Microsoft breaks Patch Tuesday record with 974-CVE deluge
Microsoft issued an out-of-band emergency update for Windows 11 to resolve critical bugs introduced by its record-breaking September Patch Tuesday. The original update caused Remote Desktop Services failures on Windows Server, alongside issues with Hyper-V and USB audio. This follows a massive security release that addressed between 963 and 974 vulnerabilities, including two zero-days already used in attacks. Security teams must now balance the need to patch these high-risk flaws against the stability risks introduced by the initial deployment.
What changed
Microsoft released an emergency out-of-band update to fix RDS, Hyper-V, and USB audio failures caused by the September security patches.
Live updates
-
Microsoft releases emergency Windows 11 update after record patch causes failures
Microsoft issued an out-of-band emergency update for Windows 11 to resolve critical bugs introduced by its record-breaking September Patch Tuesday. The original update caused Remote Desktop Services failures on Windows Server, alongside issues with Hyper-V and USB audio. This follows a massive security release that addressed between 963 and 974 vulnerabilities, including two zero-days already used in attacks. Security teams must now balance the need to patch these high-risk flaws against the stability risks introduced by the initial deployment.
Why it matters
The September 2026 update is the largest of the year, with AI cited as a driver for the high volume of vulnerabilities. Two of the flaws were exploited in the wild and added to the CISA KEV catalog. The subsequent emergency patch highlights the tension between rapid vulnerability mitigation and system stability.
What is confirmed
- Microsoft confirmed September security updates caused Remote Desktop Services failures on Windows Server.
- An emergency out-of-band update for Windows 11 fixes issues with Remote Desktop, USB audio, and Hyper-V.
- The September Patch Tuesday addressed two exploited zero-day flaws.
Still unconfirmed
- The September Patch Tuesday contained 974 security fixes.
- The September Patch Tuesday contained 963 CVEs.
What to watch next
- Confirmation of whether the emergency patch resolves all RDS failures across all Windows Server versions
- Further CISA advisories regarding the two exploited zero-days
confidence 90%Sources used for this update (6)
- hothardware.com — Microsoft Smashes Patch Tuesday Record With 974 Security Fixes
- www.computerworld.com — September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message
- www.bleepingcomputer.com — Microsoft: September updates cause RDS failures on Windows Server
- www.theverge.com — Microsoft issues emergency Windows 11 update to fix its record-breaking patch
- mashable.com — Windows 11 emergency update: Microsoft races to fix bugs
- lapaasvoice.com — Microsoft Patch Tuesday Fixes Two Zero-Days
-
Microsoft Resolves Record 974 CVEs in September Patch Tuesday
Microsoft issued its largest Patch Tuesday on record, fixing 974 flaws including two zero-days already exploited in the wild. The total number of resolved vulnerabilities reached 999 when including 25 non-Microsoft CVEs. Windows received 723 fixes, Office and Office 2016 received 111, SQL received 62, and Developer Tools received 22. Security teams face 119 critical flaws and 20 wormable vulnerabilities. CISA has added the two exploited zero-days to its KEV catalog. AI is cited as a factor behind the high volume of vulnerabilities.
Why it matters
Large-scale patch cycles increase the burden on IT teams to prioritize critical updates. The presence of wormable flaws means threats can spread automatically across networks without user interaction. This update follows a trend of increasing vulnerability discovery assisted by automated tools.
What is confirmed
- Microsoft fixed a record 974 flaws in its September Patch Tuesday.
- Two of the patched vulnerabilities were already being exploited.
- The update includes 20 wormable vulnerabilities.
- Windows received 723 vulnerability fixes.
- Office and Office 2016 received 111 fixes.
- The total number of resolved vulnerabilities, including non-Microsoft CVEs, is 999.
Still unconfirmed
- Nightmare Eclipse released a Microsoft Defender zero-day exploit called ShieldCrash that grants full System privileges.
What to watch next
- Confirmation of whether ShieldCrash is included in the 974 patched CVEs
- CISA updates regarding the ShieldCrash exploit
- Reports on the actual adoption rate of the September patches across enterprise networks
confidence 90%Sources used for this update (4)
- thenextweb.com — Microsoft patches a record 974 flaws, and two are already under attack
- www.techpowerup.com — Microsoft Fixes Nearly 1,000 Vulnerabilities Across Windows, Office, and Azure
- innovatopia.jp — 【解説】Adobe、脆弱性172件を修正|Acrobat Reader 32件の優先度
- www.securityweek.com — New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
-
Microsoft Patches Record 974 Vulnerabilities in September 2026
Microsoft issued its largest Patch Tuesday on record, resolving 974 CVEs across its software portfolio. The update addresses two zero-day flaws actively exploited in the wild, both of which are now listed in the CISA KEV catalog. The fixes include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Security teams must prioritize 119 critical flaws and 20 wormable vulnerabilities. Including 25 non-Microsoft CVEs, the total number of resolved vulnerabilities reached 999.
Why it matters
Patch Tuesday is a monthly cycle where Microsoft releases security updates to protect users from cyberattacks. The sheer volume of this release forces IT teams to prioritize specific high-risk flaws to prevent system compromise. Remote code execution, privilege escalation, and information disclosure comprise nearly 90% of the patched bugs.
What is confirmed
- Microsoft fixed a record 974 CVEs in the September 2026 Patch Tuesday update.
- Two zero-day vulnerabilities exploited in the wild were included in the update.
- The CISA KEV catalog now includes the two exploited zero-days.
- The update addresses 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
- The release includes 20 wormable vulnerabilities.
Still unconfirmed
- The update contained 119 critical flaws.
- Over 110 shortcomings received a critical severity rating.
- The total number of resolved vulnerabilities reached 999 after including 25 non-Microsoft CVEs.
What to watch next
- Confirmation of the exact number of critical severity ratings across all sources
- Reports on successful exploitation of the 20 wormable vulnerabilities
confidence 90%Sources used for this update (12)
- The Register — Microsoft breaks Patch Tuesday record with 974-CVE deluge
- arstechnica.com — Why this month’s Microsoft patch release is a doozy
- Krebs on Security — Microsoft Plugs Nearly 1,000 Security Holes
- thehackernews.com — Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
- Dark Reading — Patch Tuesday Sets Another Record With 974 CVEs
- thecyberexpress.com — Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited
- news.ssbcrack.com — Microsoft Breaks Patch Tuesday Record With Nearly 974 CVEs in September 2026
- www.infosecurity-magazine.com — Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
- www.techrepublic.com — Microsoft Fixes 974 Flaws in Record Patch Tuesday
- securityaffairs.com — Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
- thehackernews.com — Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
- lifehacker.com — Microsoft's Record-Setting Patch Tuesday Update Fixes Nearly 1,000 Flaws