title: "Microsoft's Record-Setting Patch Tuesday Update Fixes Nearly 1,000 Flaws" url: "https://lifehacker.com/tech/microsofts-record-setting-patch-tuesday-update-fixes-nearly-1000-flaws" author: "Emily Long"
Credit: Beata Zawrzel/NurPhoto via Getty Images
Key Takeaways
- Microsoft just released fixes for nearly 1,000 bugs, which is approaching double the number of flaws patched in July.
- Two of the vulnerabilities addressed this month are zero-days that have been exploited in the wild.
- AI is making it easier for bad actors to develop tools to exploit vulnerabilities as well as allowing developers to fix them more quickly.
- It's always been important to install security updates as soon as they're available, but it's even more critical now with a larger number of flaws open to exploitation.
Security updates have been trending larger, and Microsoft's Patch Tuesday for September is no exception. The company just released fixes for nearly 1,000 bugs, which is approaching double the number of flaws patched in July (the previous record). Two of the vulnerabilities addressed this month are zero-days that have been exploited in the wild.
This massive jump is in large part due to AI, which is making it easier for bad actors to develop tools to exploit vulnerabilities while also allowing developers to find and fix them more quickly. This means we're likely to continue seeing sizeable updates on shorter release cycles, ideally reducing the time hackers have to take advantage of these flaws. Microsoft has typically pushed Patch Tuesday fixes around 10 a.m. PT on the second Tuesday of every month.
It's always been important to install security updates as soon as they're available, but it's even more critical now with a larger number of flaws open to exploitation. PC users should receive Patch Tuesday updates automatically, but you can check the status via Start > Settings > Windows Update > Check for Windows updates.
September's Patch Tuesday addresses 966 flaws with two zero-days
As BleepingComputer reports, the 966 flaws fixed this month are broken down across the following categories: 438 elevation-of-privilege vulnerabilities, 19 security feature bypass vulnerabilities, 258 remote-code-execution vulnerabilities, 173 information disclosure vulnerabilities, 16 spoofing vulnerabilities, and 56 denial-of-service vulnerabilities. These figures do not include other vulnerabilities (204 in total across other Microsoft products) patched earlier this month.
One of the zero-days addressed in September is an elevation of privilege vulnerability in the Windows Update Stack. CVE-2026-81963 allows attackers to gain SYSTEM privileges via improper link resolution before file access. The bug discovery has been attributed to Romain Deperne and the Microsoft Threat Intelligence Centre.
What do you think so far? Be the first to post a comment.
The other zero-day is also an elevation of privilege vulnerability. CVE-2026-85880 is a flaw in the Windows Advanced Local Procedure—an attacker could execute code in a low-privilege AppContainer, and the vulnerability could escape the sandbox and gain SYSTEM privileges locally. The bug was discovered by Volexity, as well as Mark Kelly, David Galazin, and Jeremy Hedges with Proofpoint.
Both zero-days have been actively exploited in the wild, though Microsoft has not provided any details as to how.
Emily Long
Emily Long is a freelance writer based in Salt Lake City.
More by Emily
Today’s Wordle Hints (and Answer) for Wednesday, September 9, 2026
September 9, 2026
Today’s Wordle Hints (and Answer) for Tuesday, September 8, 2026
September 8, 2026
Emily Long is a freelance writer based in Salt Lake City.
Latest
Why the Apple Health App's Redesign Is a Big Deal
September 9, 2026
Apple's 'Reference Image' Preserves Your Original Photos (Even After You Edit Them)
September 9, 2026
September 9, 2026
Keep Scrolling for Next Article
February 11, 2026 Add as a preferred source on Google

Credit: Daniel Chetroni / Shutterstock.com
Key Takeaways
- The latest "Patch Tuesday" fixes 58 vulnerabilities in total, six of which are zero-day flaws.
- Three of the six actively exploited zero-days fixed in February are security feature bypass vulnerabilities.
- Machines receive updates automatically, but you can check your settings to be sure.
Microsoft's February security update is a big one. This latest "Patch Tuesday" fixes 58 vulnerabilities in total, six of which are zero-day flaws. As a reminder, a zero-day is a vulnerability that has been either actively exploited in the wild or publicly disclosed before an official fix is released by the developer.
As BleepingComputer reports, security flaws were found in the following categories: 25 elevation-of-privilege vulnerabilities, five security feature bypass vulnerabilities, 12 remote code-execution vulnerabilities, six information disclosure vulnerabilities, three denial of service vulnerabilities, and seven spoofing vulnerabilities. Three of the elevation of privilege vulnerabilities and two of the information disclosure vulnerabilities are considered "critical." (These numbers do not include the three Microsoft Edge vulnerabilities patched earlier in February.)
Patch Tuesday updates are typically released around 10 am PT on the second Tuesday of every month, and your device should receive them automatically. BleepingComputer reports that this month's release also includes Secure Boot certificate updates for 2011 certificates that are expiring in June.
Six zero-days patched in February
Three of the six actively exploited zero-days fixed in February are security feature bypass vulnerabilities:
-
CVE-2026-21510: This is a flaw the Windows Shell that allows an attacker to execute content without warning or gaining user consent, though the user does need to open a malicious link or shortcut file.
-
CVE-2026-21513: This MSHTML Framework vulnerability allows an unauthorized attacker to bypass a security feature over a network. Microsoft has not released details on how this flaw was exploited.
-
CVE-2026-21514: This vulnerability in Microsoft Word allows an attacker to bypasses OLE mitigations in Microsoft 365 and Microsoft Office once a user has opened a malicious Office file.
All three of the above flaws have been attributed to Microsoft Threat Intelligence Center (MSTIC), Microsoft Security Response Center (MSRC), Office Product Group Security Team, and Google Threat Intelligence Group along with an anonymous researcher for CVE-2026-21510 and CVE-2026-21514.
What do you think so far? Be the first to post a comment.
Two of the zero-days are elevation of privilege vulnerabilities. CVE-2026-21519 is a Desktop Windows Manager flaw that allows an attacker to gain SYSTEM privileges, while CVE-2026-21533 is a Windows Remote Desktop Services flaw that allows an attacker to elevate privileges locally. The former has been attributed to MSTIC and MSRC, while the latter was discovered by the Advanced Research Team at CrowdStrike.
Finally, CVE-2026-21525 is a denial of service vulnerability in the Windows Remote Access Connection Manager that allows an unauthorized attacker to deny service locally. This flaw was discovered by the ACROS Security team with 0patch—it was reportedly found in a public malware repository in December 2025.
Emily Long
Emily Long is a freelance writer based in Salt Lake City.
More by Emily
Today’s Wordle Hints (and Answer) for Wednesday, September 9, 2026
September 9, 2026
Today’s Wordle Hints (and Answer) for Tuesday, September 8, 2026
September 8, 2026
Emily Long is a freelance writer based in Salt Lake City.
Latest
The iPhone 18 Pro Series Comes With Big Gains in Battery Life
September 9, 2026
Apple Just Announced the Foldable 'iPhone Duo'
September 9, 2026
Apple Just Announced the iPhone 18 Pro and iPhone 18 Pro Max
September 9, 2026
Keep Scrolling for Next Article






probably introduced 10000 while 'fixing' the 1000
Yup. Only like 8,584,920,029 to go now!