ComputerWeekly

Patch Tuesday: Microsoft updates address almost 1,000 flaws


As record numbers of software vulnerabilities continue to surface, Microsoft has once again smashed its previous record to smithereens, issuing just short of 1,000 bug fixes in its September 2026 Patch Tuesday update.

With over 100 critical flaws to address, the capacity of human security teams to keep up with the new normal of AI-assisted vulnerability discovery is now falling rapidly away, leaving organisations around the world painfully exposed.

“Looking at nearly 1,000 vulnerabilities in a single month, all I can think is: ‘My God, it’s full of stars.’ AI-assisted bug discovery has exploded patch counts into a whole new galaxy, and defenders simply have to embrace the suck,” Dustin Childs, head of threat awareness at the Zero Day Initiative (ZDI), told Computer Weekly via email.

Jack Bicer, director of vulnerability research at patch management firm Action1, added: “At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first. With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.”

Childs, whose monthly Patch Tuesday blog update has become essential reading for cyber pros, noted one small mercy in that – while Redmond has published more CVEs this year so far than it did in 2024 and 2025 put together – there does not appear to have been a corresponding surge in active exploitation activity.

Nevertheless, two elevation of privilege (EoP) flaws, CVE-2026-81963 in Windows Update Stack and CVE-2026-69380 in Microsoft Exchange Server, should be prioritised, he said.

The Action1 team also flagged CVE-2026-85880, another EoP arising from a heap-based buffer overflow issue in Windows Advanced Local Procedure Call (ALPC) that is being actively exploited in the wild.

Worms are back

But of more concern this month, said ZDI’s Childs, is a 20-strong cluster of wormable flaws.

“We haven’t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to SigRed, that reality could change fast,” he said.

The DNS Server flaw – CVE-2026-69730 – allows an unauthenticated attacker to execute code over the network and could present a severe risk across wider enterprise networks, explained Childs.

Historically, wormable flaws such as SigRed, which was unearthed in the summer of 2020, have proved particularly dangerous because they don’t require user interaction, spread automatically, and since they target core network infrastructure – like DNS Server – can cause serious system crashes, topple networks by overloading them, and serve as a vector for malicious payloads such as ransomware.

Changing times, new approaches

With record breaking updates effectively rendering the whole concept of a monthly maintenance window obsolete, security teams must adopt new approaches to vulnerability management, said Nick Carroll of Nightwing’s ShadowScout team.

He outlined four practical steps that defenders can take right now:

  • Shrink your exposed perimeter by pulling admin interfaces, legacy appliances and unpatched on-prem Exchange servers off the public internet and hiding them behind authenticated access;
  • Start to automate automated, phased rollout rings for operating systems and endpoints to deploy large volume releases without needing to manually test each patch;
  • Focus resources on vulnerabilities that are confirmed exploited instead of wasting time remediating every low-context alert at once;
  • If an e-commerce, payment, or ERP platform is exposed to an edge vulnerability, don’t just patch it, rotate credentials, tokens, and downstream integration keys too.

“Patch management is no longer a checklist item for the IT department; it is an active operational defence discipline that requires continuous, intelligence-led exposure management,” said Carroll.



Source link