started · updated
Microsoft issues record 974 security patches, including two exploited zero-days
Microsoft has issued its largest-ever batch of security patches during the September 2026 Patch Tuesday, addressing at least 974 vulnerabilities across its product suite. This record-breaking volume is largely attributed to the company’s increasing use of artificial intelligence to accelerate the discovery of software flaws.
The update includes 723 vulnerabilities affecting Windows, 111 for Office, 62 for SQL Server, and 22 for various developer tools. Additionally, nine vulnerabilities were addressed for Exchange Server, including one with a CVSS rating of 9.3.
Two zero-day vulnerabilities are being actively exploited in the wild: CVE-2026-81963, which affects the Windows Update Stack, and CVE-2026-85880, which involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) mechanism. Both flaws allow attackers to escalate privileges to SYSTEM level. Security experts have noted that while AI is creating larger haystacks of discovered flaws, the number of critical, highly exploitable vulnerabilities remains manageable for organizations to prioritize.
Entities
Chrome · Exchange Server · Google · Microsoft · Office · SQL Server · Salvatore Gulizia · V8 · Windows
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The Chrome V8 vulnerability also affects other Chromium-based browsers including Edge, Brave, and Opera.
- [● 2 SOURCES] Microsoft released updates for Exchange Server addressing nine vulnerabilities, the highest rated at CVSS 9.3. www.frankysweb.de · cyberinsider.com
- [○ 1 SOURCE] The high number of vulnerabilities found is attributed to Microsoft's new internal AI-driven scanning system, MDASH. www.blogspan.net
- [● 5 SOURCES] Google patched a high-severity zero-day vulnerability in the Chrome V8 engine, identified as CVE-2026-85046. www.linux-magazin.de · www.presse-citron.net · www.independent.co.uk
- [● 13 SOURCES] Two Windows vulnerabilities, CVE-2026-85880 and CVE-2026-81963, are being actively exploited in the wild. cyberinsider.com · www.blogspan.net · cybernoz.com · australiancybersecuritymagazine.com.au · japan.zdnet.com · +7 more
- [○ 1 SOURCE] Google Chrome has transitioned to a two-week update cycle for desktop, Android, and iOS to improve security.
- [● 11 SOURCES] Microsoft released security updates in September 2026 addressing 974 CVEs, including 723 affecting Windows. cyberinsider.com · www.blogspan.net · cybernoz.com · australiancybersecuritymagazine.com.au · krebsonsecurity.com · +5 more
- [● 4 SOURCES] Researcher Salvatore Gulizia discovered the CVE-2026-85046 vulnerability. www.presse-citron.net · www.independent.co.uk
- [● 3 SOURCES] The surge in vulnerability discovery is attributed to the use of artificial intelligence for code auditing. cybernoz.com · world-today-journal.com · securityaffairs.com
- [● 4 SOURCES] CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) mechanism. australiancybersecuritymagazine.com.au · cyberinsider.com · www.security-insider.de · securityaffairs.com
- [● 2 SOURCES] The September update includes 111 vulnerabilities for Office and 62 for SQL products. cybernoz.com · cyberinsider.com
- [● 2 SOURCES] The September 2026 Patch Tuesday release includes 9 vulnerabilities for Exchange Server. cyberinsider.com · www.frankysweb.de