Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Merz’s SPD partners rebel after far-right rout – POLITICO

    September 9, 2026

    Polanski calls for report on ecosystem collapse to be published in full | Zack Polanski

    September 9, 2026

    Reform UK says migrant deal was ratified by far-right National Rally president | France

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Merz’s SPD partners rebel after far-right rout – POLITICO
    • Polanski calls for report on ecosystem collapse to be published in full | Zack Polanski
    • Reform UK says migrant deal was ratified by far-right National Rally president | France
    • Google DeepMind alumni are building tools to accelerate fusion power for the grid
    • Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
    • Malone Lam Pleads Guilty in $245M Crypto Theft Case
    • Southeast Asia Shifts Taiwan Stance as China Rises
    • Jessica Pegula beats Emma Navarro to set up Sabalenka semifinal at US Open | Tennis
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 9, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.

    These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month. Along with Microsoft’s fixes for 25 non-Microsoft CVEs, the update brings the total number of vulnerabilities resolved to 999.

    September’s record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May.

    “At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first,” Jack Bicer, director of vulnerability research at Action1, said. “With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”

    Cybersecurity

    The two vulnerabilities that have come under active exploitation are listed below –

    • CVE-2026-85880 (CVSS score: 7.8) – A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges
    • CVE-2026-81963 (CVSS score: 7.8) – An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges

    “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system,” Microsoft said in an advisory for CVE-2026-85880. “No additional user interaction is required.”

    Adam Barnett, lead software engineer at Rapid7, said all supported versions of Windows receive a patch for CVE-2026-81963, a move that “presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter.”

    Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an offensive security researcher at Airbus Helicopters, and the Microsoft Threat Intelligence Center (MSTIC) have been credited with the second bug.

    The Windows maker said it has detected zero-day exploitation efforts targeting the flaws, but did not disclose any specifics as to who is behind them, the scale of such efforts, and if those attacks have successfully breached any victims.

    Per exposure management and vulnerability assessment platform Tenable, there have been seven privilege escalation flaws in the Windows Update Stack since 2022. However, CVE-2026-81963 is the first zero-day as well as the first to be exploited in the wild. As for CVE-2026-85880, it’s the second to be weaponized as a zero-day since CVE-2023-21674, which was addressed in January 2023.

    The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026.

    Some of the other notable flaws patched by Microsoft are as follows –

    • CVE-2026-55007 (CVSS score: 8.1) – A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network
    • CVE-2026-80097 (CVSS score: 8.6) – An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally
    • CVE-2026-69465 (CVSS score: 8.8) – A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network
    • CVE-2026-65669 (CVSS score: 9.6) – An injection vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network
    • CVE-2026-69525 (CVSS score: 9.8) – A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network
    • CVE-2026-69595 (CVSS score: 9.8) – A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows an unauthorized attacker to execute code over a network
    • CVE-2026-69730 (CVSS score: 9.8) – A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network
    • CVE-2026-69829 (CVSS score: 9.8) – A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network
    • CVE-2026-72979 (CVSS score: 9.8) – A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network

    According to TrendAI’s Zero Day Initiative (ZDI), Microsoft has patched a total of 2,760 security flaws this year alone, indicating how artificial intelligence (AI)-assisted vulnerability discoveries are unlikely to slow down any time soon.

    “September’s Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026,” Satnam Narang, senior staff research engineer at Tenable, said in a statement shared with The Hacker News.

    Cybersecurity

    “To put it into context, this month’s Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year’s total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go.”

    Despite the massive batch of patches, the number of vulnerabilities that are expected to impact most organizations remains quite low, not to mention the absence of a correlating spike in active exploits so far. Narang added that it’s critical for organizations to understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable over the internet, and prioritize remediation based on this risk context.

    “I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning,” Tyler Reguly, associate director of Security R&D at Fortra, said.

    “This is not a Microsoft specific problem. We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we’re reducing the attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence.

    Exploited flaws including Microsoft Patches record Windows ZeroDays
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Burnham urged to tackle inequality with policies including wealth tax | Economic policy

    Hackers Return $263 Million Stolen From Liquid Network

    The Hidden Instructions That Can Hijack AI Agents

    FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

    What It Took to Reach 1 Billion Build Manifests

    CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Merz’s SPD partners rebel after far-right rout – POLITICO

    September 9, 2026

    Polanski calls for report on ecosystem collapse to be published in full | Zack Polanski

    September 9, 2026

    Reform UK says migrant deal was ratified by far-right National Rally president | France

    September 9, 2026

    Google DeepMind alumni are building tools to accelerate fusion power for the grid

    September 9, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Merz’s SPD partners rebel after far-right rout – POLITICO

    September 9, 2026

    Polanski calls for report on ecosystem collapse to be published in full | Zack Polanski

    September 9, 2026

    Reform UK says migrant deal was ratified by far-right National Rally president | France

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.