Microsoft's Record-Breaking Patch Tuesday Brings Security Chaos
Microsoft's September Patch Tuesday update cycle has broken records with an unprecedented number of security vulnerabilities. The patch release, which is part of a long-standing tradition of updating all products on the second Tuesday of every month since October 2003, covers 973 vulnerabilities. Of these, 119 have been rated critical, and two are known to have been exploited in the wild.
The good news is that updates are available for all vulnerabilities, including the two Windows zero-days, CVE-2026-85880 and CVE-2026-81963. However, with so many vulnerabilities announced at once, enterprises may struggle to prioritize which ones need immediate attention.
Cybersecurity experts recommend using a tiered patching SLA mechanism, where KEV-listed CVEs are patched within 24-36 hours, and the next tier includes internet-facing high-privilege infrastructures. Severity scores alone are not enough; everything needs to be put into the context of risk to the enterprise.