Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Where Should Apple Go After The iPhone Duo? Bring On Smaller And Larger Foldables

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    One of AI’s Fiercest Critics Says All the Doom Talk Is ‘Meant to Distract Us’

    September 11, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Microsoft Fixes 974 Flaws in Record Patch Tuesday
    Cybersecurity

    Microsoft Fixes 974 Flaws in Record Patch Tuesday

    InfoForTechBy InfoForTechSeptember 10, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Microsoft’s September Patch Tuesday has turned patching into a numbers game, with nearly 1,000 vulnerabilities landing at once and two already being exploited.

    Microsoft addressed 974 vulnerabilities in its September 2026 security update, making it the company’s largest Patch Tuesday release on record. Security researchers counted 119 critical vulnerabilities, with 723 entries affecting Windows components and 111 affecting Office products.

    The surge follows several months of unusually large releases, including 570 vulnerabilities in July and 400 in August. Security researchers have suggested that Microsoft’s growing use of AI-assisted discovery tools may be contributing to the increase. But the size of the list is not the most important part.

    Microsoft has classified two vulnerabilities as actively exploited: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack, and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC).

    Security researchers said both flaws could ultimately allow attackers to obtain SYSTEM-level privileges.

    Action1’s Jack Bicer told TechRepublic that CVE-2026-81963 can allow a low-privileged local attacker to gain SYSTEM privileges without user interaction. Mike Walters of Action1 said CVE-2026-85880 can let an attacker escape a low-privilege AppContainer and obtain SYSTEM privileges.

    Cohesity’s Amol Sarwate, in a statement to TechRepublic, said the two vulnerabilities should be the first priority because attackers can use them to move from an existing foothold to deeper control of a Windows machine.

    “In a record-setting Patch Tuesday of [974] fixes, top priority goes to the two actively exploited Windows flaws (CVE-2026-85880 and CVE-2026-81963),” Sarwate said.

    More Microsoft news

    The bigger enterprise risk

    Security researchers identified 20 vulnerabilities as potentially wormable because they may allow unauthenticated attackers to remotely execute code without user interaction. One of the most concerning is CVE-2026-69730, a Windows DNS Server flaw with a CVSS score of 9.8.

    Dustin Childs of Trend Micro’s Zero Day Initiative compared it with SigRed, the critical Windows DNS Server vulnerability disclosed in 2020.

    “We haven’t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed, that reality could change fast,” Childs told TechRepublic.

    Other infrastructure targets include DHCP, Remote Desktop Services, Netlogon, NFS and Exchange Server. Exchange deserves particular attention because CVE-2026-55007 could allow remote code execution when a server processes a malicious Visio attachment. Exploitation requires sustained low-memory conditions, making an attack more difficult, but no user interaction is required after the attachment reaches the server.

    Patch priority matters more than the headline number

    For IT teams, the lesson from September’s release is not to chase 974 vulnerabilities equally.

    Organizations should first patch or mitigate the two exploited zero-days, then prioritize exposed DNS, DHCP, Remote Desktop, Exchange, Netlogon and identity infrastructure. IT teams should use Microsoft’s advisories and their own asset inventories to rank the remaining Office and endpoint fixes by exposure and business criticality.

    AI may be dramatically increasing the number of bugs defenders can fix, but organizations still have limited time and resources to deploy those fixes. This month’s combination of exploited zero-days and wormable flaws makes prioritization especially important.

    Read more: AI could accelerate vulnerability discovery and shrink the supply of exploits governments rely on, intensifying the race between attackers and defenders.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026

    JADEPUFFER’s Second Wave Multi-Agent Attacks

    September 11, 2026

    200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    September 10, 2026

    U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

    September 9, 2026

    Before You Paste Anything Into ChatGPT, Check This List

    September 9, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026333 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202627 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026333 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202627 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.