Microsoft’s September update, released this week, is its largest Patch Tuesday on record, fixing 966 separate flaws across Windows and its business software. Buried in that number are two zero-day vulnerabilities that attackers were already exploiting before the fix existed. If your business runs Windows machines, and almost every UK SME does somewhere, this is the kind of update that shouldn’t wait for the next quiet Friday afternoon.
Why these two flaws are worse than a routine patch
One of the actively exploited flaws is a Windows privilege escalation vulnerability, the kind of bug that doesn’t get an attacker into your systems on its own, but turns a small foothold into full control once they’re in. In practice, that means a single successful phishing email or an infected download, ordinarily a containable incident, can escalate straight to system-level access on the affected machine. That’s a meaningfully worse outcome than the same attack would achieve on a fully patched device, and it’s exactly the kind of gap ransomware crews look for once they’re inside a network.
The scale of this update matters too. Nearly a thousand fixes in one release makes it tempting to assume most of them are minor and the update can wait. The two zero-days are the reason it can’t: attackers don’t need your whole estate vulnerable, they need one unpatched machine with the right flaw, and they were already using these two before Microsoft shipped a fix. This is also the largest single Patch Tuesday Microsoft has ever released, which tells you something about the direction of travel: security researchers, and increasingly attackers, are using AI tools to find flaws in existing software far faster than before, so months this heavy are likely to become more common, not less.
Why “we’ll get to it” is riskier than it used to be
The old habit of batching Windows updates into a monthly or quarterly IT review made sense when zero-days were rare. It makes far less sense now. A zero-day, by definition, means attackers had a working exploit before any defence existed, so the clock on “time to patch” started before you even knew there was a problem. Once Microsoft publishes the fix, the vulnerability details effectively become public too, which security researchers have long observed tends to accelerate attacker activity rather than slow it down, as less sophisticated attackers reverse-engineer the patch to build their own exploit. In practice, that means the safest window to patch is the first few days after release, not the next scheduled maintenance slot three weeks away.
What to actually do this week
Start with anything internet-facing or handling sensitive data, servers, remote access tools, finance and HR machines, since those are the highest-value targets if a device is compromised. If your business uses automatic updates through Windows Update or a managed IT provider, confirm the September patches have actually installed rather than assuming they have; update failures are common and often go unnoticed until something goes wrong. If you’re running older, unsupported Windows versions anywhere in the business, this is also a good prompt to check whether they’re still receiving security updates at all, because unsupported machines don’t get zero-day fixes like this one, ever.
For businesses without a dedicated IT function, this is where a fast, practical check-in pays for itself. CoolCoding can confirm your systems are actually patched, not just scheduled to be, and flag anything running end-of-life software before it becomes the weak link an attacker finds first. It’s a much cheaper conversation to have this week than after an incident.
The takeaway
Two live, exploited vulnerabilities inside one 966-flaw update is a reminder that “we’ll patch it eventually” is a real risk, not just an IT department preference. Check that this month’s Windows updates have actually installed across your business, prioritise anything internet-facing or handling sensitive data, and retire anything still running unsupported software. The gap between “patch available” and “patch installed” is exactly where these attacks succeed.