www.infosecurity-magazine.com 9 Sept 2026, 09:40 UTC

Microsoft Patches Record 974 CVEs Amid Exploited Windows Zero-Days

CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT has reported a record-breaking 974 CVEs addressed in its September 2026 Patch Tuesday, shattering the previous high of 570 CVEs. The August–September trend shows a sharp rise in patched flaws, with Windows accounting for 723 CVEs and Office for 111. The prior three months also show increases: 570 in July, 400 in August, then 974 in September, following Microsoft’s warning in July about a surge in updates driven in part by its use of agentic AI tools to discover zero-days.

With such volumes, security teams are urged to adopt a risk-based vulnerability management approach to prioritise the flaws posing the greatest risk to their environments.

Microsoft notes two zero-day flaws actively exploited at the time of the update: CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that could allow local privilege elevation when code is executed in a low-privilege AppContainer, and CVE-2026-81963, an improper link resolution before file access in Windows Update Stack that enables local privilege elevation by an authorised attacker. The update also contains 119 critical vulnerabilities.

Action1’s Jack Bicer highlights several prioritised flaws: CVE-2026-62878 (Windows DNS Server remote code execution, stack-based buffer overflow, severity 9.8), CVE-2026-62823 (Windows DHCP Server remote code execution, heap-based buffer overflow, 8.8), CVE-2026-62893 (Windows Deployment Services remote code execution, use-after-free, 9.8), CVE-2026-65789 (Windows DNS remote

code execution, use-after-free, 8.1), and CVE-2026-58231 (three critical vulnerabilities affecting Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform). Researchers note the need for rapid triage to determine which updates require immediate action.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline