Microsoft’s 8 September release fixed 966 vulnerabilities by BleepingComputer’s count (Tenable and Malwarebytes count 964), 105 of them Critical. Two were exploited zero-days that lead to SYSTEM privileges: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC. BleepingComputer attributes the jump in volume to Microsoft starting to use an AI-powered vulnerability discovery system.

The cumulative update (KB5124008) then broke Remote Desktop Services and RDP connections, Hyper-V Plan9 sharing to Linux guests and some USB audio devices. On 16 September Microsoft shipped out-of-band fixes, including KB5129195 for Windows 11 24H2 and 25H2, KB5129194 for 26H1 and KB5129236 for Windows 10, plus Windows Server builds.

This is the case for patch rings in a single month. Two zero-days say patch fast; a broken Remote Desktop stack says don’t patch everything at once. Pilot on a small group first — including at least one remote desktop host — then the rest of the fleet a few days later, and confirm the out-of-band fix has landed before you call the month done.

What it means for your businessIf remote desktop connections broke after September’s update, the fix is the 16 September out-of-band release. From here on, stage updates through a pilot ring that includes a remote desktop host.
Source & referenceBleepingComputer — September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days ↑Tenable — September 2026 Patch Tuesday addresses 964 CVEs ↑Cybersecurity News — Microsoft releases emergency Windows updates ↑