LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
vulnerability

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and d

zeroday.news ·

Photo: Tyler Lahti (CC BY-SA 4.0) via Wikimedia Commons

Microsoft has released an unprecedented number of security updates, addressing 974 vulnerabilities across its Windows operating systems and other software. This marks the largest single patch batch in the company's history, significantly surpassing the previous record of 570 fixes issued in July. The total number of vulnerabilities patched by Microsoft in 2026 has now exceeded 2,600, more than double the 1,245 addressed in 2020, which was previously a record year.

Among the extensive list of fixes, 113 vulnerabilities were rated as "critical," indicating they could allow an attacker to take control of a vulnerable Windows machine with minimal or no user interaction. Two of these critical flaws are actively being exploited as zero-days: CVE-2026-81963 and CVE-2026-85880, both of which permit privilege escalation on Windows systems.

One particularly severe critical flaw is CVE-2026-69730, a DNS weakness affecting Windows Server 2012 and later, as well as Windows 10. Microsoft has warned that an unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected system, and has indicated that exploitation is likely. Another critical vulnerability, CVE-2026-69829, is a remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 out of 10 and can be exploited with low attack complexity, requiring no privileges or user interaction.

Microsoft attributes the increased volume of vulnerability discoveries, in part, to the assistance of artificial intelligence in security research. Other major software vendors, including Adobe, Cisco, Google, Mozilla, and Oracle, have also reported an uptick in their patch cadence and volume, crediting AI-assisted research. Google, for instance, has announced it will now release security updates every two weeks.

However, the surge in patches presents a significant challenge for organizations. Deploying such a large number of updates each month requires extensive testing to ensure compatibility with third-party software and to avoid disruptions to business operations. Security experts emphasize the need for organizations to prioritize which vulnerabilities are most relevant and exploitable within their specific environments, rather than attempting to address every single fix.

While regular Windows users do not typically need to test patches, it remains crucial for them to regularly apply updates through Windows Update to protect their systems. Given the escalating size of these monthly patch releases, it is advisable not to defer updates for extended periods. Enterprise administrators are encouraged to monitor community resources for any reports of updates causing unexpected issues.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.