Patch Tuesday Sets Another Record With 974 CVEs
Reported exploitedWindowsOfficeOur summary
Microsoft has addressed a record-high 974 vulnerabilities in its September security update, including two flaws currently being exploited in the wild. The affected products span Windows, Office, Exchange Server, and SQL Server, with CVE-2026-85880 and CVE-2026-81963 representing immediate risks as both allow privilege escalation on compromised systems.
Beyond the active exploits, the release includes 13 critical-rated issues and 20 wormable remote code execution bugs, notably CVE-2026-69730 in Windows DNS Server. Organizations should prioritize applying these updates to mitigate the risk of automated network propagation and unauthorized administrative access.
Dark Reading publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.