Microsoft Patches Record 973 Flaws, Including Two Exploited Windows Zero-Days

Microsoft’s September 2026 Patch Tuesday addresses 973 vulnerabilities, with 113 rated critical and two already exploited in the wild, according to Cisco Talos. The massive update arrives amid a broader surge in security patches driven by automated vulnerability discovery tools.

Microsoft released its September 2026 Patch Tuesday updates, deploying fixes for a 973 vulnerabilities across its software ecosystem. Among the hundreds of fixes, 113 are rated critical, with remote code execution flaws dominating the highest-severity tiers. Cisco Talos reported that two of the targeted security holes are already being exploited by attackers in real-world attacks. This month’s total of 973 vulnerabilities is a sharp increase from the 163 flaws Microsoft fixed in its April 2026 Patch Tuesday, as previously reported.

Active Zero-Day Exploits Target Windows Update Stack and ALPC

The actively exploited flaws are CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, both carrying a CVSS score of 7.8.

Critical Remote Code Execution Flaws and High-Severity CVEs

Among the critical issues, 82 are remote code execution vulnerabilities. Several are rated 9.8 on the CVSS scale, including flaws in Windows DNS Server (CVE-2026-69730), Windows DHCP Server (CVE-2026-69845 and CVE-2026-72979), Skype for Business (CVE-2026-66302), Windows Imaging Component (CVE-2026-70296), Windows RRAS (CVE-2026-69590), Windows SSTP (CVE-2026-73009), Microsoft Failover Cluster (CVE-2026-73010), and Windows Graphics Component (CVE-2026-77493). Other notable fixes include a CVSS 9.0 elevation of privilege in Spring Cloud Azure (CVE-2026-69854) and a CVSS 9.6 SQL Server elevation of privilege (CVE-2026-65669). Azure Cosmos DB spoofing (CVE-2026-69857) and Windows Kerberos RCE (CVE-2026-69676) were also patched.

The release also covers multiple remote code execution flaws in Microsoft Excel (CVE-2026-81948, CVE-2026-81950, CVE-2026-81951, CVE-2026-81959, CVE-2026-81953) and an Outlook RCE (CVE-2026-78525). Additional fixes span Windows RRAS, RMCAST, DirectWrite, IP Helper, Media Foundation, Graphics Kernel, and other components.

Read more:  Завели бы такого? LG показала робота, который складывает белье и готовит завтраки

AI-Driven Vulnerability Discovery Supercharges Patch Volumes

The sheer scale of the September release reflects a broader shift across the cybersecurity industry. Sources familiar with Microsoft’s security operations indicate that the rapid increase in monthly patches is directly tied to automated security-focused AI models that are discovering flaws at an unprecedented pace. The company’s own AI system, MDASH, had identified 16 Windows vulnerabilities that were fixed in the May 2026 Patch Tuesday.

Microsoft Patch Tuesday Fixes 973 Flaws, Two Exploited
Photo: Technobezz

Earlier in the year, AI models developed by firms like Anthropic and OpenAI demonstrated the capability to find deep-seated weaknesses in major operating systems and web browsers within hours rather than weeks. Sources tell me that Microsoft will set another patch Tuesday record today, the third in just a few months. Microsoft typically patches around 100 flaws every month, but in June it set a new record of around 200 fixes. July’s patch Tuesday was even bigger, with Microsoft patching at least 570 security holes, almost triple the number of June’s record-breaking release. Microsoft engineers had a chance to catch their breath a bit in August when they plugged nearly 400 security vulnerabilities.

The Growing Patch Gap and Pressure on IT Teams

The rapid influx of hundreds of monthly security updates places immense strain on corporate IT departments. Enterprise administrators must thoroughly test patches before deployment to ensure updates do not disrupt internal business applications, creating a dangerous window known as the patch gap. IT admins typically have to test patches from Microsoft to ensure any fixes don’t interfere with critical business applications. This process can create what’s called a “patch gap” between a vulnerability being disclosed and people applying the fix. In an AI era of security vulnerabilities being rapidly discovered and disclosed, there’s a huge amount of pressure on businesses to close the patch gap. Anthropic discovered earlier this year that Mythos could even create working exploits for newly disclosed software vulnerabilities in a matter of hours, instead of weeks. This puts businesses at risk of being hit by an exploit if they don’t patch soon enough.

Read more:  Канадское агентство по инспекции пищевых продуктов приостановило действие лицензии Goodfood на безопасные пищевые продукты
The Microsoft logo
Photo: The Verge

As automated tools continue to uncover vulnerabilities faster than traditional deployment cycles can easily accommodate, security experts urge organizations to streamline their testing processes and apply critical updates immediately to mitigate the risk of active exploitation. When hundreds of vulnerabilities are now being discovered every month, time is very much of the essence.

Microsoft Patches Zero Day And More

Читайте также

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.