LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
vulnerabilitycritical

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates

zeroday.news ·

Photo: Ank Kumar (CC BY-SA 4.0) via Wikimedia Commons

Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due to the company's use of agentic AI tools for discovering zero-day vulnerabilities.

The September update, released on September 8, addressed a wide array of products, with Windows accounting for the majority of fixes at 723 CVEs, followed by Office with 111. The past three months have shown a clear upward trend in the number of CVEs patched, with 570 in July, 400 in August, and the current 974 in September. This contrasts with earlier figures for the year, which included 200 CVEs in June, 120 in May, and 164 in April.

Among the 974 CVEs, 119 were rated as critical. Microsoft specifically highlighted two zero-day flaws that were confirmed to be actively exploited by threat actors at the time of the update. The first, CVE-2026-85880, is a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC). Rated with a high severity score of 7.8, this flaw could allow an attacker with low-privilege AppContainer code execution to achieve local privilege escalation. The second actively exploited flaw, CVE-2026-81963, involves improper link resolution before file access in the Windows Update Stack, enabling an authorized attacker to elevate privileges locally.

Given the unprecedented scale of the September update, security experts emphasized the need for a risk-based approach to vulnerability management. The challenge for IT and security teams is to quickly identify and prioritize vulnerabilities that demand immediate attention from those that can follow a standard deployment cycle.

Several other vulnerabilities were identified as high-priority for patching. These include CVE-2026-62878, a critical remote code execution (RCE) vulnerability in Windows DNS Server stemming from a stack-based buffer overflow, with a severity rating of 9.8. Another critical RCE, CVE-2026-62893, affects Windows Deployment Services due to a use-after-free condition, also rated 9.8.

Additional high-severity RCE vulnerabilities include CVE-2026-62823 in Windows DHCP Server, caused by a heap-based buffer overflow and rated 8.8, and CVE-2026-65789 in Windows DNS, resulting from a use-after-free condition and rated 8.1. The update also addressed three critical vulnerabilities, CVE-2026-58231, spanning Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver and ABAP Platform.

vulnerabilityzero-daypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.