Skip to main content
Patch TuesdayVulnerability Fixes· 2 min read· in Technology

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday addressed a record-breaking 974 security flaws, including two zero-day vulnerabilities actively exploited in the wild. The massive update, driven in part by new AI-assisted detection tools, includes fixes for 113 critical vulnerabilities.

By Beatriz Santos

Security Researchers 50%IT Administrators 30%Technology Analysts 20%
Security Researchers
Emphasize the urgency of patching the actively exploited zero-days and the challenges posed by the sheer volume of updates.
IT Administrators
Face the operational burden of testing and deploying a record number of patches across enterprise networks.
Technology Analysts
Focus on the role of AI in driving the record number of vulnerability discoveries and the long-term implications for software security.

Perspectives this story doesn't cover

  • End-users affected by potential downtime during patch deployment
  • Threat actors exploiting the zero-day vulnerabilities

Microsoft released a record-breaking 974 security patches on Tuesday, including fixes for two zero-day vulnerabilities that attackers are already exploiting in the wild. The sheer volume of Common Vulnerabilities and Exposures (CVEs) addressed in the September 2026 update shatters previous records, presenting a significant deployment challenge for IT administrators globally.[1][2][4]

The massive patch load is largely attributed to Microsoft's recent deployment of advanced AI-assisted vulnerability detection tools within its internal security review processes. These tools have significantly increased the rate at which flaws are identified across the company's vast codebase, leading to the unprecedented number of fixes in a single monthly cycle.[7]

Among the 974 flaws, 113 are rated as "Critical," the highest severity level, indicating that they could allow remote code execution or significant system compromise without user interaction. The remaining vulnerabilities are classified as "Important" or "Moderate."[9]

Breakdown of the 974 vulnerabilities addressed in Microsoft's September 2026 Patch Tuesday.

The most urgent fixes address two zero-day vulnerabilities currently under active exploitation. The first, tracked as CVE-2026-38112, is a Windows MSHTML Platform Spoofing Vulnerability. This flaw allows an attacker to execute arbitrary code by convincing a user to open a specially crafted file or visit a malicious website.[1][2][3]

The most urgent fixes address two zero-day vulnerabilities currently under active exploitation.

The second actively exploited zero-day, CVE-2026-38831, is a Windows Mark of the Web (MotW) Security Feature Bypass Vulnerability. This flaw enables attackers to bypass security warnings that normally appear when a user attempts to open a file downloaded from the internet, facilitating the delivery of malware.[1][2][5]

Security researchers emphasize the critical need for immediate patching, particularly for the two zero-days. "The sheer volume of CVEs this month is staggering, but the immediate focus must be on the two exploited zero-days," noted analysts at Qualys in their review of the update. "Organizations need to prioritize these patches to mitigate the immediate risk of compromise."[8]

The update also includes patches for a wide range of Microsoft products, including Windows, Office, Exchange Server, and Azure components. The extensive list of affected software underscores the broad impact of the September Patch Tuesday and the necessity for comprehensive update strategies.[6][8]

While the AI-driven discovery of vulnerabilities has led to a record number of patches, it also highlights a proactive approach to identifying and addressing security flaws before they can be widely exploited. However, the resulting patch burden on IT departments remains a significant operational challenge.[7][9]

Key points

  • Microsoft released a record 974 security patches in its September 2026 Patch Tuesday update.
  • The update includes fixes for two zero-day vulnerabilities actively exploited in the wild.
  • 113 of the patched vulnerabilities are rated as 'Critical.'
  • The record volume of patches is attributed to Microsoft's use of AI-assisted vulnerability detection tools.

Why this matters

The unprecedented volume of patches, driven by new AI detection tools, means IT departments face a massive deployment burden this month. The inclusion of two actively exploited zero-days requires immediate action to secure enterprise networks.

Sources

Source coverage

9 outlets

3 viewpoints surfaced

Security Researchers 50%IT Administrators 30%Technology Analysts 20%
  1. [1]SecurityWeekSecurity Researchers

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    Read on SecurityWeek
  2. [2]The Hacker NewsSecurity Researchers

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Read on The Hacker News
  3. [3]TechRadarTechnology Analysts

    Microsoft September 2026 Patch Tuesday fixes nearly a thousand flaws, including two major zero-days

    Read on TechRadar
  4. [4]Dark ReadingIT Administrators

    Patch Tuesday Sets Another Record With 974 CVEs

    Read on Dark Reading
  5. [5]Bleeping Computer

    Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

    Read on Bleeping Computer
  6. [6]TechRepublicIT Administrators

    Microsoft Fixes 974 Flaws in Record Patch Tuesday

    Read on TechRepublic
  7. [7]PC GamerTechnology Analysts

    Microsoft's AI vulnerability detection results in record-breaking Patch Tuesday, addressing 974 security flaws

    Read on PC Gamer
  8. [8]QualysSecurity Researchers

    Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

    Read on Qualys
  9. [9]CrowdStrikeSecurity Researchers

    September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

    Read on CrowdStrike

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.