# Microsoft Sets New Record with Patch Tuesday, Fixes Nearly 1000 Vulnerabilities

*Published September 11, 2026*
*Source: [https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html](https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/microsoft-sets-new-record-with-patch-tuesday-fixes-nearly-1000-vulnerabilities) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Microsoft has made history with its latest Patch Tuesday, addressing an unprecedented 974 vulnerabilities across its software products, including two critical zero-day exploits. This massive update includes 723 flaws in Windows, 111 in Office, 62 in SQL, and 22 in Developer Tools. Of the total vulnerabilities, over 110 have been classified as critical, focusing on privilege escalation, remote code execution, and information disclosure. This brings the total number of vulnerabilities addressed this month to 999, including 25 non-Microsoft CVEs. 

The significant volume of patches in September follows a steady increase in vulnerability fixes from previous months, with 457 in August and 663 in July. The sheer number of updates presents a challenge for IT and security teams, who need to prioritize critical vulnerabilities over less urgent ones. Notably, the actively exploited vulnerabilities include CVE-2026-85880 and CVE-2026-81963, both of which have been added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog. This requires Federal Civilian Executive Branch agencies to apply the necessary fixes by September 22, 2026. 

Cybersecurity firms, including Volexity and Proofpoint, and researchers from Airbus Helicopters and Microsoft's Threat Intelligence Center have been instrumental in identifying these zero-day exploits. While the identity of the attackers remains undisclosed, the scale of exploitation efforts is concerning. Despite the large number of patches, the impact on most organizations is expected to be minimal, with many vulnerabilities not posing immediate threats. Organizations must evaluate which vulnerabilities are relevant and prioritize them accordingly. 

The record-breaking patch count indicates a proactive approach to reducing the attack surface, with Microsoft and other major software vendors continually striving to address vulnerabilities before they can be exploited. This trend is likely to continue as AI-assisted vulnerability discoveries evolve.
