Microsoft Plugs Nearly 1,000 Security Holes

Microsoft has just released a massive patch bundle, plugging nearly 1,000 security holes in its Windows operating systems and other software. This is the company’s biggest single patch batch ever, eclipsing its previous record set just last month when it issued updates for at least 570 vulnerabilities.

The sheer number of flaws addressed this time around is staggering – over 2,600 so far this year alone, more than twice Microsoft’s previous record-setting patch year in 2020. And with three months still to go, the pace shows no signs of slowing down. But what does it all mean for users and organizations?

The updates address a range of critical vulnerabilities, including two “zero-day” flaws that are already being actively exploited by attackers. These two bugs – CVE-2026-81963 and CVE-2026-85880 – allow an attacker to elevate their privileges on Windows systems, essentially giving them carte blanche to wreak havoc on affected machines.

But Microsoft’s not the only one shipping massive patch bundles lately. Other major software companies like Adobe, Cisco, Google, Mozilla, and Oracle have all recently credited AI-assisted research with increasing their patch cadence and volume. So what’s behind this surge in vulnerabilities? And how can organizations keep up?

According to Tyler Reguly, associate director of security research and development at Fortra, one key challenge is testing patches before deploying them across an organization. “It’s time to put our CISOs and CSOs on notice,” he said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment?”

Of course, regular Windows users don’t need to test patches before deploying them – but they still need to keep their systems up to date by periodically opening Windows Update or else facing nag notices about pending updates. And with these patch releases ballooning in size, it’s probably best not to let them pile up month after month.

But here’s the thing: while the number of vulnerabilities being patched is rising, the number of flaws that can and will affect most organizations remains quite low. As Satnam Narang, senior staff research engineer at Tenable, puts it, “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles.” So what matters most is understanding which vulnerabilities actually apply to your organization – and prioritizing remediation based on risk context.

For enterprise Windows admins, keeping an eye on askwoody.com for news of any updates that appear to be causing problems will be essential. And as always, the SANS Internet Storm Center has a per-patch breakdown ordered by severity and urgency. As we navigate this increasingly complex security landscape, one thing is clear: staying vigilant and up-to-date is crucial – but so too is prioritizing remediation based on risk context.


Source: Krebs on Security — 2026-09-08