Microsoft has released patches for an unprecedented 973 vulnerabilities as part of its latest Patch Tuesday update, a new record for the company. Among these, two specific vulnerabilities, identified as CVE-2026-81963 and CVE-2026-85880, are confirmed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to be actively exploited in the wild.
Federal agencies have been directed to apply patches for these two actively exploited vulnerabilities by September 22. CVE-2026-81963 impacts a component integral to the installation of Windows updates, while CVE-2026-85880 affects a messaging system within the Windows operating environment.
Security experts highlight the critical nature of CVE-2026-81963, noting that a compromise of the update stack could grant attackers persistent control over a system, making remediation difficult. This type of vulnerability often serves as an initial step in a broader attack chain, potentially allowing an attacker to escalate privileges after an initial phishing compromise.
The sheer volume of vulnerabilities addressed this month surpasses Microsoft's previous record of over 600 fixes in July, which itself was triple the number from the preceding month. The total number of bugs disclosed by Microsoft this year has now exceeded 2,600, more than double the previous annual record set in 2020.
Concerns have been raised by cybersecurity researchers regarding the increasing number of minor vulnerabilities, which some attribute to the widespread adoption of artificial intelligence tools for code review. These smaller flaws can often be chained together to facilitate more significant and dangerous attacks.
In related news, Adobe also announced a critical-severity vulnerability affecting its Adobe Commerce product this month. Meanwhile, an estimated 22,000 corporate Exchange servers reportedly remain unpatched against weaponized exploit code, according to cybersecurity analysis.






