Skip to content
Microsoft's Record Patch Tuesday Addresses 973 Vulnerabilities

Microsoft's Record Patch Tuesday Addresses 973 Vulnerabilities

First seen 5 Oct 2026, 20:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 21:26 UTC
  • •Microsoft's October 2026 Patch Tuesday addressed 973 vulnerabilities, the largest to date.
  • •CVE-2026-81963 and CVE-2026-85880 are actively exploited elevation-of-privilege vulnerabilities.
  • •Patching urgency is critical due to a negative seven-day mean time to exploit.

On October 5, 2026, Microsoft released a record-breaking 973 vulnerabilities, including 113 rated. Among these, two vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are in the wild. Both are local elevation-of-privilege vulnerabilities that allow attackers to elevate their privileges to SYSTEM on affected systems. The flaws impact Windows 11 and Windows Server 2025, with a CVSS score of 7.8. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 8, 2026. The urgency for patching is heightened due to the rapid exploitation timeline, with average exploitation occurring seven days before patches are released. Security professionals are advised to prioritize these patches based on their specific environments and risk assessments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-08
CVE-2026-81963 and CVE-2026-85880 published
Microsoft disclosed two elevation-of-privilege vulnerabilities, both actively exploited and added to CISA's KEV catalog.
Venturebeat
2026-10-05
Record Patch Tuesday released
Microsoft released a total of 973 vulnerabilities, marking the largest Patch Tuesday ever, including critical RCEs and privilege escalation flaws.
isc.sans.edu

More articles in this cluster (2)

Following this threat?

Track CVE-2026-81963 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which systems are affected?
The vulnerabilities affect Windows 11 and Windows Server 2025 systems.
What is the CVSS score for the vulnerabilities?
Both CVE-2026-81963 and CVE-2026-85880 have a CVSS score of 7.8.
What should organizations do?
Organizations should prioritize applying the patches for these vulnerabilities based on their risk assessments.