BREACH WATCH BRIEF Critical ☁️ Advisory

Microsoft Releases Patch for 974 Vulnerabilities, Including Two Actively Exploited Zero‑Days

Microsoft issued updates for 974 Windows flaws, two of which are zero‑day exploits already in the wild. The scale underscores the importance of continuous vulnerability‑management and auditable patch evidence for compliance programs.

SeverityCritical
Type☁️ Advisory
ConfidenceHigh
ReportedSep 8, 2026
Technology & SaaS Technology enterprises that run Microsoft Windows across desktops, servers, and cloud workloads. Vulnerability Exploit

What happened

Microsoft’s September Patch Tuesday delivered fixes for at least 974 security vulnerabilities across Windows and related software, including two zero‑day flaws (CVE‑2026‑81963, CVE‑2026‑85880) that are actively exploited and 113 critical‑severity bugs such as a remote‑code‑execution flaw in the Windows Shell (CVSS 9.8).

Why it matters for trust and compliance

  • The event tests the control objective of timely vulnerability remediation, a core requirement across frameworks; continuous evidence of patch deployment is essential for audit readiness.
  • Enables automated collection of patch‑deployment logs to satisfy evidence requirements for vulnerability‑management controls.
  • Provides a unified view that maps patch status to multiple compliance frameworks, reducing manual audit effort.

Who is affected

Technology enterprises that run Microsoft Windows across desktops, servers, and cloud workloads.

Recommended actions

  1. Prioritize and apply the two zero‑day and all critical patches within your patch‑management window.
  2. Capture installation logs and retain them as audit evidence of remediation.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.