I opened three different write-ups on this month’s Patch Tuesday before I even started this post, and I got three different totals for how many vulnerabilities Microsoft fixed.[1][2][5] SecurityWeek says 974.[1] Zero Day Initiative counts 972 new CVEs, 997 once you add the external and Chromium bugs already tracked elsewhere.[5] SecurityOnline says 996, with 119 rated Critical.[2] Nobody’s lying here. ZDI itself says the gap comes from whether external and Chromium-based Edge bugs get folded into the same total as the new Microsoft-only CVEs.[5] If your board asks “how many did we patch this month” and you hand them a number, know which of these three you’re quoting and why it differs from the other two.

The two that were already being used

Buried under the record-setting total, two bugs actually matter more than the count: both are elevation-of-privilege flaws already being exploited in the wild before the patch shipped, and both carry a CVSS of 7.8.[1][2]

  • CVE-2026-85880 — a heap overflow in the Windows ALPC subsystem. ALPC is the internal messaging layer Windows processes use to talk to each other, and this is only the second zero-day found in it since 2023.[1] An attacker who can already run low-privilege code — say, from inside a sandboxed AppContainer — can use it to escape and land at SYSTEM, no user interaction required.[1]
  • CVE-2026-81963 — a link-following flaw in the Windows Update Stack. Same outcome, different door: local privilege escalation to SYSTEM, and the first time this particular component has ever had a zero-day tracked against it in five years of ZDI’s records.[1][2]

Neither one gets you in the door by itself.[1] Both are the second stage after something else already got an attacker onto the box — which is exactly the profile you’d expect an AI-assisted vulnerability hunt to surface at scale: not the front door, but every hinge on every internal door once you start really looking.[1][5] ZDI also flagged 20 separate bugs in this release that qualify as wormable — remote code execution, no auth, no click required — which is its own five-alarm number that got a little lost under “record month” as a headline.[5] Microsoft has not published exploit details or victim counts for either zero-day, which is standard practice to slow copycat attacks but also means nobody outside Microsoft knows how widely either is already being used.[2]

Then Defender’s patch got bypassed the same day

Here’s the part that actually made me sit up. Microsoft shipped a fix for CVE-2026-69414 — nicknamed ShieldBreak, a privilege-escalation bug in the Malware Protection Engine — on the Thursday just before this month’s Patch Tuesday.[6] ShieldBreak itself was already a bypass of an earlier Defender bug, RoguePlanet, that Microsoft had patched back in July.[7] Right after the September patches went out, an anonymous researcher going by Nightmare Eclipse (also using the handle MSNightmare) published ShieldCrash: a working proof-of-concept that triggers the same underlying ShieldBreak behavior through a path Microsoft’s fix didn’t close.[3][4][6]

The researcher’s own description, posted alongside the exploit code, is blunt: Microsoft “failed to properly patch ShieldBreak,” and under specific conditions “it is still possible to trigger the exact same problem."[4] They’re calling it a skeleton PoC for now — arbitrary file read as SYSTEM on all supported Windows versions, not yet a full write primitive — and say they might build it out further later, adding they’re “feeling a bit lazy” for now.[4][6] This is one entry in a long string of zero-days this researcher has released against Windows and Defender components since April — Bleeping Computer counts at least eight named exploits before this one — in what’s become a running public dispute with Microsoft over its bug bounty and disclosure process; Microsoft has responded with public warnings about legal action over what it calls malicious activity.[6] I’m not wading into who’s right there. I don’t have the private correspondence between the two sides, and it’s not the part of this that’s actually useful to you Monday morning.

What is useful: by BleepingComputer’s account, RoguePlanet to ShieldBreak took about a month; ShieldBreak to ShieldCrash took hours.[6][7] Whatever this researcher’s motives, they’ve now demonstrated more than once that a Defender-engine fix can get bypassed fast.[6][7] Testing cited by Malwarebytes found the ShieldBreak chain actually requires Defender to be the active AV, so turning it off “helps” against this one bug and hurts against everything else.[7] That’s not a reason to disable Defender, and Malwarebytes says as much.[7] It’s a reason to stop treating “patch shipped” as the finish line for your endpoint security stack specifically, because that stack is now a standing target for exactly this kind of iterate-until-it-breaks-again research.

What I’d actually do this week

  1. Patch the two exploited zero-days first — CVE-2026-85880 and CVE-2026-81963 — they’re the ones with confirmed in-the-wild activity, record-setting release or not.[1][2]
  2. Don’t quote a single “X vulnerabilities patched” number without saying which source and which counting method it came from — 974, 996, and 972-to-997 are all defensible depending on what’s folded in.[1][2][5]
  3. Track ShieldCrash for a real patch, not just this week’s. Microsoft hasn’t confirmed a fix for CVE-2026-69414’s new bypass path yet, and the PoC is public on GitHub.[4] Watch endpoint telemetry for unexpected SYSTEM-level file reads in the meantime — that’s the observable your EDR can actually catch even without a signature for this specific technique.
  4. If your org runs Defender as primary AV on anything internet-facing or high-value, this is the week to check you’re not still relying on “patched last month” as your only control there.

Sources

[1] https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days — SecurityWeek: Microsoft Patches Record 974 Vulnerabilities [2] https://securityonline.info/patch-tuesday-zero-day-september-2026 — SecurityOnline: Patch Tuesday Zero-Day Sept 2026 [3] https://securityonline.info/windows-defender-0day-cve-2026-69414 — SecurityOnline: ShieldCrash Windows Defender 0day PoC [4] https://github.com/MSNightmare/ShieldCrash — GitHub: MSNightmare/ShieldCrash PoC [5] https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review — ZDI: September 2026 Security Update Review [6] https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access — BleepingComputer: New Microsoft Defender ShieldCrash zero-day grants SYSTEM access [7] https://www.malwarebytes.com/blog/bugs/2026/08/shieldbreak-bypasses-microsofts-patch-for-earlier-defender-flaw — Malwarebytes: ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw