LmCast :: Stay tuned in

Microsoft Plugs Nearly 1,000 Security Holes

Recorded: Sept. 8, 2026, 10:10 p.m.

Original Summarized

Microsoft Plugs Nearly 1,000 Security Holes – Krebs on Security

Advertisement

Advertisement

Skip to content

HomeAbout the Author
Advertising/Speaking

Microsoft Plugs Nearly 1,000 Security Holes

September 8, 2026

0 Comments

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Image: Shutterstock.com, Kirill Makarov.
This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.
Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.
Also scary is CVE-2026-69829, a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.
Microsoft’s summary of the security updates released today. Image: msrc.microsoft.com.
Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).
Tyler Reguly, associate director of security research and development at Fortra, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.
“It’s time to put our CISOs and CSOs on notice,” Reguly said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.”
Satnam Narang is senior staff research engineer Tenable. Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.
“AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,” he said. “It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”
Of course, regular Windows users don’t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program’s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.
Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear to be causing problems. As always, the SANS Internet Storm Center has a per-patch breakdown ordered by severity and urgency.

This entry was posted on Tuesday 8th of September 2026 05:44 PM

Latest Warnings Security Tools Time to Patch
CVE-2026-69730 CVE-2026-69829 CVE-2026-81963 CVE-2026-85880 Fortra Microsoft Patch Tuesday September 2026 Satnam Narang Tenable Tyler Reguly

Post navigation
← FBI Probes Service Selling 153M+ Drivers Licenses

Leave a Reply Cancel replyYour email address will not be published. Required fields are marked *Comment * Name *
Email *
Website

Δ

Advertisement

Advertisement
Mailing ListSubscribe hereSearch KrebsOnSecurity

Search for:

Recent Posts

Microsoft Plugs Nearly 1,000 Security Holes

FBI Probes Service Selling 153M+ Drivers Licenses

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Who’s Tracking You? Use This New Service to Find Out

Microsoft Plugs Nearly 400 Security Holes


Story Categories

A Little Sunshine

All About Skimmers

Ashley Madison breach

Breadcrumbs

Data Breaches

DDoS-for-Hire

DOGE

Employment Fraud

How to Break Into Security

Internet of Things (IoT)

Latest Warnings

Ne'er-Do-Well News

Other

Pharma Wars

Ransomware

Russia's War on Ukraine

Security Tools

SIM Swapping

Spam Nation

Target: Small Businesses

Tax Refund Fraud

The Coming Storm

Time to Patch

Web Fraud 2.0

Why So Many Top Hackers Hail from Russia

© Krebs on Security - Mastodon

Microsoft released its latest patch bundle, which addressed at least 974 security holes across its Windows operating systems and other software, marking the largest single patch batch ever provided by the company. This update significantly surpassed Microsoft’s previous record set in July, which covered over 570 vulnerabilities, bringing the year's total to more than 2,600, more than double the 1,245 recorded in 2020. The speed of this patching cycle is attributed by Microsoft to the use of artificial intelligence for vulnerability discovery, although security experts caution that organizations still struggle with the human-intensive process of testing and deploying numerous fixes monthly.

The released batch included two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, which are currently being actively exploited to allow attackers to elevate privileges on Windows systems. Of the total bugs addressed, 113 were rated as critical, meaning they could potentially be exploited by malware or malicious actors to gain control over a vulnerable Windows machine without user assistance. Among these critical flaws, two stand out: CVE-2026-69730, a DNS weakness present in systems like Windows Server 2012 and Windows 10, which allows an unauthenticated attacker to leverage specially crafted packets for exploitation, and CVE-2026-69829, a critical remote code execution flaw within the Windows Shell with a CVSS base score of 9.8; this vulnerability can be exploited with minimal attack complexity and no user interaction.

Beyond Microsoft’s activity, other major software vendors, including Adobe, Cisco, Google, Mozilla, and Oracle, are also leveraging AI-assisted research to increase their patch cadence and volume, exemplified by Google's plan to release security updates every two weeks. The deployment of these patches presents operational challenges for organizations; Tyler Reguly, associate director of security research and development at Fortra, highlighted that a core difficulty lies in testing updates across an entire organizational environment because third-party software may not function seamlessly following underlying operating system changes. He stressed the necessity for security teams to be supported in deploying fixes outside of standard business hours and compensating them for this effort.

Satnam Narang, a senior staff research engineer at Tenable, offered a perspective on vulnerability management, asserting that while AI discovery is creating larger collections of vulnerabilities, it is not necessarily finding more actionable flaws. Narang emphasized the critical need for organizations to contextualize these discoveries by determining which vulnerabilities actually apply to their specific environment, assessing whether they are reachable and exploitable threats, and prioritizing remediation based on this risk context. Regular Windows users should maintain periodic updates, while enterprise administrators must monitor sources such as askwoody.com and breakdowns from the SANS Internet Storm Center for severity and urgency rankings to manage these rapidly increasing patch volumes effectively.