Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft has released a record number of patches to fix 974 CVEs across its products. This includes two vulnerabilities that have been exploited in the wild as zero-days.
The first zero-day, CVE-2026-85880, is a heap buffer overflow issue in Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. Microsoft has not patched an ALPC flaw since April 2023.
The second zero-day, CVE-2026-81963, is an improper link resolution before file access defect in Windows Update Stack. This vulnerability also allows local attackers to elevate their privileges to System.