isc.sans.edu Microsoft's Record Patch Tuesday Addresses 973 Vulnerabilities
Article Content
- •Microsoft's October 2026 Patch Tuesday addressed 973 vulnerabilities, the largest to date.
- •CVE-2026-81963 and CVE-2026-85880 are actively exploited elevation-of-privilege vulnerabilities.
- •Patching urgency is critical due to a negative seven-day mean time to exploit.
On October 5, 2026, Microsoft released a record-breaking 973 vulnerabilities, including 113 rated. Among these, two vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are in the wild. Both are local elevation-of-privilege vulnerabilities that allow attackers to elevate their privileges to SYSTEM on affected systems. The flaws impact Windows 11 and Windows Server 2025, with a CVSS score of 7.8. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 8, 2026. The urgency for patching is heightened due to the rapid exploitation timeline, with average exploitation occurring seven days before patches are released. Security professionals are advised to prioritize these patches based on their specific environments and risk assessments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-81963 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which systems are affected?
What is the CVSS score for the vulnerabilities?
What should organizations do?
Continue Reading
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…
Microsoft Security Update Addresses Active Exploits On September 8, 2026, Microsoft released a security update addressing critical vulnerabilities in its products, notably CVE-2026-85880 and CVE-2026-81963, both of which were confirmed to be actively exploited before the update was issued. The vulnerabilities involve privilege escalation in Windows Advanced Local…