{"id":618737,"date":"2026-09-09T00:14:09","date_gmt":"2026-09-09T00:14:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/618737\/"},"modified":"2026-09-09T00:14:09","modified_gmt":"2026-09-09T00:14:09","slug":"microsoft-posts-nearly-1000-bugs-for-patch-tuesday-as-cisa-warns-two-being-exploited","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/618737\/","title":{"rendered":"Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited"},"content":{"rendered":"<p class=\"paragraph\"> Microsoft\u2019s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time. <\/p>\n<p class=\"paragraph\"> The federal cyberdefense agency, CISA, confirmed that two of them \u2014 CVE-2026-81963 and CVE-2026-85880 \u2014 are being exploited by hackers. Federal agencies have until September 22 to patch them.\u00a0 <\/p>\n<p class=\"paragraph\"> Tenable\u2019s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows. More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll.\u00a0 <\/p>\n<p class=\"paragraph\"> Others explained that bugs like CVE-2026-81963 are the first step in a ransomware chain where hackers phish one user and use their access to gain escalated privileges.\u00a0 <\/p>\n<p class=\"paragraph\"> \u201cThe component makes it worse. An attacker who owns the update stack owns the thing you&#8217;d use to evict them,\u201d Automox engineer Serena DiPenti said. \u201cIf you can&#8217;t say when the update stack last ran, you can&#8217;t say whether it&#8217;s patched.\u201d <\/p>\n<p class=\"paragraph\"> The two are among <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Sep\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">973 bugs<\/a> disclosed on Patch Tuesday by Microsoft. The company set a previous record in July with fixes for <a href=\"https:\/\/therecord.media\/microsoft-vulnerabilities-patch-tuesday-release\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">more than 600 security vulnerabilities<\/a> \u2014 which itself was triple the size of the previous record <a href=\"https:\/\/therecord.media\/microsoft-ships-largest-patch-tuesday-on-record\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">set the month before<\/a>. <\/p>\n<p class=\"paragraph\"> Cybersecurity researchers and defenders have warned for months that the use of artificial intelligence code-review tools would prompt an onslaught of minor vulnerabilities that could be chained together for dangerous attacks.\u00a0 <\/p>\n<p class=\"paragraph\"> Narang noted that the latest Patch Tuesday release pushes the year\u2019s total bugs disclosed over 2,600, which is already more than double the previous record-setting year of 2020.\u00a0Qualys cybersecurity expert Diksha Ojha added that another vulnerability <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-146.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">announced<\/a> by Adobe this month was a <a href=\"https:\/\/sansec.io\/research\/stylesmuggler-0day\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">critical-severity bug<\/a> in Adobe Commerce.\u00a0 <\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft\u2019s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time. The&hellip;\n","protected":false},"author":2,"featured_media":618738,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[61,60,80],"class_list":["post-618737","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/618737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=618737"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/618737\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/618738"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=618737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=618737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=618737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}