Microsoft Fixes 973 Vulnerabilities, Including 2 Zero-Days Exploited in the Wild
Microsoft released its Patch Tuesday update for September 2026, addressing a total of 973 vulnerabilities across various products. This includes two zero-day vulnerabilities that have been exploited in the wild.
The most critical vulnerability is CVE-2026-81963, which affects Windows Update Stack and has been exploited as a zero-day. The other zero-day vulnerability is not specified by Microsoft, but it is considered to be just as severe.
Other notable vulnerabilities include a remote code execution (RCE) flaw in the Print Spooler service (CVE-2026-85877), an elevation of privilege (EoP) issue in Windows Biometric Service (multiple CVEs), and a spoofing vulnerability in Microsoft Authentication Library for Node.js (CVE-2026-84003).
Microsoft has provided patches for all the identified vulnerabilities, and users are advised to apply them as soon as possible to prevent any potential attacks.