Microsoft Fixes Record 974 Security Flaws as Two Windows Bugs Face Active Attacks

Last updated: September 10, 2026 Reading time: 5 minutes
Disclosure
Share
Microsoft Fixes Record 974 Security Flaws as Two Windows Bugs Face Active Attacks
  • Microsoft fixed 974 security flaws this Patch Tuesday, its biggest release ever.
  • Two Windows bugs are already under attack, and both hand hackers have full SYSTEM control.
  • Experts warn that sorting the urgent fixes now matters more than the huge count.

Microsoft rolled out a record-breaking update this Tuesday. The company fixed 974 flaws across its entire software lineup. Two of those flaws are already being used by hackers right now.

Windows alone picked up 723 fixes this month. Office and Office 2016 received 111 fixes between them. SQL Server got 62 fixes, and Developer Tools received 22. Over 110 of these flaws carry a critical severity rating.

Three flaw types make up almost 90% of this month’s list. They are privilege escalation, remote code execution, and information leaks. Microsoft also patched 25 bugs found in other companies’ products this round. That brings the grand total to 999 fixes.

This is Microsoft’s biggest month on record. August brought 457 fixes. July brought 663, June brought 220, and May brought 161. Each month kept breaking the last one’s record.

According to Jack Bicer, director of vulnerability research at Action1, the real challenge isn’t finishing the list. He explained that teams must quickly spot which flaws need action first, since hundreds of fixes now land at once.

Two Windows Bugs Hackers Are Already Using

Two flaws stand out from the rest of the pile. Hackers are actively using both of them today.

The first is CVE-2026-85880. It’s a heap overflow bug inside Windows’ Advanced Local Procedure Call system. It lets an attacker already stuck in a low-privilege app jump up to full SYSTEM access. Microsoft’s advisory notes that the attacker needs no extra clicks from the victim to pull this off.

A separate Facebook incident shows the risks of privilege escalation flaws. In 2018, a bug exposed unpublished photos from up to 6.8 million users to third-party apps. Facebook fixed the issue and notified affected users.

The second is CVE-2026-81963. It’s a flaw in how the Windows Update system handles links. It also hands attackers SYSTEM-level access once triggered. According to Adam Barnett, lead software engineer at Rapid7, this fix works to stop Windows Update from trusting a fake, attacker-made link in place of a real system file.

Volexity and Proofpoint get credit for flagging the first bug. Romain Deperne of Airbus Helicopters, along with Microsoft’s own threat team, found the second one. Microsoft hasn’t named who’s behind these attacks. The company also hasn’t shared how many people have been hit so far.

According to Tenable, the Windows Update Stack has carried seven privilege bugs since 2022. This is the first one ever used as a zero-day before a patch existed. The ALPC bug is only the second such case since a similar flaw appeared back in January 2023.

CISA has added both flaws to its Known Exploited Vulnerabilities list. Federal agencies must apply these fixes by September 22, 2026.

More High-Risk Fixes Buried in the Pile

Several other bugs deserve quick attention too, even without confirmed attacks yet.

CVE-2026-69525 hits Remote Desktop Services and scores a 9.8 severity rating. CVE-2026-69730 hits the Windows DNS server, also at 9.8. CVE-2026-69829 hits Windows Shell, and CVE-2026-72979 hits the DHCP server. Both of those carry that same top score.

CVE-2026-65669 targets SQL Server and lets attackers grab higher access over a network. CVE-2026-69465 hits SharePoint and needs no valid login to trigger remote code execution. CVE-2026-80097 targets Microsoft Authenticator and could let someone slip past its protections locally. CVE-2026-55007 affects Exchange Server through a memory-handling flaw.

Every one of these lets an attacker run code or grab higher access with little resistance. Security teams should treat this whole group as a fast follow-up job.

Why Experts Say the Number Game has Lost Meaning

According to Tenable’s Satnam Narang, this month marks another turning point for Patch Tuesday. He pointed out the count sits close to a thousand new flaws. That’s nearly 70% more than July’s previous record of 569 fixes, he added. This year’s total has already crossed 2,600 fixes. That beats the old full-year record of 1,245, set back in 2020, with months still left in 2026.

The Zero Day Initiative puts this year’s Microsoft total even higher, at 2,760 fixes. That pace suggests AI tools are helping researchers find bugs faster than before.

Despite the flood of fixes, Narang says most companies won’t feel every single one. He explained that teams should focus on which flaws actually touch their own systems. They should also check whether those flaws sit exposed to the open internet.

According to Tyler Reguly of Fortra, huge fix counts aren’t really bad news on their own. He said big vendors like Microsoft and Oracle are being proactive, not careless. Reguly added that clearing out old, hard-to-find bugs now shrinks the attack surface before hackers can use it. He expects Patch Tuesday to settle into a calmer rhythm once that backlog clears out.

The news sparked plenty of reaction on X. Andrea Mazzarini (@mazz_andrea) urged teams to patch the two exploited bugs before touching the rest of the pile. M I Mohit (@mimohit_4u) warned that local privilege bugs often rank below remote code flaws, yet attackers already hold the first half of that chain.

CHEXUM (@Chexum_) said the real struggle isn’t reading the list, but figuring out which dozen fixes actually apply to your setup. AIPathfinder (@NavigateAI_) predicted that AI-driven bug hunting will keep outpacing the monthly patch calendar. Jessie Soung (@j3soung) called the numbers alarming but was relieved Microsoft caught the exploited bugs in time.

Security Board News (@BytesNora) said both zero-days deserve the top spot in every patch queue this month. Companies should push out fixes for the two exploited flaws first. Everything else on the list can follow the normal patch schedule.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts