Microsoft Patch Tuesday Hits Record 999 Vulnerabilities Amid Exploited Flaws
Microsoft released its latest Patch Tuesday update, which addressed a staggering 999 vulnerabilities across various products. This is the highest number of CVEs (Common Vulnerabilities and Exposures) Microsoft has ever published in a single day.
Rapid7 analyzed the patch release and found that two of these vulnerabilities are already being exploited in the wild. Both flaws affect Windows components, specifically the Windows Advanced Local Procedure Call mechanism and the Windows Update Stack, allowing attackers to gain SYSTEM privileges through buffer overflows or improper link resolution.
The absence of a corresponding security advisory for Google Chrome's fix of CVE-2026-85046 is also raising concerns. Rapid7 notes that this could lead to defenders missing zero-day vulnerabilities altogether, especially given the rising volume of vulnerabilities Microsoft is processing.