Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time.
The federal cyberdefense agency, CISA, confirmed that two of them — CVE-2026-81963 and CVE-2026-85880 — are being exploited by hackers. Federal agencies have until September 22 to patch them.
Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows. More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.
Others explained that bugs like CVE-2026-81963 are the first step in a ransomware chain where hackers phish one user and use their access to gain escalated privileges.
“The component makes it worse. An attacker who owns the update stack owns the thing you'd use to evict them,” Automox engineer Serena DiPenti said. “If you can't say when the update stack last ran, you can't say whether it's patched.”
The two are among 973 bugs disclosed on Patch Tuesday by Microsoft. The company set a previous record in July with fixes for more than 600 security vulnerabilities — which itself was triple the size of the previous record set the month before.
Cybersecurity researchers and defenders have warned for months that the use of artificial intelligence code-review tools would prompt an onslaught of minor vulnerabilities that could be chained together for dangerous attacks.
Narang noted that the latest Patch Tuesday release pushes the year’s total bugs disclosed over 2,600, which is already more than double the previous record-setting year of 2020. Qualys cybersecurity expert Diksha Ojha added that another vulnerability announced by Adobe this month was a critical-severity bug in Adobe Commerce.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



