Cybersecurity

Microsoft Issues Record 974-Fix Security Update as Exploited Zero-Days Raise Patch Pressure

0

Microsoft has released its September 2026 security update with a record 974 vulnerability fixes, including two Windows flaws that have already been exploited in the wild.

The unusually large Patch Tuesday release covers Microsoft’s Windows operating systems and a broad range of enterprise products, including Office, SQL Server, Exchange Server, SharePoint, Azure and developer tools. Security researchers say the scale of the update creates another major patch-management challenge for organizations trying to determine which vulnerabilities require immediate attention.

The update includes 723 Windows vulnerabilities and 222 security bugs affecting Office, alongside fixes across Microsoft’s other product lines. Twenty of the vulnerabilities are considered potentially wormable because they can enable remote code execution without authentication or user interaction.

Two Zero-Days Are Already Being Exploited

The most urgent issues in the September release are two Windows vulnerabilities Microsoft says are being exploited.

The first, CVE-2026-85880, is a heap buffer-overflow vulnerability affecting Windows Advanced Local Procedure Call (ALPC). An attacker capable of executing code inside a low-privilege AppContainer could exploit the flaw to escape the sandbox and elevate privileges to SYSTEM level.

The second, CVE-2026-81963, affects the Windows Update Stack. It is an improper link-resolution vulnerability that can also allow a local attacker to elevate privileges to SYSTEM.

Microsoft has not publicly disclosed who is exploiting the two vulnerabilities or how many organizations may have been affected.

Both flaws have also been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, increasing the pressure on government organizations to deploy the fixes. Federal civilian agencies have until September 22 to apply the relevant patches.

Enterprise Products Are Also in the Crosshairs

The September update extends far beyond Windows desktops.

Among the vulnerabilities highlighted by security researchers are flaws affecting Exchange Server, SharePoint, SQL Server and Remote Desktop Services.

One Remote Desktop Services vulnerability, CVE-2026-69525, carries a reported CVSS score of 9.8 and can allow remote code execution over a network. Another SQL Server vulnerability, CVE-2026-65669, has a reported CVSS score of 9.6.

For organizations running Microsoft’s enterprise infrastructure, these vulnerabilities can represent a significantly greater concern than flaws affecting software that is not exposed to external networks.

Security teams therefore face the task of mapping Microsoft’s enormous patch list against their own infrastructure rather than treating every vulnerability equally.

Patch Volume Is Becoming a Security Problem of Its Own

The size of Microsoft’s latest release is significant because vulnerability volumes have risen sharply throughout 2026.

Microsoft addressed hundreds of vulnerabilities in previous monthly releases, but September’s batch is substantially larger. Security researchers have pointed out that organizations now face a growing challenge in separating vulnerabilities that require immediate remediation from those that can follow normal patching cycles.

The sheer number of fixes can create what security teams sometimes call a patch gap — the period between a vulnerability being disclosed and an organization successfully deploying the relevant fix.

That gap becomes particularly dangerous when attackers are already exploiting a vulnerability.

AI Is Accelerating Vulnerability Discovery

Another factor behind the growing volume of vulnerabilities is the increasing use of artificial intelligence in security research.

Researchers are increasingly using AI-assisted tools to identify weaknesses, analyze large codebases and develop proof-of-concept exploits. That can help defenders discover and fix vulnerabilities earlier, but it can also accelerate the process by which weaknesses are found and potentially weaponized.

The result is a more demanding environment for enterprise security teams: vulnerabilities can be discovered faster, patches can arrive in larger batches and attackers can potentially move more quickly once an exploitable weakness becomes public.

Prioritization Becomes More Important Than Patch Counts

Despite the record-breaking number, security researchers caution against treating the headline vulnerability count as an indication that every organization faces the same level of risk.

The more important questions are whether a vulnerable product is actually deployed, whether the affected component is exposed, whether exploitation is technically possible in the organization’s environment and whether attackers are already targeting the flaw.

For September, the two exploited Windows zero-days deserve particular attention because the threat is no longer theoretical.

Microsoft’s latest release ultimately illustrates a broader reality of modern enterprise security: the challenge is no longer simply finding vulnerabilities, but identifying the dangerous ones quickly enough to close the window before attackers can exploit them.

Boston Scientific Warns Cyberattack Could Hit 2026 Revenue and Profit Forecasts

Previous article

Qualcomm and Amazon Strike Major AI Chip Deal as Cloud Giants Seek Nvidia Alternatives

Next article

You may also like

Comments

Comments are closed.