It is Tuesday again. More specifically, it is Patch Tuesday, the day each month when Microsoft releases security updates for Windows and other Microsoft products.
September 2026 has delivered a very clear reminder that patching is no longer a routine housekeeping task. It is a critical part of protecting your business.
Microsoft’s September Patch Tuesday addressed a record-breaking 966 security vulnerabilities, including 105 Critical vulnerabilities and two zero-day vulnerabilities that were already being exploited. The previous record was 570 vulnerabilities in July 2026, which shows just how quickly the cyber security landscape is changing.
For business owners, the message is simple. Keeping Windows and your other business applications updated is more important than ever.
What Was Included in September’s Patch Tuesday?
The September 2026 security release covered an unusually large number of vulnerabilities across Microsoft products. The approximate breakdown included:
- 438 elevation of privilege vulnerabilities
- 258 remote code execution vulnerabilities
- 173 information disclosure vulnerabilities
- 56 denial of service vulnerabilities
- 19 security feature bypass vulnerabilities
- 16 spoofing vulnerabilities
Of the 105 vulnerabilities rated Critical, 81 involved remote code execution, 20 involved elevation of privilege, two involved information disclosure and one involved a security feature bypass.
Different security researchers may report slightly different totals depending on how vulnerabilities are counted. However, there is broad agreement that this was Microsoft’s largest Patch Tuesday release to date.
These numbers can sound abstract, but each vulnerability represents a weakness that may allow an attacker to access a system, run malicious code, steal information, bypass security controls or disrupt business operations.
Two Actively Exploited Zero-Day Vulnerabilities
Two of the most important vulnerabilities addressed in the September release were zero-days that Microsoft confirmed were already being exploited.
CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability
CVE-2026-81963 affects the Windows Update Stack. It involves improper handling of links before files are accessed and may allow an authorised local attacker to elevate their privileges to NT AUTHORITY\SYSTEM.
SYSTEM privileges provide an attacker with an extremely high level of control over a Windows device. Once this level of access is achieved, the attacker may be able to disable security tools, install malware, access sensitive information or establish ongoing access.
CVE-2026-85880: Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability
CVE-2026-85880 affects the Windows Advanced Local Procedure Call system. It involves a heap-based buffer overflow that may allow an attacker operating from a low-privilege process to gain SYSTEM-level permissions.
Neither vulnerability is described as a standalone remote code execution attack. An attacker generally needs an initial foothold on the device before exploiting them. However, that does not make them harmless.
Modern attacks frequently begin with phishing, credential theft, malicious browser notifications, compromised websites or social engineering techniques such as ClickFix. Once an attacker gains limited access, an elevation of privilege vulnerability can help turn that initial compromise into a serious security incident.
Why the Number of Vulnerabilities Is Increasing
The increasing use of artificial intelligence is changing vulnerability discovery.
Security researchers and software vendors are using AI-assisted tools to analyse software, identify weaknesses and find vulnerabilities faster. This is helping the security community discover and fix issues that may previously have remained hidden.
However, the same types of capabilities are also available to cybercriminals. Malicious actors can use affordable AI tools to research targets, develop convincing social engineering messages, analyse software and speed up parts of their attack process.
AI is not solely responsible for the large number of vulnerabilities being reported, but it is helping both defenders and attackers work faster. Businesses therefore need security controls that can keep pace with a rapidly changing threat environment.
Why Patching Matters to Every Business
Patching reduces the period during which a known vulnerability can be exploited.
Once a vulnerability and its update become public, attackers may begin studying the weakness, developing exploit methods and scanning for systems that have not been updated. Businesses that delay patching may leave a known door open after the instructions for attacking it have effectively become public.
Patching is particularly important for organisations that hold sensitive or regulated information. Accounting firms, financial planners, legal practices, medical practices, schools, mining companies, real estate agencies and professional services businesses may all hold information that is valuable to cybercriminals. Implementing patching software has now become a critical part of every IT support business in Perth.
Windows Updates Are Only Part of the Picture
Installing Windows updates is essential, but Windows is not the only software running on a business device.
A typical workstation may also include:
- Web browsers
- PDF readers and editors
- Video conferencing applications
- Accounting and bookkeeping software
- Practice management systems
- Compression and file transfer tools
- Remote access applications
- Printer and scanner utilities
- Industry-specific applications
- Browser extensions and supporting components
Cybercriminals regularly target vulnerabilities in third-party applications because these applications may not be covered by a business’s standard Windows update process.
This creates a dangerous situation where Windows appears fully patched, but other applications remain outdated and vulnerable.
For organisations seeking reliable managed IT services, patching should therefore include both the operating system and the third-party applications used across the business.
Why Local Administrator Access Increases Risk
The two actively exploited September zero-days also reinforce the importance of removing unnecessary local administrator privileges.
Many employees do not require administrator access to perform their normal duties. When users have local administrator permissions, malicious software or an attacker operating through their account may have more opportunities to alter settings, install applications, disable protections or exploit privilege-related vulnerabilities.
Removing local administrator access is not a complete security solution, but it can significantly reduce the impact of a compromised account or device.
This control is even more effective when combined with:
- Endpoint detection and response
- Application whitelisting
- Multi-factor authentication
- Security awareness training
- Advanced patch management
- Vulnerability scanning
- Strong access controls
- Reliable backups
- A documented incident response plan
This layered approach is fundamental to effective small business cyber security and corporate cyber security. No single product can prevent every attack. The objective is to make it difficult for an attacker to gain access, escalate privileges, execute unauthorised software and move through the environment.
Advanced Patch & Vulnerability Management
Qbit’s Advanced Patch & Vulnerability Management service provides proactive patch management and vulnerability monitoring to identify and remediate security risks caused by outdated software, missing updates and known exploitable weaknesses.
Cybercriminals frequently target software vulnerabilities for which updates are already available. In many cases, the issue is not that a fix does not exist. The problem is that the update has not been identified, tested or installed across every affected device.
Qbit performs continuous vulnerability scanning to identify and prioritise security weaknesses across managed systems. Regular scanning helps ensure emerging risks are identified quickly and provides visibility into areas requiring remediation.
Advanced Patch Management complements this process by helping deploy security updates for supported third-party applications. This extends protection beyond Windows and Microsoft Office to a broader range of applications used throughout the working day.
In simple terms, vulnerability scanning helps find the problem, while advanced patch management helps fix it.
Used together, these services can help businesses:
- Identify outdated software across managed devices
- Prioritise vulnerabilities according to risk
- Apply third-party application updates more consistently
- Reduce exposure to known exploits
- Improve visibility and reporting
- Support ongoing risk management
- Demonstrate a more structured approach to cyber security
- Support relevant SMB1001 requirements
This service is an important part of the broader cyber security services Perth businesses need as threats become faster, more automated and more targeted.
Patching and SMB1001 Certification
Qbit believes every business should work towards certification under the SMB1001 cyber security standard, with Silver as a sensible minimum target and higher levels considered according to the organisation’s risk, industry and contractual obligations.
SMB1001 is a multi-tiered cyber security standard designed specifically for small and medium-sized businesses. It provides five progressive certification levels: Bronze, Silver, Gold, Platinum and Diamond.
The standard covers more than technology. Its control areas include technology management, access management, backup and recovery, policies and processes, and education and training.
Patching is embedded within this broader security approach. The current standard includes requirements relating to tested and approved software updates across organisational devices, while higher levels introduce additional expectations around server patch management, access controls, governance and staff awareness.
Achieving certification is not simply about purchasing a group of security products. A business must implement, maintain and be able to demonstrate the required controls, policies and processes.
Qbit has achieved SMB1001 Gold certification, giving our team practical experience in the implementation and ongoing management of these controls. This helps us support clients with a realistic pathway towards certification rather than providing advice based only on theory.
For businesses looking for a Perth IT company that understands both technology and cyber security standards, this experience is especially valuable.
People Remain an Essential Line of Defence
Technical controls are critical, but people remain an important part of cyber security.
If an employee recognises a suspicious email, refuses an unexpected request to run a command, reports a fake browser warning or questions an unusual login prompt, they may prevent an attacker from gaining the initial foothold needed to exploit a vulnerability.
Businesses should regularly remind employees to:
- Be cautious with unexpected links and attachments
- Never follow instructions from an untrusted website to paste commands into their computer
- Report suspicious messages promptly
- Avoid approving unexpected multi-factor authentication prompts
- Use unique passwords or passphrases
- Store passwords in an approved password manager
- Allow approved updates and restarts to complete
- Contact IT support when something unusual occurs
Security awareness training works best when it is ongoing, practical and reinforced by secure technical controls.
The Takeaway for Perth Businesses
September’s Patch Tuesday demonstrates that patching cannot be treated as an occasional maintenance task.
Businesses need visibility over operating systems and third-party applications, a structured process for testing and deploying updates, effective vulnerability scanning, controlled administrator access and employees who know how to recognise suspicious activity.
The objective is not to install every update without review or to assume that patching alone will stop every attack. A mature patching strategy balances security, stability and operational requirements while ensuring genuine risks are addressed promptly.
For businesses comparing IT support services Perth, managed IT support Perth or broader Perth IT solutions, it is worth asking how Windows patches, third-party applications and identified vulnerabilities are actually managed. A provider should be able to explain what is monitored, what is updated, how issues are prioritised and what happens when remediation requires further action.
If you would like to strengthen your patching process, reduce exposure to known vulnerabilities or work towards SMB1001 Silver certification or higher, contact Qbit IT Solutions. Our team can review your current environment and explain how Advanced Patch & Vulnerability Management can support a practical, layered cyber security strategy for your business.





