ASX 2009,005.90
-14.20(-0.16%)
NIKKEI65,020.94
+806.46(+1.26%)
NIFTY 5023,897.70
+24.25(+0.10%)
HSI25,650.87
+427.66(+1.74%)
SHANGHAI3,930.116
-11.972(-0.30%)
Trending:US MarketsAI & SiliconUSA Jobs DeskFed PolicyCybersecurityGov & LawEntertainmentSports Wire

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days The Hacker News Why this month's Microsoft patch release is a doozy Ars Technica Microsoft Plugs Nearly 1,000 Security Holes Krebs on Security...

By Nexvoro Tech Wire
PUBLISHED WED, SEP 9, 2026 6:00 PM UTC6 MIN READ
CNBC Market Tracker • NASDAQ:MSFT
REAL-TIME QUOTE
Microsoft Corp
$468.50+4.10 (+0.88%)
Volume: 68.4M
52-Wk Range: $138.80 - 271.00

KEY POINTS

  • Primary coverage dispatched via Google News US Technology.
  • Signals noteworthy shifts in sector dynamics and operational developments.
  • Comprehensive factual details verified from official publication records.
  • Objective, non-partisan journalistic standards preserved.
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
PHOTO VIA GOOGLE NEWS US TECHNOLOGYNEXVORO EDITORIAL WIRE

Primary Journalistic Dispatch & Direct Reporting

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.

These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month. Along with Microsoft's fixes for 25 non-Microsoft CVEs, the update brings the total number of vulnerabilities resolved to 999.

September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July , 220 in June , and 161 in May .

In-Depth Developments & Factual Context

"At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first," Jack Bicer, director of vulnerability research at Action1, said . "With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle."

The two vulnerabilities that have come under active exploitation are listed below -

"An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880. "No additional user interaction is required."

Industry Impact & Strategic Analysis

Adam Barnett, lead software engineer at Rapid7, said all supported versions of Windows receive a patch for CVE-2026-81963, a move that "presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter."

Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an offensive security researcher at Airbus Helicopters, and the Microsoft Threat Intelligence Center (MSTIC) have been credited with the second bug.

The Windows maker said it has detected zero-day exploitation efforts targeting the flaws, but did not disclose any specifics as to who is behind them, the scale of such efforts, and if those attacks have successfully breached any victims.

Forward Outlook & Market Perspective

Per exposure management and vulnerability assessment platform Tenable, there have been seven privilege escalation flaws in the Windows Update Stack since 2022. However, CVE-2026-81963 is the first zero-day as well as the first to be exploited in the wild. As for CVE-2026-85880, it's the second to be weaponized as a zero-day since CVE-2023-21674 , which was addressed in January 2023.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.

Some of the other notable flaws patched by Microsoft are as follows -

According to TrendAI's Zero Day Initiative (ZDI), Microsoft has patched a total of 2,760 security flaws this year alone, indicating how artificial intelligence (AI)-assisted vulnerability discoveries are unlikely to slow down any time soon.

"September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026," Satnam Narang, senior staff research engineer at Tenable, said in a statement shared with The Hacker News.

"To put it into context, this month's Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year's total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go."

Reporting synthesized and verified under Nexvoro.tech editorial guidelines. Full primary records referenced via Google News US Technology.

Sponsored / Google AdSense SlotResponsive Leaderboard 728x90 / 970x250 (article-mid-story)
Reporting synthesized under Nexvoro.tech Editorial Standards • Referenced via Google News US Technology
Verified Dispatch
Related Tickers:#GOVERNMENT#US NEWS#GOOGLE

More Coverage in Government

View Topic Desk →
White House Press Pool Suspended as Major US Outlets Boycott Administration Over Media Ban
Government
Government3H AGO

White House Press Pool Suspended as Major US Outlets Boycott Administration Over Media Ban

Major US television networks and print publications have suspended pooled coverage of President Donald Trump following the exclusion of CNN, Politico, and MS NOW. The affected media organisations have filed a federal lawsuit against the administration, while the White House defends its actions and launches an independent streaming initiative.

BBC World7 min read
Midwestern Shifts Force GOP to Pivot From Offense to Defense in High-Stakes Senate Battles
Government
Government3H AGO

Midwestern Shifts Force GOP to Pivot From Offense to Defense in High-Stakes Senate Battles

Once confident about expanding their Senate majority, Republican strategists are now scrambling to protect traditional strongholds as economic pressures mount across the Midwest. President Donald Trump's economic agenda faces intense scrutiny from voters, altering the trajectory of key legislative races.

Politico Politics & Law6 min read