MICROSOFT has released a record-breaking Patch Tuesday, issuing updates to fix at least 974 security holes across Windows and related software. The batch dwarfs July’s previous record of 570 vulnerabilities and brings the year’s total to more than 2,600. The company notes that artificial intelligence is aiding vulnerability discovery, though security experts caution that prioritising and deploying fixes remains a human, process-heavy challenge for many organisations.
Among the fixes, two zero-days are being actively exploited: CVE-2026-81963 and CVE-2026-85880, both enabling privilege escalation on Windows. Overall, 113 of the addressed flaws are rated critical—meaning they could allow malware or attackers to take control of a vulnerable system with little user interaction.
Notable flaws include CVE-2026-69730, a DNS weakness affecting Windows Server 2012 onward and Windows 10, which Microsoft says could be exploited by unauthenticated attackers simply by sending a crafted packet; and CVE-2026-69829, a remote code execution vulnerability in Windows Shell with a CVSS base score of 9.8.
The article emphasises the ongoing pressure on enterprise IT teams to test and rollout updates, and notes that while the vulnerability count is rising, the proportion that affect most organisations remains relatively small.