Close Menu
NCIJ Network NCIJ Network
    What's Hot

    LIV Golf: Players free to leave after competition files for bankruptcy protection

    September 8, 2026

    Will UK sanctions have any impact on Israel’s ‘settler terrorists’ in West Bank? | Israel

    September 8, 2026

    UK to force Apple and Google to block explicit images on children’s smartphones | Internet safety

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • LIV Golf: Players free to leave after competition files for bankruptcy protection
    • Will UK sanctions have any impact on Israel’s ‘settler terrorists’ in West Bank? | Israel
    • UK to force Apple and Google to block explicit images on children’s smartphones | Internet safety
    • OpenAI says it cracked 90-year-old maths problem in 88 hours
    • Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
    • StablecoinX Names New CEO to Oversee ENA Treasury
    • Scientists discover a powerful new antivenom hidden in rattlesnake blood
    • Yemen’s Houthis Attack Saudi Arabia’s Oil Infrastructure
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days.

    The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges.

    “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory.

    Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out.

    The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in Windows Update Stack, the components used for Windows update installation. The vulnerability also allows local attackers to elevate their privileges to System.

    As Narang notes, this is the first Update Stack security weakness to be flagged as a zero-day of the seven flaws resolved in the component over the past five years.

    Advertisement. Scroll to continue reading.

    Overall, Microsoft rolled out patches for 723 flaws in Windows and fixed 222 security bugs in its Office suite, including 111 in Office 2016 for this month’s Patch Tuesday. Multiple security issues were also addressed in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9).

    Also as part of its September 2026 Patch Tuesday updates, Microsoft rolled out fresh Servicing Stack Updates (SSU), which are classified as critical updates. They apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.

    Some of the issues that deserve special attention include CVE-2026-55007 (remote code execution (RCE) in Exchange Server), CVE-2026-80097 (elevation of privilege (EoP) in Authenticator), CVE-2026-69465 (RCE in SharePoint, CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), ZDI’s Dustin Childs says.

    According to Childs, 20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction.

    “One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang said.  

    “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context,” he added.

    According to Fortra associate director Tyler Reguly, the large number of newly released patches, which is not a Microsoft-specific trend, shows that proactive vendors are keen on reducing the attack surface.

    “Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated,” Reguly said.

    Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Related: The Hidden Instructions That Can Hijack AI Agents

    Related: SAP Patches Critical Extended Passport Processing Vulnerability

    Related: MikroTik Patches Critical Flaws Chained to Hack Routers

    Exploited including Microsoft Patches record Vulnerabilities ZeroDays
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another Account

    Microsoft releases Windows 10 KB5122878 extended security update

    Windows 11 cumulative updates KB5124008 & KB5122880 released

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    C-sections hit record high in Wales as mothers warn of support gap

    Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    LIV Golf: Players free to leave after competition files for bankruptcy protection

    September 8, 2026

    Will UK sanctions have any impact on Israel’s ‘settler terrorists’ in West Bank? | Israel

    September 8, 2026

    UK to force Apple and Google to block explicit images on children’s smartphones | Internet safety

    September 8, 2026

    OpenAI says it cracked 90-year-old maths problem in 88 hours

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    LIV Golf: Players free to leave after competition files for bankruptcy protection

    September 8, 2026

    Will UK sanctions have any impact on Israel’s ‘settler terrorists’ in West Bank? | Israel

    September 8, 2026

    UK to force Apple and Google to block explicit images on children’s smartphones | Internet safety

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.