Microsoft has set a new record by addressing 974 vulnerabilities in its latest Patch Tuesday update, which includes two zero-day vulnerabilities that have been actively exploited. This significant update spans various products, with 723 flaws in Windows, 111 in Office, and others in SQL and Developer Tools. Among these, over 110 vulnerabilities have been classified as critical, highlighting the ongoing challenges in maintaining software security.
Details of the Patch Release
In this massive update, Microsoft tackled privilege escalation, remote code execution, and information disclosure vulnerabilities, which together account for nearly 90% of the fixes. The updates, which also include patches for 25 non-Microsoft CVEs, bring the total number of addressed vulnerabilities to 999. This follows a series of monthly updates where 457 flaws were fixed in August and 663 in July, reflecting an upward trend in the company’s vulnerability management efforts.
Jack Bicer, director of vulnerability research at Action1, emphasized the importance of prioritizing which vulnerabilities to address first, given the sheer volume of updates. He noted that IT and security teams must quickly identify which patches require immediate attention to effectively mitigate risks.
Exploited Zero-Day Vulnerabilities
The update includes two zero-day vulnerabilities that have raised significant concerns. CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, and CVE-2026-81963, an improper link resolution in the Windows Update Stack, both allow attackers to gain SYSTEM privileges. Microsoft has identified active exploitation attempts but has not disclosed further details about the attackers or the scope of these efforts.
Security researchers from Volexity, Proofpoint, and Airbus Helicopters, along with the Microsoft Threat Intelligence Center, contributed to identifying these critical vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply these patches by September 22, 2026.
Additional Notable Vulnerabilities
Other vulnerabilities addressed in this update include CVE-2026-55007 in Microsoft Exchange Server and CVE-2026-65669 in SQL Server, among others, with CVSS scores ranging from 8.1 to 9.8. These flaws pose significant risks, such as unauthorized code execution and privilege escalation over networks, underscoring the critical need for timely patch application.
According to TrendAI’s Zero Day Initiative, Microsoft has already patched 2,760 security flaws this year, showcasing the growing role of AI-assisted vulnerability detection. Experts like Satnam Narang of Tenable stress the need for organizations to prioritize patching based on the risk and exposure of these vulnerabilities to prevent potential breaches.
Despite the large number of vulnerabilities patched, the most significant threats remain limited in scope. Cybersecurity experts urge organizations to assess which vulnerabilities directly impact them and prioritize remediation efforts accordingly. As Tyler Reguly from Fortra notes, while the numbers are high, they reflect proactive security measures to mitigate risks before exploitation occurs.
