Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
Microsoft’s latest Patch Tuesday set a new record with 973 disclosed bugs, including two actively exploited vulnerabilities tracked as CVE-2026-81963 and CVE-2026-85880. Researchers warned that thousands of unpatched Exchange servers and weaknesses in the Windows update stack could help attackers chain exploits into ransomware-style intrusions. #CVE-2026-81963 #CVE-2026-85880 #Microsoft #Windows #Exchange #AdobeCommerce

Keypoints

  • Microsoft disclosed 973 vulnerabilities in its latest Patch Tuesday release.
  • CISA confirmed active exploitation of CVE-2026-81963 and CVE-2026-85880.
  • Federal agencies must patch the two exploited flaws by September 22.
  • More than 22,000 corporate Exchange servers are still unpatched against weaponized exploit code.
  • Researchers warned that attackers can chain these bugs into privilege escalation and ransomware attacks.

Read More: https://therecord.media/microsoft-patch-tuesday-september-2026