Microsoft has released its monthly Patch Tuesday security update, addressing a record 974 vulnerabilities across its product suite. This extensive update includes fixes for two actively exploited zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, both of which allow for privilege escalation and have a CVSS rating of 7.8.
The vulnerability CVE-2026-81963 impacts the Windows Update Stack, while CVE-2026-85880 affects Windows Advanced Local Procedure Call. These zero-days were being actively exploited prior to Microsoft's disclosure and subsequent patching.
The sheer volume of vulnerabilities disclosed this month marks Microsoft's largest ever, a trend attributed by some researchers to the increasing use of artificial intelligence in vulnerability discovery. Despite this record number of disclosures, there has not been a corresponding surge in actively exploited zero-days.
More than 10% of the defects addressed in this update are rated as critical. The patches span a wide range of Microsoft products, with 723 vulnerabilities found in Windows, 111 in Office, 111 in Office 2016, 62 in SQL, and 22 across various developer tools.
Security experts advise organizations not to be overwhelmed by the total number of vulnerabilities, but rather to prioritize remediation based on their specific risk exposure. The increasing number of disclosed vulnerabilities, particularly with AI assistance, means a larger overall pool of potential issues, but not necessarily a higher number of immediately actionable threats for every organization.
It is crucial for security teams to identify which vulnerabilities are applicable to their systems, assess their exploitability and reachability, and then prioritize patching efforts accordingly. The challenge lies in discerning which vulnerabilities demand immediate attention versus those that can follow a standard deployment cycle.
The full list of vulnerabilities addressed in this month's update is available through Microsoft's Security Response Center.






