Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The new record total for Patch Tuesday is 973 vulnerabilities.
Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time.
The federal cyberdefense agency, CISA, confirmed that two of them — CVE-2026-81963 and CVE-2026-85880 — are being exploited by hackers. Federal agencies have until September 22 to patch them.
Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows. More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.
Source: https://therecord.media/microsoft-patch-tuesday-september-2026
Related breach coverage
- Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs2026-09-09
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 and 997 CVEs in this update. The company also […]
- Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk2026-09-14
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]
- U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog2026-09-10
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a […]
- U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog2026-08-28
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let […]