< Back to all clusters
[TECHNOLOGY] · United States · 21 sources

started · updated

Microsoft issues record 974 security patches, including two exploited zero-days

Microsoft has issued its largest-ever batch of security patches during the September 2026 Patch Tuesday, addressing at least 974 vulnerabilities across its product suite. This record-breaking volume is largely attributed to the company’s increasing use of artificial intelligence to accelerate the discovery of software flaws.

The update includes 723 vulnerabilities affecting Windows, 111 for Office, 62 for SQL Server, and 22 for various developer tools. Additionally, nine vulnerabilities were addressed for Exchange Server, including one with a CVSS rating of 9.3.

Two zero-day vulnerabilities are being actively exploited in the wild: CVE-2026-81963, which affects the Windows Update Stack, and CVE-2026-85880, which involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) mechanism. Both flaws allow attackers to escalate privileges to SYSTEM level. Security experts have noted that while AI is creating larger haystacks of discovered flaws, the number of critical, highly exploitable vulnerabilities remains manageable for organizations to prioritize.

Entities

Chrome · Exchange Server · Google · Microsoft · Office · SQL Server · Salvatore Gulizia · V8 · Windows

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

3 days ago
3 days ago
4 days ago