
Microsoft Patches Record 974 Flaws Including Two Actively Exploited Windows Zero-Days
Microsoft's largest Patch Tuesday to date resolved 974 vulnerabilities with two confirmed zero-days under active exploitation. Official attribution remains limited while procurement and incident data reveal ongoing structural weaknesses in Windows components. Federal agencies must patch by September 22 or face compliance exposure.
The pattern of repeated sandbox escapes and Update Stack weaknesses indicates systemic issues in how Microsoft prioritizes defensive hardening versus feature delivery. Agencies and enterprises now face compressed timelines to triage hundreds of patches while monitoring for follow-on campaigns. Next indicators will appear in CISA KEV additions and any Microsoft Threat Intelligence reports that name specific tooling or infrastructure tied to the two CVEs.
CISA: At least 40 percent of FCEB agencies will report incomplete patching of CVE-2026-85880 by the September 22 deadline.
Sources (3)
- [1]Microsoft Security Response Center September 2026 Advisory(https://msrc.microsoft.com/update-guide)
- [2]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [3]Tenable Research Windows Update Stack Analysis(https://www.tenable.com/research)