arstechnica.com 8 Sept 2026, 21:11 UTC

Microsoft’s Record 972-Flaw Patch Haul Includes Two Zero-Days

CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT’S September patch release is described as a record by Ars Technica, fixing about 972 vulnerabilities, with 112 rated as high-severity critical. The piece notes that two months earlier Microsoft set a prior record with 570 fixes. When including the Chromium-edge fixes ported into Edge, the total reaches 997.

The article places these numbers in the context of a broader industry trend of record vulnerability disclosures, alongside an open letter from major tech firms warning of a narrowing patch window ahead of AI-assisted attack waves. It also cites Dustin Childs of the Zero Day Initiative, who calls this the “new normal” for vulnerability discovery, while cautioning that, so far, there has not been a clear spike in active exploits.

Among the notable flaws highlighted are two zero-days: CVE-2026-81963 and CVE-2026-85880, affecting the Windows Update service and the Windows Advanced Local Procedure, with no public information on exploitation or breadth.

Further items include CVE-2026-55007 in Exchange Server, enabling remote code execution via a malicious Visio attachment in an email; CVE-2026-80097, a local privilege escalation in Microsoft Authenticator; CVE-2026-69465, a cluster of around 17 SharePoint vulnerabilities permitting remote code execution; CVE-2026-65669, a SQL Server privilege-escalation flaw exploitable through SQL Copilot; and CVE-2026-69525, a remote code execution issue in Remote Desktop Services rated 9.8.

The researcher notes many vulnerabilities were wormable, capable of spreading machine to machine without user interaction. The article also discusses the debate over AI-assisted vulnerability hunting, contrasting concerns about false positives and cost with claims of record bug discovery across the industry.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline