Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft released a record-breaking set of security patches addressing 974 vulnerabilities, including two zero-day flaws currently being exploited. Security experts emphasize the need for IT teams to prioritize these critical updates.
Why it matters
The massive scale of these vulnerabilities poses a significant risk to global enterprise and consumer systems, necessitating urgent patching.
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.
These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month. Along with Microsoft's fixes for 25 non-Microsoft CVEs, the update brings the total number of vulnerabilities resolved to 999.
September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July , 220 in June , and 161 in May .
Also covering this story
4 other newsrooms covered this event. We read each version separately.
Microsoft breaks another patch Tuesday record
Microsoft Releases Record September Patch Tuesday Fixing 900+ Flaws Including Two Exploited Zero-Days
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
Microsoft breaks Patch Tuesday record with 974-CVE deluge
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in