news.mlab.sh
Back to the feed
vulnerability

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

CriticalCVSS 9.8
Summary

Microsoft released a record 974 security patches this Patch Tuesday, including two zero-day vulnerabilities that were actively being exploited. These flaws, primarily within Windows and its suite of products, could allow local attackers to gain elevated privileges. While the sheer number of patches is increasing, the number of vulnerabilities actually impacting most organizations remains relatively low, highlighting the importance of prioritizing remediation based on risk assessment.

Microsoft released a record 974 security patches this Patch Tuesday, including two zero-day vulnerabilities that were actively being exploited. The first, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that allows a local attacker to escape the sandbox and elevate privileges on the affected system, requiring no user interaction. The second zero-day, CVE-2026-81963, is an improper link resolution before file access defect in Windows Update Stack, also enabling local privilege escalation.

Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023. Multiple security issues were addressed across Windows (723), Office (222), SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9).

Several of the newly resolved vulnerabilities, including CVE-2026-55007 (RCE in Exchange Server), CVE-2026-80097 (EoP in Authenticator), CVE-2026-69465 (RCE in SharePoint), CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), are considered ‘wormable’ – meaning they can be exploited without authentication or user interaction.

According to ZDI’s Dustin Childs, 20 of the newly resolved vulnerabilities could be considered wormable.

Microsoft’s proactive approach to patching, alongside vendor efforts to reduce their attack surface, is leading to an increase in the number of patches released. However, a key takeaway is that the number of vulnerabilities that actually pose a significant threat to most organizations remains relatively low, emphasizing the need for careful prioritization and risk-based remediation strategies.

Read the full article at SecurityWeek