Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Resolves Record 974 Vulnerabilities in September

Microsoft Resolves Record 974 Vulnerabilities in September

Posted on September 9, 2026 By CWS

Microsoft has set a new record by addressing 974 vulnerabilities in its latest Patch Tuesday update, which includes two zero-day vulnerabilities that have been actively exploited. This significant update spans various products, with 723 flaws in Windows, 111 in Office, and others in SQL and Developer Tools. Among these, over 110 vulnerabilities have been classified as critical, highlighting the ongoing challenges in maintaining software security.

Details of the Patch Release

In this massive update, Microsoft tackled privilege escalation, remote code execution, and information disclosure vulnerabilities, which together account for nearly 90% of the fixes. The updates, which also include patches for 25 non-Microsoft CVEs, bring the total number of addressed vulnerabilities to 999. This follows a series of monthly updates where 457 flaws were fixed in August and 663 in July, reflecting an upward trend in the company’s vulnerability management efforts.

Jack Bicer, director of vulnerability research at Action1, emphasized the importance of prioritizing which vulnerabilities to address first, given the sheer volume of updates. He noted that IT and security teams must quickly identify which patches require immediate attention to effectively mitigate risks.

Exploited Zero-Day Vulnerabilities

The update includes two zero-day vulnerabilities that have raised significant concerns. CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, and CVE-2026-81963, an improper link resolution in the Windows Update Stack, both allow attackers to gain SYSTEM privileges. Microsoft has identified active exploitation attempts but has not disclosed further details about the attackers or the scope of these efforts.

Security researchers from Volexity, Proofpoint, and Airbus Helicopters, along with the Microsoft Threat Intelligence Center, contributed to identifying these critical vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply these patches by September 22, 2026.

Additional Notable Vulnerabilities

Other vulnerabilities addressed in this update include CVE-2026-55007 in Microsoft Exchange Server and CVE-2026-65669 in SQL Server, among others, with CVSS scores ranging from 8.1 to 9.8. These flaws pose significant risks, such as unauthorized code execution and privilege escalation over networks, underscoring the critical need for timely patch application.

According to TrendAI’s Zero Day Initiative, Microsoft has already patched 2,760 security flaws this year, showcasing the growing role of AI-assisted vulnerability detection. Experts like Satnam Narang of Tenable stress the need for organizations to prioritize patching based on the risk and exposure of these vulnerabilities to prevent potential breaches.

Despite the large number of vulnerabilities patched, the most significant threats remain limited in scope. Cybersecurity experts urge organizations to assess which vulnerabilities directly impact them and prioritize remediation efforts accordingly. As Tyler Reguly from Fortra notes, while the numbers are high, they reflect proactive security measures to mitigate risks before exploitation occurs.

The Hacker News Tags:CVE, Cybersecurity, Exploit, IT security, Microsoft, Patch Tuesday, security update, Vulnerabilities, Windows, zero-day

Post navigation

Previous Post: Chrome 153 Updates Address 230 Security Flaws, Including Critical 0-Day
Next Post: Chrome Users Urged to Update Amid V8 Security Flaw

Related Posts

Spark RAT Exploits Vulnerabilities to Target Cambodian Systems Spark RAT Exploits Vulnerabilities to Target Cambodian Systems The Hacker News
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog The Hacker News
Critical Flaw in ChatGPT Agents Allows Rogue AI Deployment Critical Flaw in ChatGPT Agents Allows Rogue AI Deployment The Hacker News
Gaslight macOS Malware Targets AI Analysis with Prompt Injection Gaslight macOS Malware Targets AI Analysis with Prompt Injection The Hacker News
Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws Microsoft Criticizes Uncoordinated Disclosure of Zero-Day Flaws The Hacker News
North Korean Hackers Exploit npm Packages for Malware North Korean Hackers Exploit npm Packages for Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows Defender Vulnerability: New Flaw Discovered
  • Ivanti Releases Vital Security Updates for Key Products
  • Critical cPanel Vulnerability Allows Root Access
  • Chrome Users Urged to Update Amid V8 Security Flaw
  • Microsoft Resolves Record 974 Vulnerabilities in September

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark