Microsoft Patches Record 974 Vulnerabilities, Including Two Actively Exploited Zero-Days
Tech
⚠ Single-source
30m ago

Microsoft Patches Record 974 Vulnerabilities, Including Two Actively Exploited Zero-Days

AI-synthesized · Bias removed · Facts only
2 sources: 0 left · 2 center · 0 right
Image: Thehackernews

Microsoft issued security updates addressing a record-breaking 974 vulnerabilities on Tuesday, including two zero-day flaws actively exploited in the wild. The updates cover a wide range of Microsoft products, with 723 flaws found in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Over 110 of the vulnerabilities are considered critical. The two actively exploited zero-days are CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963, an improper link resolution vulnerability in the Windows Update Stack. Both vulnerabilities allow an authorized attacker to elevate privileges locally to SYSTEM level.

According to Microsoft, CVE-2026-85880 allows an attacker executing code within a low-privilege AppContainer to escape the sandbox and gain elevated privileges without requiring user interaction. CVE-2026-81963 affects all supported Windows versions and potentially allows malicious links to overwrite system components, according to Rapid7 lead software engineer Adam Barnett. Cybersecurity firms Volexity and Proofpoint reported CVE-2026-85880, while Romain Deperne of Airbus Helicopters and the Microsoft Threat Intelligence Center (MSTIC) identified CVE-2026-81963.

This record-setting update follows patches for 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May. Jack Bicer, director of vulnerability research at Action1, noted the challenge for IT and security teams of prioritizing updates at this scale. Tenable reports seven privilege escalation flaws in the Windows Update Stack since 2022, with CVE-2026-81963 adding to this history. The total number of vulnerabilities resolved, including 25 non-Microsoft CVEs, is 999.

What is not yet known

  • The identity of the actors exploiting the zero-day vulnerabilities remains undisclosed.
  • The scale of the exploitation attempts and whether any breaches have occurred are not detailed.
Was this useful?

Read the original coverage

💬 Comments

📜 Comment Policy