What shipped on Tuesday
Microsoft patched 974 CVEs on September 9, the highest single-month release count on record. Of those, 105 are rated Critical: 81 enable remote code execution, 20 are elevation of privilege, 2 are information disclosure, and 1 is a security feature bypass. Help Net Security identified a DNS-over-TCP remote code execution class they are calling a SigRed successor, though full technical details are not yet public.
The two zero-days exploited before the patch
CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call. A local attacker can gain SYSTEM on Windows 10 and Windows Server 2012 through 2022. CVE-2026-81963 is an improper link resolution flaw in the Windows Update Stack. A low-privilege authenticated attacker can gain SYSTEM on Windows 11 and Windows Server 2025. Both were confirmed exploited in the wild before Tuesday's release.
Twenty wormable remote code execution flaws
Beyond the zero-days, 20 vulnerabilities in this batch allow unauthenticated remote code execution with no user interaction required. The highest-exposure targets are CVE-2026-55007 in Exchange Server, CVE-2026-69465 in SharePoint, and CVE-2026-69525 in Remote Desktop Services. Network-exposed Exchange and RDS hosts should be treated as priority targets in any internal patch sequencing.
ShieldCrash arrived hours after the patch
Anonymous researcher Nightmare Eclipse published a proof-of-concept called ShieldCrash within hours of the Patch Tuesday release. ShieldCrash bypasses CVE-2026-69414 (ShieldBreak), a Microsoft Defender privilege escalation flaw included in Tuesday's patch. The bypass restores SYSTEM access on fully patched Windows 10 and Windows 11, though without write access to the file system. This is the tenth Defender or Windows bypass Nightmare Eclipse has released since April 2026, following ShieldBreak, LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. Microsoft has no patch for ShieldCrash as of this writing.
Where to start
Patch network-exposed Exchange, SharePoint, and Remote Desktop Services first for the wormable RCEs. For the zero-days, CVE-2026-85880 affects older Windows Server versions that typically carry heavier legacy workloads, so treat those alongside the Windows 11 and Server 2025 hosts exposed to CVE-2026-81963. For ShieldCrash, there is no patch yet. Monitor Microsoft's security advisory channel and apply workarounds as they become available.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are managing a large Windows patch cycle and want to think through prioritization.