September 9, 2026 974 Patches, Two Being Exploited Right Now: How a Dental Practice Should Read September’s Patch Tuesday
On September 8, Microsoft shipped the largest Patch Tuesday in its history: fixes for roughly 974 vulnerabilities across Windows, Office, SQL Server and its developer tools (Microsoft Security Response Center, September 2026 Security Updates). The headline number is alarming, and it is meant to be read exactly the opposite way. For a dental office running a practice server, a dozen workstations and a couple of imaging PCs, the useful news this month is not “974” – it is “two.” Two of those flaws are already being exploited in real attacks, and those are the ones that decide what you do tonight. The rest is a queue, not an emergency.
Why the number keeps breaking records – and why that is not the scary part
Microsoft has been setting monthly records all year, and the reason is structural: the company is using AI to hunt for bugs in its own code, and AI finds them faster than humans ever did. More vulnerabilities discovered is not the same as more vulnerabilities being used against you. The security industry was blunt about this. “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,” said Tenable’s Satnam Narang, urging organizations to work out which flaws actually apply to them and are genuinely reachable before panicking about the total (CyberScoop, September 2026 Patch Tuesday coverage). The Zero Day Initiative’s Dustin Childs made the same point – the pile keeps growing, but there has been “no correlating spike in active exploits.” Translation for a practice: a 974-item update is not 974 times more dangerous than a normal month. It is a normal month with a much longer to-do list, and the trick is sorting the list.
The two that actually matter this month
Both of the flaws being exploited before the patch existed are privilege-escalation bugs rated CVSS 7.8. The first, CVE-2026-81963, is in the Windows Update Stack. The second, CVE-2026-85880, is in Windows Advanced Local Procedure Call (ALPC), a core piece of how Windows processes talk to each other. Neither is a remote “click a link and you’re owned” flaw. Both are the second move in an attack: an intruder who has already gotten a small foothold on a machine – through a phishing attachment, a malicious download, a stolen password – uses the bug to escalate from an ordinary user account to SYSTEM, the highest level of control on a Windows machine. Once an attacker is SYSTEM, they can disable security tools, install ransomware across the network and reach the patient data on your server. That is why local privilege escalation is never “just” local. It is the hinge between a minor incident and a practice-ending one, and it is exactly why the foothold stage – the phishing email, the invisible-text phishing that slips past your spam filter – matters so much. Patch these two first. On the practice server and any machine that touches patient records, they go on tonight or first thing tomorrow, not at the end of the month.
A priority order for everything else
After the two exploited zero-days, you are not clearing 972 items by hand – you are sorting them. As Action1’s Jack Bicer put it, at this scale “the challenge is not simply getting through the patch list but knowing what needs attention first.” A sensible order for a dental practice:
1. The two exploited zero-days – server and record-handling machines, immediately. 2. Critical-rated flaws on anything internet-facing – your firewall-adjacent server, any remote-access tool, anything a patient or vendor can reach from outside. More than one in ten of this month’s fixes are rated critical, and the internet-facing ones are where an outsider can actually touch them. 3. Reachable workstations – reception and operatory PCs that open email and browse the web, because that is where the foothold usually starts. 4. The long tail – the hundreds of fixes for components you may not even run (SQL Server features, developer tools, server roles a small practice never enabled) follow your normal monthly cycle. Most of the 974 simply do not apply to a typical office, and the ones that do are handled by letting Windows Update run on your managed schedule.
The machines you can’t just reboot at 2 p.m.
The real friction in a clinical setting is not deciding to patch – it is when. You cannot force a restart on the PC driving a CBCT or an intraoral sensor in the middle of a patient’s appointment, and some older imaging devices cannot take the latest Windows updates at all. That is a scheduling and segmentation problem, not a reason to skip the update. Imaging and operatory machines get patched in off-hours with the vendor’s blessing on the version, and the devices that genuinely cannot be patched get walled off on a segmented network so a compromise elsewhere can’t reach them. It is also worth remembering that Patch Tuesday is a Microsoft event – your other computers-in-disguise patch on their own calendars. The same month we have been reminded to patch actively exploited flaws in practice routers and to update the VoIP phone system, which is a computer too. A complete patch posture covers all of it, not just Windows.
What this means for your practice
A 974-fix Patch Tuesday is a test of process, not heroics. A practice with a managed patching program barely notices a record month: the two exploited flaws get pushed on a priority ring, the criticals follow on a tight schedule, workstations update overnight, imaging machines patch in approved off-hours windows, and the long tail rides the normal cycle – all tracked, so you can actually prove the practice is current if PHIPA ever asks. A practice without that program faces the same 974 as a wall of noise, patches nothing, and leaves the two exploited bugs sitting open for weeks. That gap is the whole game. Compudent runs managed patching for dental practices across Ontario – prioritizing the flaws that are actually being exploited, scheduling around clinical hours, version-checking updates against your imaging vendors, and keeping the audit trail that proves you stayed current. If this month’s number made you wonder whether your practice is actually keeping up, contact Compudent for a patch-posture assessment – we will tell you where you stand and what, if anything, is still sitting open.
Sources & further reading:
- Microsoft Security Response Center – September 2026 Security Updates
- CyberScoop – Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
- Trend Micro Zero Day Initiative – The September 2026 Security Update Review
Related Reading
- A Fake Job Offer, a Windows Kernel Rootkit: The Lazarus Zero-Day (CVE-2026-68820) and What It Means for Your Dental Practice
- February 2026 Patch Tuesday: Microsoft Fixes 6 Actively Exploited Zero-Day Vulnerabilities — What Dental Practices Need to Do Now
- When the Tool That Manages Your Network Gets Hacked: The N-able N-central Breach and What It Means for Dental Practices