Security/ microsoft · patch tuesday · zero-day · windows security

Microsoft Patches 974 Bugs, Two Already Under Attack

Microsoft's record-setting September update fixes 974 flaws, but two privilege-escalation zero-days were already being exploited when it shipped.

Microsoft's biggest Patch Tuesday yet also carried two bugs attackers were already using before the fixes landed.

The September update closes 974 security flaws across Windows and other Microsoft products, the company said in its release notes - the largest single batch in Patch Tuesday's history. Two of those flaws were already under active attack when the update shipped on Tuesday. Both let someone who already has a foothold on a Windows machine escalate to higher privileges rather than break in from scratch. Microsoft identified one as CVE-2026-81963, a flaw in the Windows Update Stack; its release notes do not specify a CVE number or affected component for the second exploited flaw.

That gap matters because privilege-escalation zero-days are usually the second half of a real-world intrusion. Attackers rarely walk through a locked front door - they phish a low-level account or drop malware first, then use a bug like this to become an administrator. A record patch count grabs headlines, but it's the two flaws already in criminals' hands that security teams need to prioritize this week.

974 fixes in a single release is a lot of ground to cover, and it's a reminder that "record" Patch Tuesdays are becoming routine as Microsoft's product surface keeps expanding.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →