Well, Patch Tuesday just broke another record.
Microsoft released roughly 995 patches this month — the largest Patch Tuesday we've seen and just five short of 1,000. That includes more than 110 critical vulnerabilities and two actively exploited zero-days.
At that point, nobody is realistically looking at a list of nearly a thousand patches and treating everything the same. The question is what needs attention now, and what can wait.

Why This Month Is Different
September 2026 wasn't just a big update — it was the biggest Microsoft has ever shipped. Depending on how researchers count external and Chromium bugs, the total lands between 966 and 997 CVEs, with most outlets settling on roughly 995. That's more than double the size of a typical monthly release, and it continues a worrying trend: Microsoft has already patched more than 2,700 CVEs this year to date — more than double any previous year.
The sheer volume is a problem in itself. When a patch list is this large, the risk isn't just the vulnerabilities — it's that the important ones get lost in the noise. That's exactly where a structured vulnerability management approach pays off.
The Two Zero-Days You Can't Ignore
Every month has critical patches, but the ones that demand immediate action are the actively exploited zero-days — flaws attackers are already using in the wild before a fix was available.
This month, Microsoft patched two zero-days already under active exploitation:
- Windows Update Stack — a vulnerability in the component that installs Windows updates, which attackers could use to gain elevated privileges
- Windows ALPC (Advanced Local Procedure Call) — a privilege escalation flaw in a core Windows communication mechanism
When a zero-day is actively exploited, the window between "patch available" and "attacker uses it" is measured in days, not months. These should be treated as patch now items, not "add to the queue" items.
What Needs Attention Now
For most SMBs, the priority order is clear:
- The two actively exploited zero-days — patch these immediately, across every affected device
- Internet-facing systems — edge devices, VPNs, remote access, and anything exposed to the internet are the highest-value targets
- Critical remote code execution (RCE) flaws — any vulnerability that lets an attacker run code remotely without authentication
- Domain controllers and servers — a compromise here gives attackers the keys to your whole network
What Can Wait
Not everything in a 995-patch release needs to be deployed this week. Lower-severity issues — important-rated flaws in rarely-used features, or vulnerabilities that require local access or physical presence to exploit — can be scheduled into your normal maintenance window.
The key is triage, not neglect. Every patch eventually needs to be applied, but a rational prioritization keeps your team focused on the risks that actually threaten your business right now.
How Virtue Technology Solutions Can Help
Managing a record-breaking patch release is exactly the kind of work that overwhelms an internal IT team — especially for small and mid-sized businesses that don't have a dedicated security staff.
At Virtue Technology Solutions, we help SMBs stay ahead of the patch cycle with a structured managed IT and cybersecurity program that includes:
- Patch management — we track, test, and deploy updates on a schedule that balances security with stability
- Vulnerability assessment — we identify which of your systems are exposed and prioritize fixes by real-world risk
- Zero-day response — when an actively exploited flaw drops, we know which of your devices are affected and patch them first
- Managed detection and response — we monitor your environment so that if something slips through, we catch it early
You don't need to read a 995-item patch list to stay secure. You need a partner who does it for you.
Overwhelmed by the patch cycle? Contact Virtue Technology Solutions for a no-pressure consultation on how we can keep your business patched, protected, and productive.