Microsoft Fixes 974 Flaws in Record Patch Tuesday
Microsoft’s record September Patch Tuesday fixes 974 vulnerabilities, including two exploited zero-days. Here’s what IT teams should prioritize. The post Microsoft Fixes 974 Flaws in Record Patch Tuesday appeared first on TechRepublic .
Microsoft's September 2026 Patch Tuesday set a record by addressing 974 security flaws, including two zero-day vulnerabilities that have already been exploited. The vulnerabilities affect various components, with 723 impacting Windows and 111 targeting Office products. Security researchers suggest that Microsoft's use of AI-assisted tools may contribute to the high number of vulnerabilities discovered.
Two vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are classified as actively exploited and can allow attackers to gain SYSTEM-level privileges. These should be prioritized by IT teams. Additionally, 20 vulnerabilities are potentially wormable, with CVE-2026-69730, a DNS server flaw, being particularly concerning. IT teams should focus on patching or mitigating these high-risk vulnerabilities first, followed by other exposed infrastructure components like DHCP, Remote Desktop Services, and Exchange Server.
Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Microsoft Breaks Another Patch Tuesday Record it.slashdot.org
- Microsoft breaks another patch Tuesday record theverge.com
- Microsoft's September 2026 Patch Tuesday fixes a record ~972 vulnerabilities, bringing its total flaws patched in 2026 to 2,760, more than double from 2025 (Dan Goodin/Ars Technica) arstechnica.com