{"id":26112,"date":"2026-09-18T10:11:56","date_gmt":"2026-09-18T18:11:56","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/18\/microsoft-plugs-nearly-1000-security-holes\/"},"modified":"2026-09-18T10:11:56","modified_gmt":"2026-09-18T18:11:56","slug":"microsoft-plugs-nearly-1000-security-holes","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/18\/microsoft-plugs-nearly-1000-security-holes\/","title":{"rendered":"Microsoft Plugs Nearly 1,000 Security Holes"},"content":{"rendered":"<p><strong>Microsoft Corp.<\/strong> today issued updates to plug at least 974 security holes in its <strong>Windows<\/strong> operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74285\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74285\" height=\"498\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/shutterstock_278764853.jpg\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74285\">Image: Shutterstock.com, Kirill Makarov.<\/p>\n<\/div>\n<p>This month\u2019s patch bundle obliterates the software giant\u2019s <a href=\"https:\/\/krebsonsecurity.com\/2026\/07\/microsoft-patches-a-record-570-security-flaws\/\" rel=\"noopener\" target=\"_blank\">previous record set in July<\/a>, when it released updates for at least 570 security vulnerabilities. September\u2019s Patch Tuesday brings this year\u2019s total to more than 2,600, more than twice Microsoft\u2019s previous record-setting patch year in 2020 (1,245) and with three more months to go.<\/p>\n<p>There are two \u201czero-day\u201d flaws fixed this month that are being actively exploited: both <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-81963\" rel=\"noopener\" target=\"_blank\">CVE-2026-81963<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-85880\" rel=\"noopener\" target=\"_blank\">CVE-2026-85880<\/a> allow an attacker to elevate their privileges on Windows system.<\/p>\n<p>Fully 113 of the bugs addressed today earned Microsoft\u2019s \u201ccritical\u201d rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.<span id=\"more-74277\"><\/span><\/p>\n<p>Among the more serious critical flaws this month is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-69730\" rel=\"noopener\" target=\"_blank\">CVE-2026-69730<\/a>, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.<\/p>\n<p>Also scary is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-69829\" rel=\"noopener\" target=\"_blank\">CVE-2026-69829<\/a>, a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.<\/p>\n<div class=\"wp-caption aligncenter\" id=\"attachment_74289\" style=\"width: 760px;\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-74289\" height=\"539\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/09\/msrc-sug-sept2026.png\" width=\"750\"\/><\/p>\n<p class=\"wp-caption-text\" id=\"caption-attachment-74289\">Microsoft\u2019s summary of the security updates released today. Image: msrc.microsoft.com.<\/p>\n<\/div>\n<p>Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).<\/p>\n<p><strong>Tyler Reguly<\/strong>, associate director of security research and development at <strong>Fortra<\/strong>, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.<\/p>\n<p>\u201cIt\u2019s time to put our CISOs and CSOs on notice,\u201d Reguly said. \u201cHow are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.\u201d<\/p>\n<p><strong>Satnam Narang<\/strong> is senior staff research engineer at <strong>Tenable<\/strong>. Narang said it\u2019s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.<\/p>\n<p>\u201cAI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn\u2019t finding more needles,\u201d he said. \u201cIt\u2019s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.\u201d<\/p>\n<p>Of course, regular Windows users don\u2019t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program\u2019s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it\u2019s probably best not to let them pile up month after month.<\/p>\n<p>Enterprise Windows admins will want to keep an eye on <a href=\"https:\/\/www.askwoody.com\/2026\/september-2026-windows-updates-are-released\/\" rel=\"noopener\" target=\"_blank\">askwoody.com<\/a> for news of any updates that appear to be causing problems. As always, the <strong>SANS Internet Storm Center<\/strong> has <a href=\"https:\/\/isc.sans.edu\/diary\/September%202026%20Microsoft%20Patch%20Tuesday\/33320\" rel=\"noopener\" target=\"_blank\">a per-patch breakdown<\/a> ordered by severity and urgency.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,32701],"tags":[28477,16740,29556,32765,17600,30064,32743,32752,32720,32338,31554,32702,30119,32739,31556,28752,32753,32754,16695,32759,32721,32258,32722,17774,32103,24608,32766,32767,32768,32769,32744,32745,32708,32709,32746,32710,32711,32713,32723,11740,32714,31558,24613,32747,32724,32725,11638,32726,32740,11869,28567,31016,11863,32755,32715,21409,32716,31561,30434,22313,32104,19277,32105,14947,32770,32717,32106,32760,31895,32056,32748,32718,16888,32761,32703,32704,22255,32749,32712,16696,22836,32750,31157,31158,19013,32727,32771,32772,32728,32756,32705,31162,31163,32729,32741,32719,31164,31030,32706,3765,15227,22691,27009,32730,32731,32732,8223,32751,20501,17220,32733,32734,31492,32762,26016,32735,32736,20502,32737,17061,16936,11884,32763,31636,32742,31564,32707,32757,31911,17006,32764,32773,17091,32738,28020,32758],"class_list":["post-26112","post","type-post","status-publish","format-standard","hentry","category-independent","category-kreb","tag-1password","tag-a-little-sunshine","tag-action1","tag-active-directory-federation-services","tag-adblock","tag-adblock-plus","tag-afd-sys","tag-ai-digital-humans","tag-aikido-security","tag-alfa-bank","tag-andtop-company","tag-atlas-data-privacy","tag-automox","tag-between-digital","tag-bitseller-expert-limited","tag-bitsight","tag-bitsight-trace","tag-blockly","tag-breadcrumbs","tag-bright-data","tag-bulkdmt","tag-cameron-john-wagenius","tag-charlie-eriksen","tag-chris-goettl","tag-connor-riley-moucka","tag-constella-intelligence","tag-cve-2026-48561","tag-cve-2026-50661","tag-cve-2026-56155","tag-cve-2026-56164","tag-cve-2026-62832","tag-cve-2026-68820","tag-cve-2026-69730","tag-cve-2026-69829","tag-cve-2026-72971","tag-cve-2026-81963","tag-cve-2026-85880","tag-cybera","tag-cybercats","tag-data-breaches","tag-decryptads","tag-dmitry-lubarsky","tag-domaintools","tag-ed-skoudis","tag-ellis","tag-epieos","tag-exploit","tag-express","tag-fengwo-group","tag-flashpoint","tag-fortra","tag-gary-norden","tag-github","tag-h96","tag-hertz","tag-huawei","tag-idscan-net","tag-igor-lubarsky","tag-infoblox","tag-intel-471","tag-intelsecrets","tag-internet-of-things-iot","tag-irdev","tag-ivanti","tag-jack-bicer","tag-jillian-kossman","tag-john-erin-binns","tag-john-taylor","tag-judische","tag-justin-sherman","tag-landon-miles","tag-larry-baldwin","tag-latest-warnings","tag-lg-electronics-usa","tag-lifetime-value-company","tag-matt-adkisson","tag-microsoft-corp","tag-microsoft-patch-tuesday-august-2026","tag-microsoft-patch-tuesday-september-2026","tag-neer-do-well-news","tag-nexus","tag-nightmare-eclipse","tag-numberguru","tag-onerep","tag-opera","tag-opsec-express","tag-patch-tuesday-july-2026","tag-pavan-davuluri","tag-pcpcats","tag-pedro-fale","tag-pem-law","tag-peoplelooker","tag-peoplesmart","tag-persy_pcp","tag-pi-hole","tag-planet13","tag-radaris","tag-radaris-com","tag-raj-parikh","tag-ransomware","tag-raspberry-pi","tag-residential-proxies","tag-residential-proxy","tag-ruben-thomson","tag-rubensecurecomputing-au","tag-rubenthomson-com","tag-samsung","tag-sans-technology-institute","tag-satnam-narang","tag-security-tools","tag-sheepstealinggmail-com","tag-shitstickppgmail-com","tag-snowflake","tag-spur","tag-spycloud","tag-surfinup8gmail-com","tag-teampcp","tag-tenable","tag-tensor-industries","tag-the-coming-storm","tag-time-to-patch","tag-tizen","tag-trevor-sutter","tag-tyler-reguly","tag-ublock-origin","tag-val-gurvits","tag-victor-worms","tag-vivo","tag-waifu","tag-web-fraud-2-0","tag-webos","tag-windows-bitlocker","tag-xiaomi","tag-yolosolo17gmail-com","tag-zach-edwards","tag-zhejiang-fengwo-iot-technology-ltd"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26112"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26112\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26112"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}