Microsoft’s latest security update is so large that it changes the scale of what Patch Tuesday normally means. The company has fixed 974 vulnerabilities across its software, including two Windows flaws already being exploited by attackers. The sheer size of the update makes prioritising the most dangerous weaknesses more important than simply installing every available fix.
• Microsoft patched 974 vulnerabilities in its September update
• Two Windows flaws are already being exploited
• Security teams face an unusually large patching workload
Windows accounts for 723 of the vulnerabilities, followed by 111 in Office and Office 2016, 62 in SQL and 22 in Developer Tools. More than 110 flaws have been rated critical, with privilege escalation, remote code execution and information disclosure making up the vast majority of the security issues. Microsoft also addressed 25 non-Microsoft CVEs, taking the total number of resolved vulnerabilities to 999.
• Windows received the largest share of fixes
• More than 110 vulnerabilities are rated critical
• Nearly 1,000 total security issues were addressed
The two exploited Windows vulnerabilities are particularly concerning. CVE-2026-85880 allows an attacker with code running in a low-privilege AppContainer to escape its sandbox and gain higher privileges, while CVE-2026-81963 affects the Windows Update Stack. Microsoft has confirmed exploitation in the wild, although it has not revealed who is behind the attacks or whether victims have been successfully compromised.
• Both zero-days are being actively exploited
• One flaw can enable privilege escalation from a sandbox
• Microsoft has not disclosed details about the attackers
The update also tackles several severe vulnerabilities affecting Microsoft Exchange Server, SQL Server, Windows Remote Desktop Services, DNS Server, DHCP Server and Windows Shell. Some carry CVSS scores as high as 9.8, highlighting the potential impact if they are successfully exploited. The two zero-days have also been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, with federal agencies required to apply the fixes by September 22.
• Several enterprise products contain high-severity flaws
• Some vulnerabilities carry a 9.8 CVSS score
• U.S. federal agencies face a September 22 deadline
September’s update follows 457 vulnerabilities patched in August and 663 in July, pushing Microsoft’s total for 2026 to more than 2,600 according to industry vulnerability tracking. The growing numbers do not necessarily mean every organisation faces the same level of danger, since exposure depends on which products are deployed and whether vulnerable systems are reachable by attackers. For businesses, the message is clear: identifying which flaws are exploitable in their own environments may now be just as important as patching quickly.
• Microsoft has patched more than 2,600 flaws this year
• Vulnerability counts have surged throughout 2026
• Organisations need to prioritise patches based on real-world exposure
Via: The Hacker News




















