Patch Tuesday Sets Another Record With 974 CVEs
Microsoft released a massive Patch Tuesday update with 974 new vulnerabilities, including two actively exploited zero-day flaws and a cluster of 20 wormable bugs. The sheer volume of vulnerabilities, driven by AI-assisted vulnerability discovery, presents a significant challenge for security teams, but experts emphasize that the actual risk to most organizations remains relatively low if they prioritize actively exploited bugs and vulnerabilities relevant to their specific environments. The trend of increasingly large Patch Tuesdays is expected to continue, but the overall attack surface is shrinking as vulnerabilities are addressed.
Microsoft released a substantial security update this month, containing 974 unique vulnerabilities, marking a record for the company. Attackers are currently exploiting two of these vulnerabilities, and another 58 are considered more likely to be targeted due to low attack complexity and high impact. Windows accounted for the majority of the vulnerabilities, with 723, followed by Office and Office 2016 (111 each). The remaining vulnerabilities were spread across other Microsoft technologies, including 62 in SQL, 22 in Developer Tools, 16 in SharePoint Server, and 12 in Azure.
This trend of increasingly large Patch Tuesdays is a result of Microsoft’s growing use of AI to discover vulnerabilities across its technology portfolio. Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, highlighted CVE-2026-69380 (CVSS:8.1), a Microsoft Exchange Server EoP, as a critical vulnerability that should be patched immediately, as it allows low-privileged attackers to impersonate any user and hijack every mailbox. He also pointed to a cluster of 20 wormable CVEs, including a Windows DNS Server flaw (CVE-2026-69730 CVSS:9.8), which poses a significant risk of self-propagating contagion across enterprise networks.
Action1 researchers identified three near-maximum severity (CVSS: 9.8) RCE bugs that should be prioritized: CVE-2026-69829, an RCE in Windows Shell; CVE-2026-69595, an RCE in Windows Services for NFS ONCRPC XDR Driver; and CVE-2026-78510, a Microsoft Word RCE. Amol Sarwate, head of security research and REDLab at Cohesity, advised organizations to prioritize vulnerabilities in the Windows identity and infrastructure plane, noting that attackers could exploit these flaws by sending unauthenticated packets to DNS, DHCP, RDS, and Netlogon listeners on domain controllers and Microsoft Exchange.
Despite the massive increase in vulnerability discovery, experts emphasize that the actual risk to most organizations remains relatively low. Satnam Narang, senior staff research engineer at Tenable, noted that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains low. Tyler Reguly, associate director of security R&D at Fortra, predicted that this trend of large Patch Tuesdays will eventually subside as long-standing, hard-to-find vulnerabilities are addressed, reducing the overall attack surface. Security teams should focus on understanding which vulnerabilities apply to their specific environments and prioritize based on risk context.
