Exploited in the wild Windows zero-day Office Microsoft rce
Patch Tuesday Sets Another Record With 974 CVEs
CVE Tools coverage
Microsoft has addressed a record-high 974 vulnerabilities in its September security update, including two flaws currently being exploited in the wild. The affected products span Windows, Office, Exchange Server, and SQL Server, with CVE-2026-85880 and CVE-2026-81963 representing immediate risks as both allow privilege escalation on compromised systems.
Beyond the active exploits, the release includes 13 critical-rated issues and 20 wormable remote code execution bugs, notably CVE-2026-69730 in Windows DNS Server. Organizations should prioritize applying these updates to mitigate the risk of automated network propagation and unauthorized administrative access.