CISA Warns of Exploited Microsoft Vulnerabilities as Patch Tuesday Discloses Record 973 Bugs

Published:

Microsoft’s latest Patch Tuesday release has set a new record, disclosing 973 vulnerabilities, with two of them—CVE-2026-81963 and CVE-2026-85880—actively exploited by hackers, according to the Cybersecurity and Infrastructure Security Agency (CISA). Federal agencies have until September 22 to address these vulnerabilities. More than 22,000 corporate Exchange servers remain unpatched against weaponized exploit code.

CVE-2026-81963 is linked to a component used for installing Windows updates, while CVE-2026-85880 affects a messaging system within Windows. Experts warn that vulnerabilities like CVE-2026-81963 can serve as initial steps in ransomware attacks, where hackers gain access through phishing and escalate their privileges. “The component makes it worse. An attacker who owns the update stack owns the thing you’d use to evict them,” said Automox engineer Serena DiPenti.

This month’s Patch Tuesday release marks a significant increase in disclosed vulnerabilities, pushing the total for the year to over 2,600—more than double the previous record set in 2020. The surge in vulnerabilities has raised concerns among cybersecurity researchers, who have warned that the use of artificial intelligence in code-review tools may lead to a rise in minor vulnerabilities that could be exploited in dangerous ways. For further details, refer to the reporting by The Record.

As organizations scramble to patch these vulnerabilities, the potential for exploitation remains high, underscoring the urgent need for timely updates and robust cybersecurity measures.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...

US DHS allegedly compiles protester dossiers in Palantir database, court filing reveals

Newly unsealed court documents allege that the US Department of Homeland Security (DHS) has compiled extensive dossiers on individuals observing Immigration and Customs Enforcement...