Rapid7 highlights two exploited flaws in September Patch Tuesday
Microsoft's September 2026 Patch Tuesday addressed 999 vulnerabilities, the highest in a single day, including 723 in Windows. Two flaws, CVE-2026-85880 and CVE-2026-81963, are being exploited in the wild. CVE-2026-85880 affects Windows but not Server 2025 or 11. CVE-2026-81963 has a CVSS score of 7.8. Google Chrome and Microsoft Edge patched CVE-2026-85046, but Microsoft did not issue an advisory. Upcoming product lifecycle changes include Windows 11 24H2 and Windows Server 2012 updates.
How this was made

The 30-second read
Why it matters
The disclosed exploits may trigger short-term defensive trading in Microsoft and raise awareness of enterprise security risks.
Market read
Security vulnerability disclosures can cause brief price volatility in affected tech stocks, especially when active exploitation is confirmed.
What to watch
Potential for Microsoft to release emergency hotfixes or leverage the Rust rewrite narrative to reassure customers.
Background
Microsoft's September 2026 Patch Tuesday released 999 CVEs, the highest ever, with two actively exploited Windows flaws.
Ticker impact
Rapid7 reports Microsoft has two exploited vulnerabilities in September Patch Tuesday, indicating immediate security risk.
downside risk of 1-2% in the next trading session.
Active exploitation can prompt enterprise customers to reassess exposure and may trigger short-term defensive positioning.
Market effects
Highlights ongoing vulnerability challenges for the software security sector.
May affect US and global enterprise software buyers monitoring patch risks.
Limited to firms with large Windows deployments; broader market impact minimal.
Counterpoint
Investors could view the disclosure as a temporary blip, expecting Microsoft to mitigate quickly.
Key entities
- companyMicrosoft
US-listed software giant (MSFT) responsible for the patched products.
- companyRapid7
Security research firm providing the exploitation analysis.



