Skip to content
Microsoft shatters Patch Tuesday record with nearly 1,000 fixes released
Photo by Diana Polekhina / Unsplash

Microsoft shatters Patch Tuesday record with nearly 1,000 fixes released

Two Windows bugs are being actively exploited, and there a total of 121 critical CVEs addressed in the latest post-AI monthly release.

Microsoft warned customers earlier this year that the monthly Patch Tuesday ritual was about to level up, and this month's release delivered, setting a new record by addressing just under 1,000 vulnerabilities in an epic release.

There are so many vulnerabilities addressed in this update that different sources came up with different totals; Microsoft itself said there were 974 CVEs addressed, while security researchers at Trend Micro's Zero-Day Initiative put the total at 997. But no matter how you slice it, "with hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle," said Action1's Jack Bicer in a blog post.

See also: Patching in the AI era: Move fast, even if it breaks things

Everyone agrees on the two Windows patches that should be immediately applied, given that Microsoft advised customers that those vulnerabilities are under active exploitation.

The first one, CVE-2026-85880, involves a "heap-based buffer overflow in Windows ALPC [that] allows an authorized attacker to elevate privileges locally, and was given a score of 7.8 out of 10. The second, CVE-2026-81963, fixes "improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally."

ZDI recommended applying patches for important flaws in Exchange and SQL Server next, given how they could allow remote code execution and escalation of privilege attacks, respectively. In total, there were 121 flaws that earned a CVE "critical" rating, but some of those are harder to exploit than others.

Number go up

The release of powerful cybersecurity models from Anthropic and OpenAI earlier this year opened the floodgates, as security researchers across the industry realized the new models could detect — and, in some cases, quickly exploit — vulnerabilities at a scale never contemplated by bulk-patching releases. According to ZDI, Microsoft has already released more patches in 2026 than it did in 2025 and 2024 — combined.

July's release contained more than 630 vulnerabilities, a record at the time, and after a brief respite in August Tuesday's release shattered the already-high expectations that Microsoft customers had for Patch Tuesdays.

"With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck," ZDI's Dustin Childs said in its blog post.

We keep our security reporting free out of public interest. Subscribing gets you full access to exclusive interviews, a 50% discount on our event tickets, and a warm fuzzy glow for supporting independent journalism at a bootstrapped, management-owned publication.

You can support us here

Add The Stack on Google