CVE Tools

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker NewsBy The Hacker News

Reported exploitedWindowsOffice

Our summary

Microsoft released its largest monthly security update ever, remediating 974 vulnerabilities across its ecosystem. Among these fixes are two Windows zero-day flaws, CVE-2026-85880 and CVE-2026-81963, that have been actively exploited in the wild.

Both vulnerabilities enable local privilege escalation with a CVSS score of 7.8, allowing attackers to gain SYSTEM privileges. The issue was reported by Volexity, Proofpoint, and Microsoft MSTIC, prompting CISA to add both CVEs to the Known Exploited Vulnerabilities catalog. Organizations should apply the September 2026 patches immediately to secure their systems.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store