آموزش

Microsoft's Record-Setting Patch Tuesday Update Fixes Nearly 1,000 Flaws

Security updates have been trending larger, and Microsoft’s Patch Tuesday for September is no exception. The company just released fixes for nearly 1,000 bugs, which is approaching double the number of flaws patched in July (the previous record). Two of the vulnerabilities addressed this month are zero-days that have been exploited in the wild.

This massive jump is in large part due to AI, which is making it easier for bad actors to develop tools to exploit vulnerabilities while also allowing developers to find and fix them more quickly. This means we’re likely to continue seeing sizeable updates on shorter release cycles, ideally reducing the time hackers have to take advantage of these flaws. Microsoft has typically pushed Patch Tuesday fixes around 10 a.m. PT on the second Tuesday of every month.

It’s always been important to install security updates as soon as they’re available, but it’s even more critical now with a larger number of flaws open to exploitation. PC users should receive Patch Tuesday updates automatically, but you can check the status via Start > Settings > Windows Update > Check for Windows updates.

September’s Patch Tuesday addresses 966 flaws with two zero-days

As BleepingComputer reports, the 966 flaws fixed this month are broken down across the following categories: 438 elevation-of-privilege vulnerabilities, 19 security feature bypass vulnerabilities, 258 remote-code-execution vulnerabilities, 173 information disclosure vulnerabilities, 16 spoofing vulnerabilities, and 56 denial-of-service vulnerabilities. These figures do not include other vulnerabilities (204 in total across other Microsoft products) patched earlier this month.

One of the zero-days addressed in September is an elevation of privilege vulnerability in the Windows Update Stack. CVE-2026-81963 allows attackers to gain SYSTEM privileges via improper link resolution before file access. The bug discovery has been attributed to Romain Deperne and the Microsoft Threat Intelligence Centre.

The other zero-day is also an elevation of privilege vulnerability. CVE-2026-85880 is a flaw in the Windows Advanced Local Procedure—an attacker could execute code in a low-privilege AppContainer, and the vulnerability could escape the sandbox and gain SYSTEM privileges locally. The bug was discovered by Volexity, as well as Mark Kelly, David Galazin, and Jeremy Hedges with Proofpoint.

Both zero-days have been actively exploited in the wild, though Microsoft has not provided any details as to how.

منبع آموزش

ZaKi

Who is mahdizk? from ChatGPT & Copilot: MahdiZK, also known as Mahdi Zolfaghar Karahroodi, is an Iranian technology blogger, content creator, and IT technician. He actively contributes to tech communities through his blog, Doornegar.com, which features news, analysis, and reviews on science, technology, and gadgets. Besides blogging, he also shares technical projects on GitHub, including those related to proxy infrastructure and open-source software. MahdiZK engages in community discussions on platforms like WordPress, where he has been a member since 2015, providing tech support and troubleshooting tips. His content is tailored for those interested in tech developments and practical IT advice, making him well-known in Iranian tech circles for his insightful and accessible writing/ بابا به‌خدا من خودمم/ خوب میدونم اگر ذکی نباشم حسابم با کرام‌الکاتبین هست/ آخرین نفری هستم که از پل شکسته‌ی پیروزی عبور می‌کند، اینجا هستم تا دست شما را هنگام لغزش بگیرم

نوشته های مشابه

دیدگاهتان را بنویسید

نشانی ایمیل شما منتشر نخواهد شد. بخش‌های موردنیاز علامت‌گذاری شده‌اند *

همچنین ببینید
بستن
دکمه بازگشت به بالا