Patch Tuesday Sets Another Record With 974 CVEs
Recorded: Sept. 8, 2026, 10:01 p.m.
| Original | Summarized |
Patch Tuesday Sets Another Record With 974 CVEs Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsVulnerabilities & ThreatsPatch Tuesday Sets Another Record With 974 CVEsPatch Tuesday Sets Another Record With 974 CVEsbyJai VijayanSep 8, 20265 Min ReadVulnerabilities & ThreatsAI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?byAlexander CulafiSep 4, 20265 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryVulnerabilities & ThreatsApplication SecurityThreat IntelligenceCyber RiskNewsPatch Tuesday Sets Another Record With 974 CVEsAttackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.Jai Vijayan,Contributing WriterSeptember 8, 20265 Min ReadSource: bombermoon via ShutterstockMicrosoft released fixes for 974 unique vulnerabilities in its scheduled security update for September, which until recently would have represented a full year’s worth of CVEs.Of these, the highest-priority vulnerabilities include two that are already under active exploitation. Additionally, Microsoft rated 13 flaws as "Critical" and 58 it deemed as bugs that attackers are more likely to exploit for different reasons, including low attack complexity and high impact.Windows accounted for most of the vulnerabilities, with 723, followed by Office and Office 2016, with 111 each. The remaining vulnerabilities were spread across other Microsoft technologies, including 62 in SQL, 22 in Developer Tools, 16 in SharePoint Server, and 12 in Azure. This month's release follows a recent trend of increasingly large and record-setting volumes of CVEs for the software giant's Patch Tuesday.An Overabundance of Elevation of Privilege FlawsAs has been the pattern in recent months, a plurality of the bugs — about 45%, or 438 — were elevation-of-privilege (EoP) vulnerabilities that can, in many cases, enable attackers to gain administrator- or system-level access to compromised systems. Another 25%, or 260, were remote code execution (RCE) flaws, while about 18%, or 175, involved information disclosure.Related:AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?The two zero-day vulnerabilities that attackers are actively exploiting, and hence need priority attention, are CVE-2026-85880 (CVSS: 7.8), an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963 (CVSS 7.8), another EoP flaw this time in Windows Update Stack. Both vulnerabilities allow an attacker who already has gained access to a vulnerable system to achieve SYSTEM-level privileges.Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, pointed to CVE-2026-69380 (CVSS:8.1), a Microsoft Exchange Server EoP, as another vulnerability that organizations should patch immediately, because it "allows low-privileged attackers to impersonate any user and hijack every mailbox in the organization."A Cluster of Wormable CVEsAlso of high priority in Microsoft's September Patch Tuesday are a cluster of 20 wormable CVEs, Childs warned in an emailed statement. The bugs enable an unauthenticated remote attacker to execute arbitrary code on vulnerable systems. The "zero-click RCE bugs — headlined by a Windows DNS Server flaw (CVE-2026-69730 CVSS:9.8) acting as SigRed’s spiritual successor — creates severe, self-propagating contagion risk across enterprise networks," he wrote.Related:SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCESigRed (CVE-2020-1350) was a maximum severity RCE flaw in DNS servers from 2020 that allowed an unauthenticated attacker to gain Local System/Domain Administrator-level control and potentially spread across a network without user interaction."Reaching nearly 1,000 monthly CVEs confirms that AI-assisted vulnerability discovery is the industry's new normal, completely outstripping human patching capacities," Childs noted. "Coupled with an extraordinary cluster of 20 wormable bugs, defenders face a higher risk of automated network contagion than they have in years."Critical RCE FlawsResearchers from Action1 highlighted three near-maximum severity (CVSS: 9.8) RCE bugs that organizations would do well to prioritize from this month's massive set: CVE-2026-69829, an RCE in Windows Shell; CVE-2026-69595, an RCE in Windows Services for NFS ONCRPC XDR Driver; and CVE-2026-78510, a Microsoft Word RCE. In emailed statement, Action1 researchers described the bugs as posing a high-risk because of their potential impact on confidentiality, integrity, and availability.Amol Sarwate, head of security research and REDLab at Cohesity, advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane this month. Attackers could exploit these flaws by sending unauthenticated packets to DNS, DHCP, RDS, and Netlogon listeners on domain controllers and Microsoft Exchange, he said in a statement.Related:Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise"On the endpoint front, security teams should prioritize the Office stack, as attackers can exploit a condition in the SMB client and create a malicious Word RTF or a malicious message in the Outlook Reading Pane that can lead to code execution," he cautioned. "A single share or phishing mail can own the workstation without the user choosing to open anything."Massive Updates are the New Normal — For NowThis is the fourth month in a row that Microsoft has released a substantially larger Patch Tuesday update than usual, reflecting the company's increasing use of AI to hunt for vulnerabilities across its technology portfolio. While the numbers might appear staggering in scale, they are not entirely unexpected and do not necessarily translate into a corresponding increase in risk for organizations, as numerous security experts have stressed in recent months. The key lies in prioritizing actively exploited bugs and the relatively smaller subset of critical flaws that attackers are more likely to exploit."One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low," noted Satnam Narang, senior staff research engineer at Tenable, in a statement. "AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles."Security teams should focus on understanding the vulnerabilities that actually apply to their organizations, figure out if the flaws are reachable and exploitable in their specific environments, and prioritize based on risk context, Narang said.It's also important to keep in mind that the massive surge in vulnerability discovery and disclosure is likely temporary, noted Tyler Reguly, associate director of security R&D at Fortra, in a statement. "We need to remember that these large CVE counts are a good thing, as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence," Reguly predicted.About the AuthorJai VijayanContributing WriterIllinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.See more from Jai VijayanWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsThreat Exposure Analytics: Measuring and Communicating Security RiskBenchmark Scores Are a False FlagBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachCloud Incident Response: Forensics in Distributed EnvironmentsMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskWhat We Missed: Delta Flight Disrupted With Wi-Fi HackWhat We Missed: Delta Flight Disrupted With Wi-Fi HackbyRob Wright,Alexander CulafiAug 20, 2026Cyberattacks & Data BreachesAgentic AI Presents New Insider Threat Model for OrgsAgentic AI Presents New Insider Threat Model for OrgsAug 19, 2026Want more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
Microsoft's recent Patch Tuesday included a record 974 unique vulnerabilities, which reflects the increasing reliance on AI-assisted vulnerability discovery in the industry, creating larger pools of potential flaws. Of these vulnerabilities, Microsoft indicated that two are currently under active exploitation, while 58 others are considered more likely to be exploited. Thirteen flaws were rated as critical, and 58 were classified as bugs where attackers are assessed as having a higher probability of exploitation due to low attack complexity and high impact. The vast majority of these vulnerabilities resided within Windows systems, accounting for 723 issues, followed by Office and Office 2016 with 111 each. Other significant findings were distributed across various Microsoft technologies, including 62 flaws in SQL, 22 in Developer Tools, 16 in SharePoint Server, and 12 in Azure. A statistical pattern emerged from these releases, with a plurality of the discovered bugs, approximately 45% or 438, being elevation-of-privilege (EoP) vulnerabilities that grant attackers administrative or system-level access to compromised systems. Furthermore, 25%, or 260 flaws, involved remote code execution (RCE), and about 18%, or 175 bugs, related to information disclosure. Two zero-day vulnerabilities, CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC) and CVE-2026-81963 in the Windows Update Stack, are actively being exploited; both allow an attacker who has already gained access to a vulnerable system to attain SYSTEM-level privileges. The threat landscape also features a cluster of 20 wormable vulnerabilities that enable unauthenticated remote attackers to execute arbitrary code on vulnerable systems, including zero-click RCE bugs such as CVE-2026-69730 in the Windows DNS Server, which presents severe self-propagating contagion risk across enterprise networks. Security experts have highlighted several critical areas for immediate attention. Dustin Childs from Trend Micro's Zero Day Initiative warned about CVE-2026-69380, an Elevation of Privilege flaw in Microsoft Exchange Server, noting it permits low-privileged attackers to impersonate any user and hijack every mailbox within an organization. Additionally, Amol Sarwate of Cohesity advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane, as attackers can exploit flaws by sending unauthenticated packets to various listeners on domain controllers and Microsoft Exchange servers. Researchers from Action1 identified three near-maximum severity RCE bugs that organizations should prioritize: CVE-2026-69829 in Windows Shell, CVE-2026-69595 in Windows Services for NFS ONCRPC XDR Driver, and CVE-2026-78510 in Microsoft Word. Relatedly, concerning the endpoint, experts cautioned that security teams must focus on the Office stack because flaws could allow code execution via malicious documents or emails originating from a single share or phishing mail. Despite the staggering volume of newly disclosed vulnerabilities, some analysts suggest this surge is not necessarily an immediate proportional increase in organizational risk. Satnam Narang, senior staff research engineer at Tenable, noted that while AI-assisted discovery generates larger vulnerability haystacks, it does not find more actionable flaws. Tyler Reguly of Fortra predicted that this massive volume of disclosures is temporary, arguing that it serves to reduce the overall attack surface before attackers can fully exploit these issues, and he anticipates a return to the normal patching cadence once long-standing vulnerabilities are addressed. The emphasis for security teams should therefore shift from merely tracking CVE counts to contextually assessing which flaws are reachable, exploitable within specific environments, and prioritized based on actual risk. |