Microsoft has released one of its largest Patch Tuesday updates, addressing 974 vulnerabilities, including two actively exploited zero-days, raising urgency for organisations to prioritise critical patches amidst a growing security workload.
Microsoft has issued one of its largest ever Patch Tuesday releases, fixing 974 vulnerabilities across its software portfolio and closing two flaws that it says have already been exploited in the wild. The update spans Windows, Office, SQL Server and developer tools, with more than 110 issues rated critical and the bulk of the flaws falling into privilege escalation, remote code execution and information disclosure categories. Industry digests said the total number of fixes reached 995 when non-Microsoft CVEs were included.
The two zero-days are CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack. Microsoft said the first bug could let an attacker in a low-privilege AppContainer escape the sandbox and gain SYSTEM-level access without extra user interaction. The company also confirmed that it has seen exploitation attempts but did not say who was behind them or whether victims were breached.
CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue, giving federal civilian agencies until 22 September 2026 to apply the fixes. Security researchers quoted by The Hacker News said the scale of this month’s release makes prioritisation essential, while Rapid7’s Adam Barnett described the Windows Update Stack fix as a tightening of controls against malicious links that could be used to replace system components. Tenable said CVE-2026-81963 is the first known zero-day in that stack, while CVE-2026-85880 is only the second time the ALPC issue has been weaponised.
Among the more serious additional fixes are a remote-code-execution flaw in Exchange Server, a privilege-escalation bug in Microsoft Authenticator, a SharePoint authorisation issue and several high-severity Windows defects affecting Remote Desktop Services, DNS, DHCP, Shell and the NFS ONCRPC XDR driver. Microsoft’s cumulative total for the year now stands at well over 2,600 vulnerabilities patched, according to Tenable and Trend Micro’s Zero Day Initiative, underscoring how quickly the company’s security workload is expanding. Researchers said organisations should not treat the headline number as the main issue, but instead focus on which flaws are reachable, exposed to the internet and relevant to their own environment.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





