Microsoft patches a record 974 flaws, and two are already under attack

https://media.thenextweb.com/2026/08/Microsoft-logo.jpg

Microsoft’s September Patch Tuesday fixes 974 security flaws across its products, according to the company’s release notes. Attackers were already exploiting two of them before the patches landed on Tuesday.

Both zero-days let an attacker who already has a foothold on a Windows machine gain higher privileges. One sits in the Windows Update Stack (CVE-2026-81963), the other in the Advanced Local Procedure Call component (CVE-2026-85880). There is no public detail yet on who is exploiting them or how widely, as Dan Goodin reported for Ars Technica. Dustin Childs of the Zero Day Initiative, who reviews every monthly release, called it a new record.

Childs doubts attackers have hijacked the update mechanism itself. His more likely reading is that attackers pair the Update Stack bug with a code execution flaw. That combination can spread malware or ransomware. His advice on both is to patch...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE