CISA Warns of Exploited Microsoft Vulnerabilities as Patch Tuesday Discloses Record 973 Bugs

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft’s latest Patch Tuesday release has set a new record, disclosing 973 vulnerabilities, with two of them—CVE-2026-81963 and CVE-2026-85880—actively exploited by hackers, according to the Cybersecurity and Infrastructure Security Agency (CISA). Federal agencies have until September 22 to address these vulnerabilities. More than 22,000 corporate Exchange servers remain unpatched against weaponized exploit code.

CVE-2026-81963 is linked to a component used for installing Windows updates, while CVE-2026-85880 affects a messaging system within Windows. Experts warn that vulnerabilities like CVE-2026-81963 can serve as initial steps in ransomware attacks, where hackers gain access through phishing and escalate their privileges. “The component makes it worse. An attacker who owns the update stack owns the thing you’d use to evict them,” said Automox engineer Serena DiPenti.

This month’s Patch Tuesday release marks a significant increase in disclosed vulnerabilities, pushing the total for the year to over 2,600—more than double the previous record set in 2020. The surge in vulnerabilities has raised concerns among cybersecurity researchers, who have warned that the use of artificial intelligence in code-review tools may lead to a rise in minor vulnerabilities that could be exploited in dangerous ways. For further details, refer to the reporting by The Record.

As organizations scramble to patch these vulnerabilities, the potential for exploitation remains high, underscoring the urgent need for timely updates and robust cybersecurity measures.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

GCC Central Banks Enhance Cybersecurity and Fintech Collaboration at Recent Meeting

The Gulf Cooperation Council (GCC) central banks are intensifying their collaboration on cybersecurity and financial technology, as highlighted during a...

Google Implements Multifaceted Defense Strategy Against AI Abuse and Cyber Threats

Google's Multifaceted Defense Strategy Against AI Abuse As artificial intelligence (AI) technologies become increasingly integrated into various sectors, the potential for their misuse has prompted...

Dstl launches strategic communications wargame ‘Defending Defender’

The Defence Science and Technology Laboratory (Dstl) has launched a new strategic communications wargame titled 'Defending Defender – Battle for the narrative'. This game...

Microsoft’s September Patch Tuesday Addresses 974 Vulnerabilities, Including Two Active Zero-Days

Microsoft has addressed 974 vulnerabilities across its product suite in its latest Patch Tuesday security program, which includes two actively exploited zero-day vulnerabilities. This...