Microsoft Unleashes Record-Breaking 966 Patch Tuesday Update Amidst Rising Vulnerability Concerns
Microsoft released its September Patch Tuesday update, which addressed a record-breaking 966 vulnerabilities across various Windows and Azure services. This is the largest monthly patch batch in the program's history, surpassing the previous record set just one month earlier in August 2026.
Two of these vulnerabilities were confirmed as actively exploited zero-days prior to the patch release and had already been added to the Known Exploited Vulnerabilities catalog maintained by the US Cybersecurity and Infrastructure Security Agency. Another 20 are classified as 'wormable', meaning an attacker could jump from one unpatched machine to the next without a single click from a user.
The wormable flaws affect DHCP, MSMQ, NFS, and SSTP VPN services, which are common in corporate environments. The unauthenticated DNS remote code execution bug researchers are calling a successor to the infamous 2020 SigRed vulnerability is also of great concern. This bug allows an attacker to execute code on vulnerable servers without valid credentials.
The sheer scale of this patch release has forced security teams to question whether monthly patching can keep pace with the speed at which vulnerabilities are being found and weaponized.