Microsoft has addressed 974 vulnerabilities across its product suite in its latest Patch Tuesday security program, which includes two actively exploited zero-day vulnerabilities. This marks the largest batch of patches ever released by the company, highlighting a trend where artificial intelligence is increasingly utilized to identify vulnerabilities more rapidly.
Despite the record number of vulnerability disclosures, there has not been a corresponding surge in actively exploited zero-days. Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, noted that while AI-assisted vulnerability discovery continues to grow, it has not yet led to a spike in active exploits.
The two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, affect the Windows Update Stack and Windows Advanced Local Procedure Call, respectively, both with a CVSS rating of 7.8, allowing attackers to escalate privileges.
More than 10% of the vulnerabilities disclosed in this update are rated critical, with 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL, and 22 across various developer tools. Experts advise security teams to focus on specific areas of risk rather than becoming overwhelmed by the sheer number of defects.
Satnam Narang, a senior staff research engineer at Tenable, emphasized the importance of understanding which vulnerabilities are relevant to organizations and prioritizing remediation based on risk context. Jack Bicer, director of vulnerability research at Action1, echoed this sentiment, stating that the challenge lies in determining which vulnerabilities require immediate attention amidst the extensive patch list.
The complete list of vulnerabilities addressed this month can be found in Microsoft’s Security Response Center.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



