Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days: A Comprehensive Analysis of the Latest Vulnerability Patch


Microsoft has patched a record 974 vulnerabilities, including two exploited Windows zero-days, in a move that highlights the ongoing struggle to keep pace with the evolving threat landscape. As organizations struggle to address the sheer number of vulnerabilities that need to be patched, the importance of understanding which vulnerabilities apply to them and prioritizing remediation cannot be overstated.

  • Microsoft has patched 974 vulnerabilities, including two critical flaws that have been actively exploited in the wild.
  • 110 vulnerabilities have a critical severity rating, with three prominent types - privilege escalation, remote code execution, and information disclosure - accounting for nearly 90% of the flaws patched this month.
  • The two most egregious vulnerabilities, CVE-2026-85880 and CVE-2026-81963, have been actively exploited in the wild, allowing attackers to elevate privileges locally and gain SYSTEM privileges.
  • Microsoft aims to patch 2,760 security flaws this year alone, highlighting the challenges of keeping pace with the rapid evolution of vulnerabilities.
  • Experts emphasize the importance of understanding which vulnerabilities apply to an organization and prioritizing remediation based on risk context.
  • The absence of a correlating spike in active exploits so far has been noted by experts, who highlight the importance of proactive vulnerability management.



  • Microsoft has recently made headlines by addressing a staggering 974 vulnerabilities in its software portfolio, including two critical flaws that have been actively exploited in the wild. This record-breaking patch Tuesday update has sent shockwaves through the cybersecurity community, as it highlights the ongoing struggle to keep pace with the ever-evolving threat landscape.

    The latest batch of patches from Microsoft spans its entire software portfolio, including Windows, Office, SQL, and Developer Tools, with a total of 110 vulnerabilities assigned a critical severity rating. Three prominent vulnerability types - privilege escalation, remote code execution, and information disclosure - account for nearly 90% of the flaws patched this month. This indicates that the most critical vulnerabilities are centered around these three types, which can have devastating consequences for organizations that fail to address them promptly.

    The two most egregious vulnerabilities that have been actively exploited in the wild are CVE-2026-85880 and CVE-2026-81963. The former, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC), allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges. The latter, an improper link resolution vulnerability in the Windows Update Stack, enables an attacker to elevate privileges locally and gain SYSTEM privileges as well. Both of these vulnerabilities have already been spotted in the wild, with attackers exploiting them to gain unauthorized access to systems.

    Microsoft has taken a proactive approach to address these vulnerabilities, patching them through a comprehensive update that brings the total number of vulnerabilities resolved to 999. This update is part of a broader effort to address the ever-growing number of vulnerabilities in its software portfolio, with Microsoft aiming to patch a total of 2,760 security flaws this year alone.

    The sheer scale of the update has prompted experts to acknowledge the challenges of keeping pace with the rapid evolution of vulnerabilities. "At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first," said Jack Bicer, director of vulnerability research at Action1. "With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle."

    As organizations struggle to keep up with the rapid pace of vulnerability patches, the importance of understanding which vulnerabilities actually apply to them cannot be overstated. "It's critical for organizations to understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable over the internet, and prioritize remediation based on this risk context," said Tyler Reguly, associate director of Security R&D at Fortra.

    Despite the overwhelming number of vulnerabilities that need to be addressed, the absence of a correlating spike in active exploits so far has been noted by experts. "I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning," said Reguly. "This is not a Microsoft specific problem. We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we're reducing the attack surface before attackers get a chance to find and utilize the vulnerabilities."

    The impact of this patch Tuesday update will be felt across the cybersecurity community, with experts highlighting the importance of proactive vulnerability management. As organizations continue to grapple with the ever-evolving threat landscape, it is essential that they prioritize vulnerability management and take a proactive approach to addressing the vulnerabilities that have been patched this month.

    Microsoft has patched a record 974 vulnerabilities, including two exploited Windows zero-days, in a move that highlights the ongoing struggle to keep pace with the evolving threat landscape. As organizations struggle to address the sheer number of vulnerabilities that need to be patched, the importance of understanding which vulnerabilities apply to them and prioritizing remediation cannot be overstated.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Microsoft-Patches-Record-974-Flaws-Including-Two-Exploited-Windows-Zero-Days-A-Comprehensive-Analysis-of-the-Latest-Vulnerability-Patch-ehn.shtml

  • https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85880

  • https://www.cvedetails.com/cve/CVE-2026-85880/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81963

  • https://www.cvedetails.com/cve/CVE-2026-81963/


  • Published: Wed Sep 9 02:02:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us