Microsoft Patches Record 974 Flaws, Two Already Being Exploited
Microsoft’s September Patch Tuesday fixes 974 security flaws across its products, according to the company’s release notes. Attackers were already exploiting two of them before the patches landed on Tuesday. Both zero-days allow an attacker with a foothold on a Windows machine to gain higher privileges.
One vulnerability sits in the Windows Update Stack (CVE-2026-81963), and the other is found in the Advanced Local Procedure Call component (CVE-2026-85880). There is currently no public detail on who is exploiting them or their extent, as reported by Dan Goodin for Ars Technica.
A Breaking Record
Dustin Childs of the Zero Day Initiative, reviewing every monthly release, called this a new record. While Childs doubts attackers have hijacked the update mechanism, he suspects they will pair the Update Stack bug with a code execution flaw to spread malware or ransomware. He recommends quick patching on both accounts.
Rapid Growth in Patches
Counting is never exact, but Microsoft’s notes list 974 of its own CVEs and republish 25 more from other vendors. Childs counts 972 new ones, or 997 including fixes for Chromium, the Google engine inside Edge. More than 110 are rated critical, Microsoft’s highest severity level.
These totals have climbed rapidly. Microsoft fixed roughly 570 flaws in July’s record release and about 620 in August. By Ars Technica’s count, they’ve now fixed 2,760 this year, more than double last year’s total.
AI-Assisted Vulnerability Discovery
Childs concluded by referencing a phrase from his military days: “embrace the suck.” He congratulated Microsoft’s "security gnomes" for their patch rate but warned that AI-assisted vulnerability discovery shows no signs of slowing down.
Top Patch Priorities
Beyond the zero-days, Childs highlighted:
- A flaw in Exchange Server (CVE-2026-55007) allowing code execution through a rigged Visio attachment.
- An issue in Outlook’s desktop version (CVE-2026-78509), also rated 9.8 out of 10, triggered by previewing an email.
- A vulnerability (CVE-2026-69525) with a similar reliability rating in Remote Desktop Services.
- A flaw (CVE-2026-80097) in Microsoft Authenticator for Android needing further work as it abuses the authentication system itself.
- Twenty wormable bugs, including flaws in core services like DHCP, DNS, Netlogon, Message Queuing and SMB.