Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days

1 min read
Source: The Hacker News
Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days
Photo: The Hacker News
TL;DR Summary

Microsoft’s September Patch Tuesday patches a record 974 vulnerabilities across Windows, Office, SQL, and Developer Tools, including two zero-days actively exploited in the wild (CVE-2026-85880 and CVE-2026-81963). The fixes bring the total resolved vulnerabilities to 999 (including 25 non-Microsoft CVEs), with over 110 rated critical and the bulk involving privilege escalation, remote code execution, and information disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog, ordering federal agencies to apply updates by September 22, 2026. Despite the high volume, attackers’ exploitation rates remain limited, so organizations should prioritize remediation based on exposure and relevance.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

5 min

vs 6 min read

Condensed

91%

1,05896 words

Want the full story? Read the original article

Read on The Hacker News