The Record from Recorded Future News·4 min read·medium

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

J
Jonathan Greig
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
AI Summary

Microsoft has released a record-breaking 973 security patches this month, with CISA warning that two specific vulnerabilities are already being actively exploited. Cybersecurity experts suggest that the surge in minor bugs may be linked to the increased use of AI-assisted coding tools.

Why it matters

The massive volume of vulnerabilities poses a significant risk to corporate infrastructure, particularly Exchange servers, and highlights the potential security trade-offs of AI-driven software development.

Dive DeeperCreate a free account to unlock

Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time.

The federal cyberdefense agency, CISA, confirmed that two of them — CVE-2026-81963 and CVE-2026-85880 — are being exploited by hackers. Federal agencies have until September 22 to patch them.

Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows. More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.

Others explained that bugs like CVE-2026-81963 are the first step in a ransomware chain where hackers phish one user and use their access to gain escalated privileges.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in