Interestana
Home/News/Microsoft Patches 974 Security Vulnerabilities in Record Batch
Krebs on Security3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Patches 974 Security Vulnerabilities in Record Batch

Microsoft Patches 974 Security Vulnerabilities in Record Batch

Microsoft Corp. released its largest-ever security update on September 10, 2024, addressing at least 974 security holes across its Windows operating systems and other software. This massive patch batch significantly surpasses the company's previous record of 570 vulnerabilities patched in July 2024. The September "Patch Tuesday" brings the total number of vulnerabilities addressed in 2024 to over 2,600, more than double the previous record year of 2020, which saw 1,245 vulnerabilities patched, with three months still remaining in the current year.

Among the 974 vulnerabilities fixed, two "zero-day" flaws, identified as CVE-2026-81963 and CVE-2026-85880, were actively being exploited at the time of the release. Both of these vulnerabilities allow an attacker to elevate their privileges on a Windows system, granting them unauthorized access and control. In addition to these zero-days, a substantial 113 of the bugs patched this month were classified by Microsoft as "critical." This critical rating signifies that these vulnerabilities could be exploited by malicious actors or malware to gain complete control over a vulnerable Windows machine with minimal user interaction or assistance.

Several critical flaws highlighted by Microsoft include CVE-2026-69730, a weakness in the Domain Name System (DNS) present in Windows Server 2012 and later versions, as well as Windows 10. Microsoft has warned that an unauthenticated attacker could exploit this vulnerability by sending a specially crafted network packet to an affected system, and that exploitation is considered likely. Another significant critical vulnerability is CVE-2026-69829, a remote code execution flaw within the Windows Shell. This vulnerability carries a high CVSS base score of 9.8 out of 10, indicating its severity, and can be exploited with low complexity, without requiring administrative privileges, and without any user interaction.

Microsoft attributes the increasing volume of discovered vulnerabilities, in part, to the growing capabilities of artificial intelligence in identifying security weaknesses. However, security experts caution that the sheer number of patches presents a significant challenge for organizations. Many companies are already struggling to effectively prioritize and deploy the necessary human-intensive testing and implementation of monthly security fixes, a task that becomes even more complex with such a large volume of updates. This trend of increasingly large patch bundles is not unique to Microsoft, as other major software companies are also releasing substantial updates to address a growing number of security issues.

Original source — read the full reporting at the publisher:

Read on Krebs on Security

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next