CVE Tools

Patch Tuesday Sets Another Record With 974 CVEs

Dark ReadingBy Jai Vijayan

Reported exploitedWindowsOffice

Our summary

Microsoft has addressed a record-high 974 vulnerabilities in its September security update, including two flaws currently being exploited in the wild. The affected products span Windows, Office, Exchange Server, and SQL Server, with CVE-2026-85880 and CVE-2026-81963 representing immediate risks as both allow privilege escalation on compromised systems.

Beyond the active exploits, the release includes 13 critical-rated issues and 20 wormable remote code execution bugs, notably CVE-2026-69730 in Windows DNS Server. Organizations should prioritize applying these updates to mitigate the risk of automated network propagation and unauthorized administrative access.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store