AUTO-UPDATED

Microsoft patches a record 974 flaws, and two are already under attack

Microsoft’s September Patch Tuesday addresses a record-breaking 974 security vulnerabilities, including two actively exploited zero-day flaws that allow attackers to gain elevated privileges on Windows systems.

Key Points

  • Microsoft released fixes for 974 vulnerabilities, with over 110 classified as critical severity.
  • Two zero-day flaws (CVE-2026-81963 and CVE-2026-85880) are currently being exploited in the wild to escalate user privileges.
  • Security experts identified 20 "wormable" bugs that can spread automatically across networks without requiring user interaction.
  • A critical vulnerability in Exchange Server (CVE-2026-55007) allows remote code execution via a malicious email attachment.
  • The surge in reported flaws is attributed to AI-assisted vulnerability discovery tools, which are identifying bugs at an unprecedented rate.

Why it Matters

The record volume of patches highlights a growing security challenge as AI-driven tools accelerate both the discovery of software flaws and the potential for automated exploitation. Organizations must prioritize rapid deployment of these updates to mitigate risks from wormable threats and zero-day attacks that could lead to widespread system compromise.
The Next Web Published by Ana Maria Constantin
Read original