Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Microsoft Patches Record 974 Bugs in September, Two Already Under Attack

Microsoft shipped security fixes for roughly 974 vulnerabilities on Tuesday, September 8, 2026, the biggest Patch Tuesday release the company has ever put out. Exact counts differ slightly depending on how researchers tally third-party and Chromium-based bugs bundled into Microsoft's Edge browser. Security Affairs cites a range of 966 to 997. PCWorld reported 973. Zero Day Initiative researcher Dustin Childs put the core number near 972, climbing to roughly 997 once Edge's Chromium ports are folded in. Socradar and multiple other outlets settled on 974 as the headline figure. The differences come down to methodology, not disagreement about the scale of the problem.
Two of the flaws are already being used by hackers in the wild. CVE-2026-85880, a heap buffer overflow in the Windows Advanced Local Procedure Call component, lets a local attacker who already has a foothold escalate to SYSTEM-level privileges. Tenable senior staff research engineer Satnam Narang noted it is only the second ALPC zero-day Microsoft has patched since January 2023. CVE-2026-81963, an improper link-resolution flaw in the Windows Update Stack, is the first Update Stack bug Microsoft has confirmed under active attack. Both carry a CVSS score of 7.8 and require an attacker to already have local, low-privilege access, meaning they're typically the second stage of an attack, not the initial break-in.
CISA added both to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies until September 22, 2026, to patch, according to time.news. That's a two-week window for a bug already being exploited, which illustrates the gap between government urgency timelines and attacker speed once a foothold is confirmed.
The bug drawing the most alarm isn't one of the exploited zero-days. It's CVE-2026-55007, a remote code execution flaw in Exchange Server that an unauthenticated attacker can trigger by emailing a specially crafted Visio attachment. The server processes it during routine content indexing. No preview, no click, no user interaction required. Microsoft's own advisory says reliable triggering is difficult, but as Security Affairs put it, defenders are treating "once is enough" as the operating rule and scheduling Exchange downtime to patch it.
Zero Day Initiative counted about 20 wormable vulnerabilities in this release, meaning remote, unauthenticated code execution bugs that spread without a user clicking anything. Computer Weekly quoted Childs comparing the DNS Server flaw, CVE-2026-69730, to SigRed, the 2020 bug that raised fears of a Windows worm outbreak. "We haven't seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed, that reality could change fast," Childs told Computer Weekly. The wormable cluster also touches DHCP Server, Active Directory, SMB client, Netlogon, NFS, RRAS and Message Queuing, according to the unnamed compiled report reviewed for this story.
Other standout Critical bugs include CVE-2026-69829, a Windows Shell RCE with a CVSS score of 9.8 that needs no user interaction, and CVE-2026-69525, a Remote Desktop Services RCE also rated 9.8. Action1's Jack Bicer told Computer Weekly the challenge this month isn't grinding through the patch list, it's figuring out what to fix first when hundreds of updates land at once.
More than 22,000 corporate Exchange servers remain unpatched against weaponized exploit code targeting these flaws, according to Nightwing cybersecurity researcher Nick Carroll, speaking to time.news. That's not a hypothetical risk. It's a live target list.
The raw scale of this release is part of a longer trend, not a one-off spike. Krebs on Security, cited in reporting compiled this week, put Microsoft's year-to-date CVE total above 2,600, more than double the company's previous full-year record. Microsoft and outside researchers point to AI-assisted vulnerability discovery as the driver, letting security teams and Microsoft's own auditors find bugs faster than ever. ZDI's Childs made the point to Computer Weekly that Microsoft has already published more CVEs this year than in 2024 and 2025 combined, and there hasn't been a matching surge in active exploitation, at least not yet.
The tension is real. More disclosed bugs could mean better auditing catching problems before criminals do. It could also mean the sheer volume overwhelms security teams who can't triage a thousand fixes a month, leaving critical ones like the Exchange and DNS flaws sitting unpatched on real networks. With 22,000 exposed Exchange servers already identified and a wormable DNS bug on the table, the next few weeks will show which scenario unfolds.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.