Microsoft releases 974 security patches for different products – a new record

Microsoft releases 974 security patches for different products – a new record

This week, Microsoft released another set of security patches as part of its Patch Tuesday schedule. The company fixed 974 vulnerabilities in various software products, setting a new monthly record. Of these, 113 received a critical assessment: Exploitation of such bugs could lead to particularly severe consequences, including remote code execution without user involvement.

    Image source: Microsoft

Image source: Microsoft

According to multiple estimates, Microsoft has closed more than 2,600 vulnerabilities since the beginning of 2026, and some researchers have counted 2,760 patched CVEs. That’s more than double the previous annual record: the company fixed about 1,250 vulnerabilities in 2020. The previous monthly high was set in July 2026, when Microsoft fixed 570 vulnerabilities. In August, their number dropped to 415.

One reason for the accelerated pace of vulnerability discovery is the use of artificial intelligence technology. Artificial intelligence can help developers and researchers quickly find bugs that might have gone undetected for a long time. This doesn’t mean that Microsoft products have suddenly become less secure: First, the number of issues being discovered and fixed has increased.

At the same time, artificial intelligence affects both sides of network security and can be used not only to discover vulnerabilities, but also to create means to exploit vulnerabilities. Demonstrations of such attacks already exist, but there is no evidence that the use of artificial intelligence has led to a corresponding increase in large-scale attacks. Therefore, the increase in the number of CVE closures mainly reflects an increase in vulnerability hunting efficiency rather than a dramatic escalation of threats.

Image source: Microsoft/KrebsOnSecurity

The most dangerous vulnerability that has been fixed is CVE-2026-69730, with a CVSS score of 9.8 out of 10. This use-after-free bug exists in the Windows DNS Server service and affects systems with Windows Server 2012 and newer server versions, as well as some versions of Windows 10. An unauthenticated attacker can remotely execute code by sending specially crafted network packets to a vulnerable system. Microsoft believes this vulnerability is likely to be exploitable.

CVE-2026-69829 is a buffer overflow vulnerability in the Windows shell and received the same CVSS score of 9.8. It allows you to remotely execute code without prior authentication and user involvement, and the attack complexity is rated as low.

Additionally, the update fixes two zero-day vulnerabilities that have been used in real-world attacks. CVE-2026-81963 is related to Windows update stacking, and CVE-2026-85880 is related to the Windows high-level native program call mechanism. Both allow an attacker who already has the ability to execute code on the computer to escalate their privileges to the system.

The record number of patches creates additional workload for enterprise system administrators. Before an update is rolled out on a large scale, they must check whether the fix is ​​compatible with the software they are using. For home users, unless you are using an older version or a customized program, it is recommended that you install new Windows updates as soon as possible.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version