches quickly while keeping their networks safe and operational.

24/7 NOC

Operational support around the clock

Patch within days

Test and roll out critical updates faster

Keep the network safe and running

Reduce exposure without disrupting the firm

Patch deployment

Microsoft is pushing patching from weeks to days

Microsoft now recommends shorter quality-update deferrals and faster enforcement. Its documented Autopatch model keeps staged testing but compresses the timeline.

1. Test ring

Receive the quality update on release day and validate early deployment signals.

2. Early production

Move to a broader representative group after a short deferral.

3. Final ring

Complete broad deployment within the remaining deadline and grace period.

Important

This is not a universal three-day mandate. Microsoft still recommends staged deployment. Its current policy guidance says the complete deferral, deadline, and grace-period sequence should not exceed seven days for normal quality updates.

Faster patching still requires testing

Moving faster does not mean deploying every update to every device at once. Microsoft’s own model retains test and production rings so IT teams can review early results before expanding deployment.

The September release demonstrated why this caution matters. Microsoft issued an out-of-band update on September 14 to correct problems affecting Remote Desktop Services, host-folder sharing with some Hyper-V Linux virtual machines, and certain multichannel USB audio configurations after the September security updates were installed.

The lesson is not to delay every security update. It is to build a process that can test quickly, detect problems early, and continue deployment without relying on a weeks-long waiting period.

What this means for law firms

Law firms need to protect sensitive information while keeping the systems used by attorneys and staff available. An update that reduces security exposure but disrupts a critical application creates a different business risk.

Risk-based prioritization

Identify actively exploited vulnerabilities and the systems where exposure is greatest.

Representative testing

Use devices and applications that reflect the firm’s actual production environment.

Deployment monitoring

Track update success, failures, restarts, and emerging compatibility problems.

Exception management

Document delayed systems, owners, reasons, review dates, and compensating controls.

Supporting context

AI is changing how vulnerabilities are found

Microsoft says advanced AI models can discover weaknesses, connect lower-severity issues into working attack paths, and produce proof-of-concept code. These capabilities can help defenders identify and correct problems earlier. They can also shorten the time needed to analyze a weakness and determine how it could be exploited.

Microsoft’s own systems

Microsoft’s MDASH platform coordinates more than 100 specialized AI agents across multiple models. Microsoft reported that it helped researchers find 16 Windows networking and authentication vulnerabilities in May 2026.

Industry partnerships

Microsoft is also working with Anthropic and other partners through Project Glasswing to test Claude Mythos Preview for defensive security research.

Where Anthropic fits into the story

Microsoft’s AI security program includes internal systems and work with outside model providers. Through Project Glasswing, Microsoft has said it is testing Claude Mythos Preview to identify and mitigate vulnerabilities earlier and improve defensive coordination.

What is not confirmed

Microsoft has not publicly identified which, if any, vulnerabilities in the September 2026 Patch Tuesday release were discovered through Claude Mythos. The record release should not be attributed to Anthropic without that evidence.

The confirmed point is broader. Microsoft is investing in AI-assisted vulnerability research through its own systems and selected partnerships. That changes the speed at which software weaknesses can be identified, evaluated, and remediated.

Talk with Cornerstone.IT

Can your firm test and deploy critical patches within days?

Review how your firm prioritizes, tests, deploys, and monitors security updates while keeping the network safe and operational.

Cornerstone.IT