Microsoft Just Shipped 972 Patches and a Researcher Broke Their Defender Fix the Same Day
September 2026 Patch Tuesday dropped with 972 CVEs. That number is not a typo. It is the largest single patch release in Microsoft's history, almost doubling August's count and shattering every record the company has set in the two decades it has been doing this. And within hours of the patches going live, a researcher called Nightmare Eclipse published a proof-of-concept showing that one of the…
September 2026 marked Microsoft's largest Patch Tuesday ever, releasing 972 patches to address CVE vulnerabilities across a variety of systems and applications. This surpasses all previous records set by Microsoft over the past two decades of patch releases. However, just hours after the patches went live, researcher Nightmare Eclipse released proof-of-concept code demonstrating that one of the most critical patches, CVE-2026-69414 for Windows Defender, was not fully effective.
The original vulnerability, dubbed RoguePlanet, was discovered in June 2026 and patched in July. A follow-up exploit called ShieldBreak appeared in August, showing the initial patch did not fully eliminate the issue. On the day of the September patch release, Nightmare Eclipse delivered ShieldCrash, which revealed that the Defender's file-handling logic still had exploitable weaknesses.
Through ShieldCrash, an attacker could force Windows Defender to access protected system files with SYSTEM-level privileges, leading to an arbitrary file read vulnerability across all supported Windows versions. This is the third vulnerability targeting Defender's file-handling in quick succession, each one bypassing the previous fix.
Since April 2026, Nightmare Eclipse has disclosed a total of nine zero-days affecting Defender, BitLocker, and various Windows components. Microsoft had previously indicated it would take legal action against researchers causing real harm with their disclosures, but the researcher continued publishing despite this.
Microsoft's patch release affected 972 vulnerabilities overall, with 113 rated as Critical. Remote code execution accounted for 258 patches, elevation of privilege for 437, and information disclosure for 171. The majority of patches addressed Windows itself, with 726 fixes, followed by Microsoft Office's 135 patches. Two zero-days were confirmed actively exploited before patch deployment: CVE-2026-85880, an ALPC heap buffer overflow leading to SYSTEM privilege escalation, and CVE-2026-81963, a Windows Update Stack vulnerability enabling privilege escalation.
Beyond the high-profile zero-days, the report highlights 20 wormable vulnerabilities that could enable remote, unauthenticated code execution with no user interaction. Notable wormable bugs include DNS Server vulnerability CVE-2026-69730 (CVSS 9.8), Netlogon vulnerability CVE-2026-72982 (CVSS 9.8), and DHCP Server vulnerabilities CVE-2026-69845 and CVE-2026-72979 (both CVSS 9.8).
Additionally, Remote Desktop Services (RDS) was hit by CVE-2026-69525 (CVSS 9.8), allowing unauthenticated code execution in a network environment.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.