Microsoft’s September Patch Tuesday addresses a record-breaking 974 security vulnerabilities, including two actively exploited zero-day flaws that allow attackers to gain elevated privileges on Windows systems.
Key Points
- Microsoft released fixes for 974 vulnerabilities, with over 110 classified as critical severity.
- Two zero-day flaws (CVE-2026-81963 and CVE-2026-85880) are currently being exploited in the wild to escalate user privileges.
- Security experts identified 20 "wormable" bugs that can spread automatically across networks without requiring user interaction.
- A critical vulnerability in Exchange Server (CVE-2026-55007) allows remote code execution via a malicious email attachment.
- The surge in reported flaws is attributed to AI-assisted vulnerability discovery tools, which are identifying bugs at an unprecedented rate.