Microsoft patched 974 defects in its largest-ever Patch Tuesday update, including two actively exploited zero-day vulnerabilities in the Windows Update Stack and Windows Advanced Local Procedure Call. Security experts said AI-assisted vulnerability discovery is increasing the number of disclosed flaws, but it has not yet caused a matching surge in real-world exploitation. #CVE-2026-81963 #CVE-2026-85880 #WindowsUpdateStack #WindowsAdvancedLocalProcedureCall
Keypoints
- Microsoft fixed 974 vulnerabilities in its monthly Patch Tuesday release.
- Two zero-days were actively exploited before disclosure.
- The exploited flaws affected the Windows Update Stack and Windows Advanced Local Procedure Call.
- More than 10% of the patched issues were rated critical.
- Researchers urged teams to prioritize vulnerabilities based on real exposure and risk.
Read More: https://cyberscoop.com/microsoft-patch-tuesday-september-2026/