Microsoft Corp. today released updates that plug at least 974 security holes in its Windows operating systems and other software, marking its biggest single patch batch ever.
The September Patch Tuesday bundle surpasses the previous record set in July, when Microsoft issued updates for at least 570 vulnerabilities, and brings this year’s total to more than 2,600, exceeding the 2020 record of 1,245 with three months remaining.
Two vulnerabilidades ainda não divulgadas, CVE 2026 81963 and CVE 2026 85880, allow an attacker to elevate privileges on Windows systems.
113 of the issues received a critical rating, meaning they could be exploited by malware to take control of a vulnerable Windows machine with little or no user assistance. The most serious critical flaw is CVE 2026 69730, a DNS weakness affecting Windows Server 2012 and Windows 10, which an unauthenticated attacker can trigger by sending a crafted packet, and which is likely to be exploited. Another critical flaw, CVE 2026 69829, is a remote code execution bug in the Windows Shell with a CVSS base score of 9.8, exploitable with low attack complexity, no privileges and no user interaction.
Other major vendors, including Adobe, Cisco, Google, Mozilla and Oracle, have also credited research based on IA for speeding their patch cadence, and Google announced it will issue security updates every two weeks.
Tyler Reguly, associate director of security research and development at Fortra, said that deploying Windows updates requires testing before rollout because not all software from terceiros works seamlessly with OS changes. He warned that teams may need to work fora do horário comercial e nos fins de semana para evitar interrupções ao ambiente de negócios, and asked whether managers reward such effort.
Satnam Narang, senior staff research engineer at Tenable, noted that while the number of vulnerabilities Microsoft patches is rising, the actual impact on most organizations remains limited. He explained that descoberta de vulnerabilidades baseada em IA in 2026 creates larger haystacks but does not increase the number of exploitable needles, so organizations must assess which flaws are reachable and prioritize remediation based on risk context.
Regular Windows users can simply open Windows Update periodically to avoid pending update notifications, while enterprise administrators should monitor askwoody.com for problematic patches and consult the SANS Internet Storm Center for a breakdown of severity per patch.