Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed a record-breaking 974 security flaws, including two zero-day vulnerabilities actively exploited in the wild. The massive update, driven in part by new AI-assisted detection tools, includes fixes for 113 critical vulnerabilities.
- Security Researchers
- Emphasize the urgency of patching the actively exploited zero-days and the challenges posed by the sheer volume of updates.
- IT Administrators
- Face the operational burden of testing and deploying a record number of patches across enterprise networks.
- Technology Analysts
- Focus on the role of AI in driving the record number of vulnerability discoveries and the long-term implications for software security.
Perspectives this story doesn't cover
- End-users affected by potential downtime during patch deployment
- Threat actors exploiting the zero-day vulnerabilities
Microsoft released a record-breaking 974 security patches on Tuesday, including fixes for two zero-day vulnerabilities that attackers are already exploiting in the wild. The sheer volume of Common Vulnerabilities and Exposures (CVEs) addressed in the September 2026 update shatters previous records, presenting a significant deployment challenge for IT administrators globally.[1][2][4]
The massive patch load is largely attributed to Microsoft's recent deployment of advanced AI-assisted vulnerability detection tools within its internal security review processes. These tools have significantly increased the rate at which flaws are identified across the company's vast codebase, leading to the unprecedented number of fixes in a single monthly cycle.[7]
Among the 974 flaws, 113 are rated as "Critical," the highest severity level, indicating that they could allow remote code execution or significant system compromise without user interaction. The remaining vulnerabilities are classified as "Important" or "Moderate."[9]
The most urgent fixes address two zero-day vulnerabilities currently under active exploitation. The first, tracked as CVE-2026-38112, is a Windows MSHTML Platform Spoofing Vulnerability. This flaw allows an attacker to execute arbitrary code by convincing a user to open a specially crafted file or visit a malicious website.[1][2][3]
The most urgent fixes address two zero-day vulnerabilities currently under active exploitation.
The second actively exploited zero-day, CVE-2026-38831, is a Windows Mark of the Web (MotW) Security Feature Bypass Vulnerability. This flaw enables attackers to bypass security warnings that normally appear when a user attempts to open a file downloaded from the internet, facilitating the delivery of malware.[1][2][5]
Security researchers emphasize the critical need for immediate patching, particularly for the two zero-days. "The sheer volume of CVEs this month is staggering, but the immediate focus must be on the two exploited zero-days," noted analysts at Qualys in their review of the update. "Organizations need to prioritize these patches to mitigate the immediate risk of compromise."[8]
The update also includes patches for a wide range of Microsoft products, including Windows, Office, Exchange Server, and Azure components. The extensive list of affected software underscores the broad impact of the September Patch Tuesday and the necessity for comprehensive update strategies.[6][8]
While the AI-driven discovery of vulnerabilities has led to a record number of patches, it also highlights a proactive approach to identifying and addressing security flaws before they can be widely exploited. However, the resulting patch burden on IT departments remains a significant operational challenge.[7][9]
Key points
- Microsoft released a record 974 security patches in its September 2026 Patch Tuesday update.
- The update includes fixes for two zero-day vulnerabilities actively exploited in the wild.
- 113 of the patched vulnerabilities are rated as 'Critical.'
- The record volume of patches is attributed to Microsoft's use of AI-assisted vulnerability detection tools.
Why this matters
The unprecedented volume of patches, driven by new AI detection tools, means IT departments face a massive deployment burden this month. The inclusion of two actively exploited zero-days requires immediate action to secure enterprise networks.
Sources
[1]SecurityWeekSecurity ResearchersMicrosoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Read on SecurityWeek →
[2]The Hacker NewsSecurity ResearchersMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Read on The Hacker News →
[3]TechRadarTechnology AnalystsMicrosoft September 2026 Patch Tuesday fixes nearly a thousand flaws, including two major zero-days
Read on TechRadar →
[4]Dark ReadingIT AdministratorsPatch Tuesday Sets Another Record With 974 CVEs
Read on Dark Reading →
[5]Bleeping ComputerMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Read on Bleeping Computer →
[6]TechRepublicIT AdministratorsMicrosoft Fixes 974 Flaws in Record Patch Tuesday
Read on TechRepublic →
[7]PC GamerTechnology AnalystsMicrosoft's AI vulnerability detection results in record-breaking Patch Tuesday, addressing 974 security flaws
Read on PC Gamer →
[8]QualysSecurity ResearchersMicrosoft and Adobe Patch Tuesday, September 2026 Security Update Review
Read on Qualys →
[9]CrowdStrikeSecurity ResearchersSeptember 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
Read on CrowdStrike →
Comments
More in Technology
See all →AI Alignment
The Orthogonality Thesis: Why Optimization Power Does Not Guarantee Moral Convergence in AI
8 sources
Engineering Metrics
How DORA Metrics Quantify Software Engineering Performance Without Tracking Individual Output
7 sources
Visual Dubbing
Amazon Prime Video Deploys AI to Alter Actors' Lips for Dubbed Shows
6 sources
Camera Sensors
How Photon Shot Noise and Pixel Binning Erase the Advantage of 200-Megapixel Smartphone Sensors
6 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.


