Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days

Microsoft’s September Patch Tuesday patches a record 974 vulnerabilities across Windows, Office, SQL, and Developer Tools, including two zero-days actively exploited in the wild (CVE-2026-85880 and CVE-2026-81963). The fixes bring the total resolved vulnerabilities to 999 (including 25 non-Microsoft CVEs), with over 110 rated critical and the bulk involving privilege escalation, remote code execution, and information disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog, ordering federal agencies to apply updates by September 22, 2026. Despite the high volume, attackers’ exploitation rates remain limited, so organizations should prioritize remediation based on exposure and relevance.
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days The Hacker News
- Why this month’s Microsoft patch release is a doozy Ars Technica
- Microsoft’s September updates fix a record 973 security flaws PCWorld
- Microsoft Plugs Nearly 1,000 Security Holes Krebs on Security
- Microsoft breaks another patch Tuesday record The Verge
Reading Insights
0
0
5 min
vs 6 min read
91%
1,058 → 96 words
Want the full story? Read the original article
Read on The Hacker News