As we reported earlier this week, Patch Tuesday set another record with 974 unique vulnerabilities released by Microsoft. For those who might be wondering what all the fuss is about, let’s break it down: these are essentially flaws or weaknesses in various Microsoft products and services that hackers can exploit to gain access to sensitive systems or data.
The sheer number of vulnerabilities this month is staggering – until recently, 974 would have represented a full year’s worth of Common Vulnerabilities and Exposures (CVEs). The highest-priority bugs include two that are already being actively exploited by attackers. Microsoft has rated 13 flaws as “Critical” and another 58 as high-risk due to factors like low attack complexity and high impact.
Windows accounts for the majority of vulnerabilities, with 723 identified, followed closely by Office (111 each) and other Microsoft technologies such as SQL (62), Developer Tools (22), SharePoint Server (16), and Azure (12). This latest release follows a recent trend of record-breaking volumes of CVEs from Microsoft’s Patch Tuesday updates.
One notable pattern in these vulnerabilities is the prevalence of elevation-of-privilege (EoP) flaws – 45% of the total, or approximately 438 bugs. These types of vulnerabilities can enable attackers to gain administrator-level access to compromised systems. Remote code execution (RCE) and information disclosure also feature prominently, with around 25% and 18%, respectively.
The two zero-day vulnerabilities that have already been exploited by hackers are particularly concerning – CVE-2026-85880 is an EoP bug in Windows Advanced Local Procedure Call (ALPC), while CVE-2026-81963 affects the Windows Update Stack. Both allow attackers who have already gained access to a system to achieve SYSTEM-level privileges.
Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, warns that organizations should prioritize patching these vulnerabilities – particularly CVE-2026-69380, an EoP flaw in Microsoft Exchange Server, which enables low-privileged attackers to impersonate users and hijack mailboxes across the organization.
Moreover, Childs points out a cluster of 20 wormable CVEs that pose significant risks due to their ability to enable unauthenticated remote attackers to execute arbitrary code on vulnerable systems. A Windows DNS Server flaw (CVE-2026-69730) is particularly worrisome as it could facilitate self-propagating contagion across enterprise networks.
Researchers from Action1 highlight three near-maximum severity RCE bugs that organizations should prioritize: CVE-2026-69829 in Windows Shell, CVE-2026-69595 in Windows Services for NFS ONCRPC XDR Driver, and CVE-2026-78510 in Microsoft Word. These bugs have the potential to impact confidentiality, integrity, and availability.
In light of this month’s record-breaking number of CVEs, it’s essential for organizations to prioritize patching these vulnerabilities as soon as possible. With AI-assisted vulnerability discovery becoming increasingly common, defenders face a higher risk of automated network contagion than ever before.
Source: Dark Reading — 2026-09-08