VYPR
patchPublished Sep 8, 2026· 3 sources

Microsoft Releases Record-Breaking 974 Security Updates, Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday addresses a record 974 vulnerabilities, including two zero-days under active exploitation, highlighting the growing challenge of patch management.

Microsoft Corp. has issued an unprecedented batch of 974 security updates, shattering its previous record for a single Patch Tuesday release. This massive update addresses numerous vulnerabilities across its Windows operating systems and other software, underscoring the escalating complexity of software security.

The sheer volume of patches released this month surpasses Microsoft's previous record of 570 set in July 2026, bringing the year-to-date total to over 2,600 vulnerabilities. This figure more than doubles the company's previous record-setting year in 2020, with three months still remaining in 2026.

Among the most critical fixes are two "zero-day" vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which were actively exploited in the wild before being patched. Both flaws allow attackers to elevate their privileges on compromised Windows systems, posing a significant immediate threat.

In total, 113 of the vulnerabilities addressed were rated "critical," meaning they could be exploited by malware or attackers to gain complete control over a vulnerable Windows machine, often with minimal user interaction. Notable critical flaws include CVE-2026-69730, a DNS weakness affecting Windows Server and Windows 10, which Microsoft warns is likely to be exploited due to its ease of abuse. Another severe vulnerability, CVE-2026-69829, is a Windows Shell remote code execution flaw with a CVSS score of 9.8, exploitable with low complexity and no user interaction.

Microsoft attributes the increased pace of vulnerability discovery, in part, to artificial intelligence. However, security experts caution that while AI aids in finding flaws, the human-intensive processes of testing and deploying these patches remain a significant challenge for organizations. Tyler Reguly of Fortra highlights the strain on IT teams, emphasizing the need for careful planning and support for staff working extended hours to deploy updates.

Satnam Narang of Tenable notes that while the number of discovered vulnerabilities is rising, the number that will actually affect most organizations remains relatively low. He stresses the importance of prioritizing remediation based on risk context, focusing on vulnerabilities that are reachable and exploitable within a specific environment.

For regular Windows users, the advice remains to keep Windows Update enabled and to install patches promptly, as letting them accumulate can lead to larger, more disruptive update processes. Enterprise administrators are advised to monitor resources like askwoody.com for potential issues arising from the new patches, and the SANS Internet Storm Center offers detailed breakdowns of the updates by severity.

The trend of massive patch releases is not unique to Microsoft, with other major software vendors also reporting increased patch cadence, often crediting AI-assisted research. This escalating volume presents a continuous challenge for cybersecurity professionals tasked with maintaining secure systems in the face of an ever-growing threat landscape.

This latest report from Dark Reading confirms Microsoft's September Patch Tuesday addresses a record-breaking 974 CVEs, slightly exceeding previous counts. It reiterates the critical nature of two actively exploited vulnerabilities and highlights an additional 58 that are highly likely to be exploited, underscoring the urgency for organizations to apply these patches.

This updated report from CyberScoop clarifies that Microsoft's September Patch Tuesday addresses a total of 974 vulnerabilities, a slight increase from the 973 previously reported. The article also highlights that while AI is accelerating vulnerability discovery, there hasn't been a corresponding surge in actively exploited zero-days, a point echoed by multiple security researchers quoted in the piece.

Synthesized by Vypr AI