Microsoft's Biggest Patch Tuesday Ever: 974 Flaws Fixed, Two Already Under Attack
Microsoft has released its largest security update on record, patching 974 vulnerabilities across Windows, Office, SQL and its developer tools, with over 110 rated critical. Combined with fixes for 25 non-Microsoft issues, the total reaches 999 patched flaws this month alone. Most of the vulnerabilities fall into three categories: privilege escalation, remote code execution and information disclosure, which together make up nearly 90% of the update.
Two of the flaws are already being actively exploited. CVE-2026-85880 allows an attacker who has already gained low-level code execution to escape a security sandbox and gain higher privileges without needing any user interaction. CVE-2026-81963 affects the Windows Update Stack and appears designed to prevent attackers from tricking the update process into installing a malicious, look-alike system component. Microsoft has not disclosed who is behind the exploitation attempts or whether any organisations have been successfully breached.
This record-breaking release follows a run of unusually large updates, with Microsoft patching 457 flaws in August and 663 in July. Security researchers note that the sheer volume makes prioritisation critical, since IT teams cannot treat every patch with the same urgency.