CVE Tools

Why this month's Microsoft patch release is a doozy

Ars Technica (Security)By Dan Goodin

Reported exploitedWindowsEdge

Our summary

Microsoft has addressed a historic surge of approximately 972 security flaws in its latest cumulative update, with 112 of them classified as critical. This release includes fixes for two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which are currently being actively exploited in the wild. The unprecedented volume of patches reflects the growing impact of AI-driven vulnerability discovery across the tech industry.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store