Back to feed

Microsoft patches 974 security flaws, a monthly record

2 min
Microsoft patches 974 security flaws, a monthly record

This digest was compiled by AI from multiple sources — links to the originals are below.

Microsoft released 974 security fixes in its September Patch Tuesday, the highest monthly total on record. The update addresses 113 critical vulnerabilities, including two zero-days already exploited in attacks. The surge reflects AI-assisted vulnerability discovery rather than a sudden decline in product security.

Key Facts

  • Microsoft released 974 security fixes in its September 2026 Patch Tuesday, surpassing the previous monthly record of 570 set in July 2026.
  • The update includes 113 critical vulnerabilities, among them CVE-2026-69730 and CVE-2026-69829, both rated 9.8 on the CVSS scale.
  • Two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, were actively exploited before the patch was released.
  • Microsoft has fixed more than 2,600 vulnerabilities since the start of 2026, with some researchers counting 2,760 CVEs.
  • CVE-2026-69730 is a use-after-free flaw in Windows DNS Server affecting Windows Server 2012 and later, allowing remote code execution without authentication.

Record Patch Volume

Microsoft's September 2026 Patch Tuesday release includes 974 security fixes, the largest monthly total in the company's history. The previous monthly record was 570 vulnerabilities, set in July 2026, followed by 415 in August. Since January 2026, Microsoft has addressed more than 2,600 vulnerabilities, with some researchers counting 2,760 CVEs. This year's total already more than doubles the previous annual record of about 1,250 vulnerabilities fixed in 2020.

Critical Vulnerabilities

Among the 113 critical flaws, CVE-2026-69730 is a use-after-free vulnerability in Windows DNS Server with a CVSS score of 9.8. The flaw affects Windows Server 2012 and newer server versions, as well as some Windows 10 releases, and allows unauthenticated remote code execution via a crafted network packet. Microsoft considers exploitation of CVE-2026-69730 likely. CVE-2026-69829, also rated 9.8, is a buffer overflow in Windows Shell that enables remote code execution without authentication or user interaction. The update also patches two zero-day vulnerabilities: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, both allowing privilege escalation to System level.

AI-Driven Discovery

The accelerated pace of vulnerability discovery is attributed to artificial intelligence tools that help developers and researchers find flaws faster. Microsoft notes that the increase reflects improved detection efficiency rather than a sudden decline in product security. AI also aids attackers in developing exploits, with demonstration samples already existing, but no evidence yet of a comparable rise in mass attacks. The record patch volume places additional workload on corporate system administrators.

1 source

Time · lag behind first