Skip to main content
Emerging Threats

Microsoft patches 974 vulnerabilities, including two actively exploited zero-days

Modern software company campus with a clean, neutral-colored cybersecurity operations area.

"AI-assisted vulnerability discovery shows no signs of slowing down," Dustin Childs of Trend Micro's Zero Day Initiative wrote — a concise assessment that prefaced Microsoft's largest-ever Patch Tuesday, in which the company fixed 974 separate defects across its product portfolio, including two zero-days that were actively exploited before disclosure.

Two actively exploited Windows zero-days: CVE-2026-81963 and CVE-2026-85880

Microsoft confirmed two vulnerabilities that were exploited prior to public disclosure: CVE-2026-81963, which affects the Windows Update Stack, and CVE-2026-85880, which affects Windows Advanced Local Procedure Call. Both carry CVSS scores of 7.8 and allow attackers to escalate privileges. The vendor released fixes for these flaws as part of the September Patch Tuesday cycle.

Scope and scale: 974 vulnerabilities across Microsoft products

The September security update included 974 distinct vulnerabilities, the largest batch Microsoft has published to date. The distribution by product was heavily weighted toward Windows: 723 vulnerabilities were addressed in Windows, 111 in Office, 111 again listed under Office 2016, 62 in SQL, and 22 across various developer tools. Microsoft reported that more than one in ten of the disclosed defects were rated critical.

What researchers are saying about AI-driven discovery

Security researchers framed the flood of disclosures as the outcome of faster discovery, not necessarily a rise in active exploitation. Dustin Childs said AI-assisted discovery is accelerating the pace of finds but added, "we have not seen a correlating spike in active exploits — yet." Satnam Narang, senior staff research engineer at Tenable, cautioned teams against being overwhelmed by the raw count: "AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles," he wrote, arguing that organizations must focus on which defects apply to them and whether they are reachable and exploitable.

Jack Bicer, director of vulnerability research at Action1, reached a similar conclusion: "At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first," he said, emphasizing the need for rapid triage when hundreds of updates arrive simultaneously.

How technologists, procurement leaders, and end users are likely to respond

  • Technologists and security teams: Expect intense triage cycles. Teams will focus on mapping the 974 disclosures to in-scope systems, identifying reachable, exploitable vulnerabilities and prioritizing remediation by risk context rather than attempting blanket patching at once.
  • Procurement and enterprise leaders: They will need to coordinate patch windows and resource allocation, concentrating scarce operational capacity on vulnerabilities with the highest impact and the greatest likelihood of exploitation, particularly the two zero-days affecting core Windows components.
  • End users and the general public: Users should lean on IT organizations to deploy prioritized updates; for most individuals the number of fixes is irrelevant compared with whether their devices receive patches for the vulnerabilities that actually affect them.

Operational priorities: triage, risk context, and Microsoft's Security Response Center

Across expert commentary in the wake of the release, a few operational themes recur: don’t equate volume with universal risk; identify which vulnerabilities affect your environment; and prioritize fixes by exploitability and reachability. Satnam Narang advised organizations to "understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context." Jack Bicer urged rapid separation of the small subset that demands immediate action from the larger set that can follow normal deployment cycles.

Microsoft has published the full list of this month’s vulnerabilities in its Security Response Center for teams that need the authoritative inventory and technical details required for patch planning.

There is a clear throughline in the record-breaking numbers: automated and AI-assisted techniques are expanding the universe of discovered defects, producing larger "haystacks" of findings. Whether that expansion will translate into a sustained rise in active exploitation remains unresolved — as Dustin Childs put it, security teams have not seen a correlating spike in active exploits "yet." The immediate implication is practical: organizations must resist being daunted by the headline count and instead apply scarce resources where exposure and exploitability make the risk concrete.

https://cyberscoop.com/microsoft-patch-tuesday-september-2026/