Microsoft’s Record-Breaking Update, Released Tuesday, Fixed Nearly 1,000 Bugs.

Security updates have been becoming increasingly extensive lately, and Microsoft’s September “Patch Tuesday” is no exception. The company just released fixes for nearly 1,000 bugs, nearly double the number of vulnerabilities patched in July (the previous record). Two of the vulnerabilities patched this month were zero-day vulnerabilities that had already been exploited by attackers.

This dramatic increase is largely due to artificial intelligence , which makes it easier for attackers to develop tools to exploit vulnerabilities and allows developers to find and patch them more quickly. This means we’ll likely continue to see significant updates with shorter release cycles , which will ideally reduce the time hackers can exploit these flaws. Microsoft typically releases patches as part of “Patch Tuesday” around 10 AM PT on the second Tuesday of each month.

Installing security updates as soon as they become available has always been important, but it’s even more critical now given the large number of exploitable vulnerabilities. PC users should receive updates automatically on Patch Tuesday, but you can check their status via Start > Settings > Windows Update > Check for Windows updates .

You may also like

The September Patch Tuesday update fixed 966 vulnerabilities, including two zero-day vulnerabilities.

As reported by BleepingComputer , the 966 vulnerabilities patched this month fall into the following categories: 438 privilege escalation vulnerabilities, 19 security feature bypass vulnerabilities, 258 remote code execution vulnerabilities, 173 information disclosure vulnerabilities, 16 spoofing vulnerabilities, and 56 denial of service vulnerabilities. These figures do not include other vulnerabilities (a total of 204 in other Microsoft products) patched earlier this month.

One of the zero-day vulnerabilities reported in September was a privilege escalation vulnerability in the Windows update stack. CVE-2026-81963 allows attackers to gain system privileges by improperly resolving links before accessing files. The discovery of the bug was reportedly investigated by Romain Deperne and the Microsoft Threat Analysis Center.

What do you think at the moment?

Another zero-day vulnerability also involves privilege escalation. CVE-2026-85880 is a flaw in Windows Advanced Local Procedure (ALP)β€”an attacker can execute code in AppContainer with low privileges, and this vulnerability can escalate beyond the sandbox and gain local SYSTEM privileges. The bug was discovered by Volexity and Mark Kelly, David Galazin, and Jeremy Hedges of Proofpoint.

Both zero-day vulnerabilities were actively exploited by attackers, although Microsoft did not provide any details about how exactly this happened.

More…

Leave a Reply