CVE Tools

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

SecurityWeekBy Ionut Arghire

Reported exploitedWindows ALPCTenableWindows Update Stack

Our summary

Microsoft released a record number of security updates this month, resolving 974 vulnerabilities across its software portfolio, including two actively exploited zero-days. The first, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) that allows local attackers to escalate privileges to System level. The second, CVE-2026-81963, involves improper link resolution in the Windows Update Stack, also enabling privilege escalation. Additionally, the patch addresses significant remote code execution risks in Exchange Server, SharePoint, and Remote Desktop Services.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store