Microsoft patched 974 flaws this month. Here's what actually matters for a small business.
September's Patch Tuesday was the largest in Microsoft's history — 974 vulnerabilities, two already being exploited. The headline number is not the useful one. Here's how to read it, and the three things to do this week.
On Tuesday Microsoft shipped fixes for 974 security vulnerabilities in a single update. That's not a typo. The previous record was 569, set in July; this one is nearly seventy percent bigger, and The Hacker News puts the running total for 2026 past 2,760.
If you run a small business on Microsoft 365 and you saw that headline, the reasonable reaction is somewhere between "should I be worried?" and "I don't have time for this." Both are fair. So here is the version for someone who doesn't have a security team: what the number actually means, which parts of it apply to you, and the three things worth doing this week.
The number is not the news
Nine hundred and seventy-four is a count of everything Microsoft fixed across everything Microsoft makes — 723 in Windows, 222 across the Office suite, the rest spread over SQL Server, developer tools and more. Most of those bugs will never be used against anyone. A large share affect software you don't run.
What matters is a much smaller set:
Two flaws are already being exploited. CVE-2026-85880 is a memory bug in a core Windows component called ALPC; CVE-2026-81963 is a flaw in the Windows Update mechanism itself. Both let an attacker who is already on a machine elevate themselves to full SYSTEM control. Both have been added to CISA's Known Exploited Vulnerabilities catalog, with a federal deadline of September 22.
Read that carefully, because it's the most useful sentence in this post: neither zero-day gets an attacker in. They help an attacker who is already in. Somebody still has to phish a user, steal a session token, reuse a password from a breach, or walk through an exposed service first. The zero-days are the second step of a break-in, not the first.
Twenty of the bugs are "wormable." Security Affairs counts twenty that could in principle spread from machine to machine with no user involved, and the article lists a cluster of them rated 9.8 out of 10 in Remote Desktop, DNS, DHCP and network file sharing. A wormable bug only bites if the vulnerable service can be reached. On an internal-only server behind a firewall, it's a patch you apply on schedule. On a machine with Remote Desktop open to the internet, it's the reason attackers are scanning for you right now.
113 are rated Critical. That's the tier where, in the wrong configuration, someone can run code on your machine without you clicking anything. It's also roughly one in nine of the total — which is the other way of saying that eight in nine are not.
Jack Bicer of Action1 put the practical problem in five words, quoted in the Hacker News piece: the job is "knowing what needs attention first." That's exactly right, and it's the whole difference between a security team and a small business — not the patching, the prioritizing.
If you're on Microsoft 365, which parts apply to you?
Every Windows PC and laptop. The two exploited zero-days are Windows bugs, and they affect the ordinary desktops your staff use. This is the part that applies to everyone.
Any server you still run yourself. The article flags a remote-code-execution flaw in Exchange Server and an authorization bypass in SharePoint Server. If you moved to Microsoft 365 years ago and never decommissioned the old on-premises Exchange box — it happens more than you'd think — that box is now the softest target you own. This is the month to patch it or, better, to finally turn it off.
Microsoft Authenticator. The Hacker News piece also lists an authentication-bypass flaw in Microsoft Authenticator, the app most of your staff use for MFA. Phones update automatically if you let them; make sure you're letting them.
Microsoft 365 itself, mostly not. Exchange Online, SharePoint Online, Teams and the rest are patched by Microsoft on Microsoft's side. You don't have to do anything for the cloud services. The exposure is on the devices that connect to them and the servers you still operate.
Three things to do this week, in order
1. Find out which devices actually installed it. Not "we have Windows Update turned on." Which machines, by name, are on the September update. Every small business we've looked at has at least one device that quietly stopped updating months ago — a laptop that never leaves the conference room, a PC under someone's desk with a full disk, a machine that was set to defer updates during a project and never set back. Those machines were behind before Tuesday. Now they're 974 patches behind. Intune, Windows Update for Business or even the Windows Update history page will tell you; whatever you use, make the list. Use CISA's September 22 deadline as your own even though it doesn't legally apply to you — it's a sensible bar, and it's eleven days away.
2. Check what you expose to the internet. The wormable bugs make this the week to be certain. If your office firewall forwards Remote Desktop, a file share, DNS or DHCP to a public address, that service just became a much bigger problem than it was on Monday. Most owners don't know what their firewall forwards; the person who set it up left. You can see what the internet sees in about ten seconds with a free external scan of your own domain — no login, nothing to install — and it will show you the services answering on your public addresses before an attacker's scanner does.
3. Then ask the harder question. Since both exploited zero-days need an attacker to already be inside, the patch closes the second door, not the first. What's the state of the first door? Is MFA actually enforced for everyone, or is there an exception list? Are there inbox rules forwarding mail outside the company? Are there old accounts that still work? A patch is a good reason to spend an hour on the tenant configuration, because that's where the break-in starts — and it's the part Patch Tuesday can't fix for you.
The honest limit of a patch count
There's a temptation, when a number like 974 lands, to treat "we patched everything" as the finish line. It isn't. It's necessary, it's this week's job, and it's still the second step.
The businesses that get broken into mostly don't get broken into through an unpatched Critical. They get broken into through a password someone reused, a login with no second factor, a session token lifted from a laptop, a mailbox rule nobody noticed. Then, once inside, the attacker reaches for exactly the kind of privilege-escalation flaw Microsoft just fixed two of. Patch those, absolutely. But if the first door is open, you've made the burglar's second step harder and left the front door ajar.
This is the reason we built Vulnerability Watch to match new advisories against the technology a tenant actually runs, rather than sending you the whole list — and the reason the rest of a Tenant Strike scan is about the tenant's configuration, not its patch level. The count is the headline. Which of them reach you is the story.
Sources: The Hacker News, SecurityWeek, Security Affairs, CISA KEV catalog, Microsoft Security Update Guide.
AI-researched from public sources, human-reviewed on September 11, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.