Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Microsoft patched 974 defects in its largest-ever Patch Tuesday update, including two actively exploited zero-day vulnerabilities in the Windows Update Stack and Windows Advanced Local Procedure Call. Security experts said AI-assisted vulnerability discovery is increasing the number of disclosed flaws, but it has not yet caused a matching surge in real-world exploitation. #CVE-2026-81963 #CVE-2026-85880 #WindowsUpdateStack #WindowsAdvancedLocalProcedureCall

Keypoints

  • Microsoft fixed 974 vulnerabilities in its monthly Patch Tuesday release.
  • Two zero-days were actively exploited before disclosure.
  • The exploited flaws affected the Windows Update Stack and Windows Advanced Local Procedure Call.
  • More than 10% of the patched issues were rated critical.
  • Researchers urged teams to prioritize vulnerabilities based on real exposure and risk.

Read More: https://cyberscoop.com/microsoft-patch-tuesday-september-2026/