Tag

Patch Tuesday

All articles tagged with #patch tuesday

Microsoft pushes emergency Windows 11 patch after Patch Tuesday glitches
technology23 days ago

Microsoft pushes emergency Windows 11 patch after Patch Tuesday glitches

Microsoft released an out-of-band emergency patch (KB5129194) for Windows 11 26H1 to fix two actively exploited zero-days and hundreds of other flaws from September’s Patch Tuesday. The fix comes a week after the major update caused issues with Remote Desktop Services, some USB audio devices, and Hyper-V Linux VMs; although it resolves several USB audio problems and is cumulative with September updates, some USB Audio Class 1.0 devices may still fail to start or produce sound. Users are urged to install the latest update promptly. The two zero-days addressed were CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (ALPC).

Microsoft pushes emergency Windows 11 fix to contain patch Tuesday fallout
technology24 days ago

Microsoft pushes emergency Windows 11 fix to contain patch Tuesday fallout

Microsoft released an emergency out-of-band update to fix bugs introduced by its record September Patch Tuesday, addressing Remote Desktop, USB audio, and Hyper-V issues across Windows 11 versions 26H1, 25H2, and 24H2 and related Windows Server LTSC/2022/2025 releases; Microsoft notes that out-of-band fixes have become more common this year.

September Patch Tuesday Breaks Remote Desktop on Windows Servers
technology27 days ago

September Patch Tuesday Breaks Remote Desktop on Windows Servers

After September Patch Tuesday, Windows Server 2019/2022/2025 systems running Remote Desktop Services can experience freezes where new RDP connections hang and existing sessions can’t log off; symptoms appear hours after reboot and are linked to KB5122876/KB5122882/KB5122871, with Event IDs 20498 and 6005 pointing to a deadlock in the RDPSERVERBASE!WDLIB_Close routine. Microsoft hasn’t provided an official fix yet. Workarounds include rolling back the updates (where feasible), toggling a feature flag to disable faulty audio redirection, or forcing RDP to TCP only; admins should test patches on non-critical hosts and maintain rollback plans until an official fix is released.

Patch Tuesday Surges, TV Espionage, and a Wave of Identity Breaches Dominate This Week in Security
security27 days ago

Patch Tuesday Surges, TV Espionage, and a Wave of Identity Breaches Dominate This Week in Security

This week’s security digest highlights a record Patch Tuesday with about 1,000 fixes, including two zero-days actively exploited for privilege escalation and a near-10 CVSS remote code execution flaw in Windows, plus alarming reports on LG smart TVs collecting telemetry and ad data, the reappearance of the Shai-Halud worm in NPM, a continuing Boston Scientific ransomware impact, Magento/Adobe Commerce vulnerabilities being exploited in the wild, Microsoft moving to block emails from unpatched Exchange servers, Nimbus Manticore phishing campaigns, and a massive 150-million-driver-license data breach tied to IDScan, with the American Meteor Society briefly knocked offline by ransomware.

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days
security1 month ago

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days

Microsoft’s September Patch Tuesday patches a record 974 vulnerabilities across Windows, Office, SQL, and Developer Tools, including two zero-days actively exploited in the wild (CVE-2026-85880 and CVE-2026-81963). The fixes bring the total resolved vulnerabilities to 999 (including 25 non-Microsoft CVEs), with over 110 rated critical and the bulk involving privilege escalation, remote code execution, and information disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog, ordering federal agencies to apply updates by September 22, 2026. Despite the high volume, attackers’ exploitation rates remain limited, so organizations should prioritize remediation based on exposure and relevance.

Patch Tuesday Sets a 974-CVE Record as Microsoft and Adobe Push Urgent Updates
technology1 month ago

Patch Tuesday Sets a 974-CVE Record as Microsoft and Adobe Push Urgent Updates

Microsoft’s Patch Tuesday breaks a record with 974 CVEs across its products, including two zero-days already being exploited (CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update Stack); the US CISA added them to its Known Exploited Vulnerabilities catalog with patch deadlines. Adobe followed with 172 CVEs across 10 bulletins, including the Magento/Adobe Commerce zero-day StyleSmuggler (CVE-2026-75650) under active abuse targeting online shops. The release also highlights Exchange Server vulnerabilities (CVE-2026-55007) as wormable and notes ongoing chatter about a Chromium-based V8 flaw (CVE-2026-85046) without a Microsoft advisory, underscoring urgency to patch across ecosystems.

technology1 month ago

Microsoft Stages Massive Patch Tuesday as AI Aids Historic Vulnerability Sweep

Microsoft released its largest patch batch ever, fixing at least 974 vulnerabilities across Windows and related software, with AI-assisted vulnerability discovery contributing to the surge and pushing this year’s total past 2,600. The update includes two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880) and 113 critical flaws, notably CVE-2026-69730 (Windows DNS) and CVE-2026-69829 (Windows Shell). Security experts caution that patch volume complicates prioritization and testing for organizations, underscoring the need for careful risk-based remediation and potentially after-hours deployment. The article also notes broader AI-driven patch increases across the industry and urges admins to follow per-patch guidance from sources like SANS and AskWoody.

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting
technology1 month ago

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting

Microsoft's September patch release fixes a record ~972 vulnerabilities (997 with Edge/Chromium), including 112 critical flaws and two zero-days in Windows Update and Windows Local Procedure; AI-assisted vulnerability discovery is driving these record numbers as the industry braces for AI-enabled exploits, though active exploitation remains limited so far.

Microsoft fixes 966 flaws in September 2026 Patch Tuesday, including two zero-days
technology1 month ago

Microsoft fixes 966 flaws in September 2026 Patch Tuesday, including two zero-days

Microsoft’s September 2026 Patch Tuesday addresses 966 vulnerabilities across a wide range of products, including two zero-days. Flaws span .NET, ASP.NET Core, Windows components (DNS, Kerberos, HTTP.sys, Win32K, etc.), Office, Exchange Server, SQL Server, Azure services, PowerShell, Visual Studio, and more. Flaws include remote code execution, elevation of privilege, information disclosure, and denial-of-service vectors, with several critical issues affecting important attack surfaces. Organizations should apply these patches promptly to reduce risk from both the two zero-days and the large variety of other vulnerabilities disclosed.

AI-powered patch blitz breaks another Patch Tuesday record
tech1 month ago

AI-powered patch blitz breaks another Patch Tuesday record

Microsoft is set to break another Patch Tuesday record as AI-driven vulnerability discovery (from Anthropic Mythos and OpenAI) uncovers flaws across Windows and other software, driving monthly fixes from roughly 100 to 200 in June, at least 570 in July, nearly 400 in August, and over 650 in September, highlighting the patch pressure on IT admins and the risk of a growing patch gap.

Windows 11 consolidates updates into a single monthly reboot to cut interruptions
technology1 month ago

Windows 11 consolidates updates into a single monthly reboot to cut interruptions

Microsoft says Windows 11 versions 24H2/25H2/26H1 will bundle driver updates, .NET updates, and firmware updates with the monthly security update, so a device restarts only once per month starting with July 28, 2026 updates and rolling out via August 14 Patch Tuesday. The bundled updates appear under Available updates and will install together on the monthly cycle; exceptions include Defender/AI/critical/expedited driver updates and emergency fixes that install immediately. Users can pause updates up to 35 days, and can restart earlier if desired. The change aims to reduce the long-standing multiple-restart interruptions of Windows Update.

Microsoft urges Windows 11 users to update within 3 days as 400+ fixes roll out
technology1 month ago

Microsoft urges Windows 11 users to update within 3 days as 400+ fixes roll out

Microsoft’s August 2026 Patch Tuesday delivers a Windows 11 update with 400+ fixes (421 across Edge, Teams, and other products), including several critical remote code execution and privilege-elevation fixes. The company warns users to install within three days and to verify they’re on Build 26200.9168 (25H2) or 26100.9168 (24H2) before updating; KB5121003 may require up to two reboots due to Secure Boot.

NightmareEclipse Unleashes Windows Defender Zero-Day Ahead of Patch Tuesday
security1 month ago

NightmareEclipse Unleashes Windows Defender Zero-Day Ahead of Patch Tuesday

Security researcher NightmareEclipse has published ShieldBreak, a new Windows Defender zero-day that allegedly lets attackers gain full control of a Windows device and may bypass the RoguePlanet patch (CVE-2026-50656). Microsoft is investigating but has not confirmed the claims; external researchers say the POC is legitimate. Tests reportedly work on Windows 11 25H2, Windows Server 2025, and even Windows 10. The disclosure comes ahead of Patch Tuesday, continuing the feud between Microsoft and the researcher over Windows security.