
🛡️ **BREAKING: Microsoft Discloses 974 Vulnerabilities Including Two Actively Exploited Zero-Days**
Published Tuesday, September 08, 2026 at 05:22 PM PT BLUF: Microsoft has disclosed 974 vulnerabilities in a single patch cycle—a record-breaking volume—including two zero-day flaws already under active exploitation in the wild. Organizations must immediately prioritize identification and patching of affected systems in their environment; researchers recommend risk-based remediation rather than attempting exhaustive patching of all 974 flaws. DETAILS: • Two zero-day vulnerabilities confirmed actively exploited in the wild; specific CVE IDs and affected products not yet detailed in available disclosures, though historical pattern (July 2026: SharePoint/AD FS zero-days; June 2026: Defender zero-day) suggests enterprise infrastructure products at risk • 974 total vulnerabilities represents a new monthly record for Microsoft, exceeding July 2026’s 622 flaws and prior monthly highs • Exploit ecosystem activity disproportionately low: despite record disclosure volume, researchers report no flood of functional public exploits for the 972 non-zero-day flaws, indicating the two actively exploited vulnerabilities remain targeted rather than mass-casualty attacks • Security researchers explicitly advise against exhaustive patching of all 974 flaws; recommend organizations focus remediation on systems matching their specific technical footprint and business risk exposure • Microsoft Patch Tuesday release implies all flaws carry official vendor fixes; zero-day patches should be prioritized for immediate testing and deployment ...