Industry News

Microsoft's Biggest Patch Tuesday Ever: 974 Fixes Include Two Actively Exploited Flaws

Krebs on Security · 9 Sept 2026
Key Takeaway Prioritise patching the actively exploited and critical vulnerabilities first, especially any Windows systems exposed to untrusted networks, and don't let a growing patch backlog delay urgent fixes.

Microsoft has issued patches for at least 974 security vulnerabilities in Windows and other software, the largest single update batch the company has ever released. This smashes the previous record of 570 set in July, and brings the 2026 total past 2,600, already more than double the previous record year of 2020.

Two of the flaws fixed this month, CVE-2026-81963 and CVE-2026-85880, are being actively exploited and allow attackers to gain elevated privileges on Windows systems. Of particular concern is CVE-2026-69730, a DNS weakness affecting Windows Server 2012 onward and Windows 10, which Microsoft warns could be exploited by an unauthenticated attacker sending a single crafted network packet. Another serious issue, CVE-2026-69829, is a remote code execution flaw in the Windows Shell that scores 9.8 out of 10 for severity and requires no user interaction to exploit. In total, 113 of the fixed bugs were rated 'critical'.

Microsoft says artificial intelligence is helping researchers find vulnerabilities faster, and other major vendors including Adobe, Cisco, Google, Mozilla and Oracle report similar trends, with Google announcing it will now ship security updates every two weeks. While faster discovery is good news for security research, it also means businesses face a growing backlog of patches to test and deploy, straining already stretched IT teams.

Summarised by CISO AI from Krebs on Security. We link back to every original so you can read it yourself.