Microsoft Tackles Record-Breaking 974 Vulnerabilities
Microsoft released its largest-ever Patch Tuesday security update, addressing 974 defects across its product suite. The update included two actively exploited zero-day vulnerabilities, specifically CVE-2026-81963 and CVE-2026-85880, which affect the Windows Update Stack and Windows Advanced Local Procedure Call respectively.
The two zero-day vulnerabilities have a CVSS rating of 7.8, allowing attackers to escalate privileges. More than one in ten defects disclosed this month are rated critical, with 723 affecting Windows, 111 each in Office and Office 2016, 62 in SQL, and 22 in various developer tools.
Researchers are advising security teams not to get overwhelmed by the number of defects but instead focus on specific areas of risk and exposure. According to Satnam Narang, senior staff research engineer at Tenable, AI-assisted vulnerability discovery 'is creating larger haystacks, but it isn’t finding more needles.'