news.mlab.sh
Back to the feed
vulnerability

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

HighCVSS 7.8
Summary

Microsoft released a massive Patch Tuesday update, exceeding 900 vulnerabilities, with two of them currently being actively exploited by hackers. The CISA has urged federal agencies to address these issues promptly, highlighting a significant increase in the total number of disclosed bugs this year. This surge in vulnerabilities underscores a growing trend of AI-assisted code review leading to more minor, yet potentially dangerous, security flaws.

Microsoft released its largest Patch Tuesday update to date, encompassing over 900 security vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that two of these vulnerabilities – CVE-2026-81963 and CVE-2026-85880 – are currently being exploited by malicious actors. Federal agencies are required to apply the necessary patches by September 22nd to mitigate the risk.

According to Tenable’s Satnam Narang, CVE-2026-81963 relates to a component used during Windows update installations, while CVE-2026-85880 affects a messaging system within Windows. Cybersecurity expert Nick Carroll reported that over 22,000 corporate Exchange servers remain unpatched, and are vulnerable to weaponized exploit code.

Analysts suggest that vulnerabilities like CVE-2026-81963 are often the initial step in a ransomware attack sequence, where attackers leverage initial access gained through phishing to escalate privileges and deploy more damaging payloads.

“The component makes it worse,” said Automox engineer Serena DiPenti. “An attacker who owns the update stack owns the thing you'd use to evict them.”

Microsoft’s Patch Tuesday release marks a substantial increase in the total number of disclosed bugs, with over 2,600 vulnerabilities announced this year – more than double the previous record set in 2020. Qualys cybersecurity expert Diksha Ojha also highlighted a critical-severity bug announced by Adobe this month within Adobe Commerce.

Researchers have cautioned that the increasing use of AI-powered code review tools could lead to a proliferation of minor vulnerabilities that can be combined to create dangerous attack vectors.

Read the full article at The Record