Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and…

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft has released a massive update, closing nearly 1,000 security loopholes across its Windows systems and software. This is the company's largest single patch batch ever, surpassing its previous record from July of 570 vulnerabilities. This month's Patch Tuesday marks the 2,600th security update for the year, more than double Microsoft's previous record-setting year in 2020.

Among the 113 critical flaws fixed this month are two "zero-day" vulnerabilities actively being exploited. These flaws can enable attackers to elevate their privileges on Windows systems without any user interaction. Other significant critical flaws include CVE-2026-69730, a DNS weakness in Windows Server 2012 and Windows 10, and CVE-2026-69829, a remote code execution flaw in the Windows Shell with a CVSS base score of 9.8.

Security experts caution that many organizations are struggling to prioritize the time-consuming task of testing and deploying these frequent updates. Tyler Reguly, a security researcher, warns that it's crucial for companies to support their teams through these challenges, such as offering after-hours and weekend deployment options. However, not all vulnerabilities pose a significant threat to most organizations, according to Satnam Narang, a security researcher.

Despite the increasing number of vulnerabilities being patched, the number of threats affecting most organizations remains relatively low. Microsoft's AI-assisted vulnerability discovery aids in identifying these issues, but it's essential for organizations to understand which vulnerabilities apply to them and prioritize remediation based on risk context.

Written by urgent.news from KrebsOnSecurity's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at krebsonsecurity.com →

More in Tech

Batch Transaction - Testcases

Automated test coverage for the Batch transaction feature (XLS-56), grouped by the invariant or execution mode each test exercises with 189 tests.

More from Tuesday 8 September →