#microsoftPatchTuesday
Microsoft's Sept Patch Tuesday rollout addresses more than 80 vulnerabilities across its product suite, including 8 rated critical and two zero-day issues that were publicly disclosed ahead of the update.
redmondmag.com/Articles/202...

#MicrosoftPatchTuesday #Cybersecurity #VulnerabilityManagement
Microsoft September Security Patch: 8 Critical Bugs, 2 Publicly Disclosed Zero-Days -- Redmondmag.com
Microsoft's September 2025 Patch Tuesday rollout addresses more than 80 vulnerabilities across its product suite, including eight rated critical and two zero-day issues that were publicly disclosed ah...
redmondmag.com
September 11, 2025 at 1:42 PM
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update #CVE2026 #Cybersecurity #MicrosoftPatchTuesday
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company's software portfolio in unusual quantities. Additionally, this update contains two Windows flaws that have been confirmed to be exploited in the wild, highlighting the urgency of fixing the vulnerabilities. The vulnerabilities span several Microsoft product categories, including Windows, Office, SQL Server and Development Tools.  Microsoft Windows accounted for 723 flaws, while Microsoft Office and Office 2016 contained 111, SQL had 62, and Developer Tools contained 22 more. There have been over 110 critical vulnerabilities rated as critical. Among the most critical issues addressed in this month's release are privilege escalation, remote code execution and information disclosure. Besides Microsoft's own vulnerabilities, the company also patched 25 non-Microsoft vulnerabilities as part of the September update, which brings the total number of vulnerabilities covered to 999.  The two actively exploited Windows vulnerabilities are CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. The CVE-2026-85880 vulnerability is a heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) function of Windows. The vulnerability can be exploited by an attacker with authorization to gain SYSTEM-level access by escalating privileges.  CVE-2026-81963 is a vulnerability that affects the Windows Update Stack and involves improper link resolution. Authorized attackers are also capable of exploiting this vulnerability for escalating local privileges and gaining system access.  By exploiting CVE-2026-85880, Microsoft stated that code running inside an AppContainer that has low privileges may escape its sandbox and gain full privileges on the affected Windows system. The attack does not require additional interaction from the user. This vulnerability has attracted significant attention due to its location within the Windows Update Stack.  There have been reports of vulnerabilities in this component that could have serious implications, especially since the update mechanism itself is responsible for the modification of system components. Microsoft has released fixes for CVE-2026-81963, however, across supported versions of Windows.  Both vulnerabilities have been exploited by Microsoft, but the company has not provided information regarding who the attackers are, how many systems were targeted, or whether successful compromises have been confirmed. According to the Cybersecurity and Infrastructure Security Agency (CISA), both vulnerabilities have been added to its catalog of known exploited vulnerabilities. There is a deadline of September 22, 2026, for federal agencies to apply available security updates.  The September release addresses several high-severity security vulnerabilities across Microsoft enterprise products in addition to the two exploited zero-days. This vulnerability could allow an unauthorized attacker to execute code remotely if exploited by an attacker. It has been rated 8.1 by the Center for Vehicular Defense.  A vulnerability rated 8.8 in SharePoint has been reported, as well as a vulnerability in SQL Server called CVE-2026-65669, which can result in network-based code execution. The vulnerability is particularly severe and carries a CVSS score of 9.6, enabling privilege escalation. Several critical vulnerabilities affect Windows Remote Desktop Services, Windows DNS Server, Windows DHCP Server, Windows Shell, and Windows Services for NFS ONCRPC XDR Driver, carrying the maximum CVSS score of 9.8.  In addition to reflecting the growing number of security vulnerabilities reported, the scale of the September release also reflects the rising number of security flaws reported by TrendAI's Zero Day Initiative. As of the beginning of 2026, Microsoft has patched 2,760 security vulnerabilities. Among Tenable's analysts, Satnam Narang noted that the September release alone brings the yearly count above 2,600 vulnerabilities, more than twice the previous record of 1,245 vulnerabilities recorded in 2020.  It is important to note, however, that the raw number of CVEs does not necessarily indicate a company's level of risk. There may be patches that do not affect a particular environment, while others require specific configurations or local access for exploitation to occur. In the immediate future, it is important to identify vulnerabilities in deployed systems that are able to be exploited realistically.  Since the two Windows zero-day vulnerabilities have already been confirmed as exploited and have been added to CISA's KEV catalog, they should be remedied sooner rather than vulnerabilities with no known exploitation activity.
dlvr.it
September 10, 2026 at 12:47 PM
📰 Windows LegacyHive Zero-Day Dirilis, Berpotensi Beri Akses Admin ke Penyerang

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/17/windows-legacyhive-zero-day-akses-admin/

#ber
it#beritaTeknologir#cyberSecurityo#exploitPocl#localPrivilegeEscalationo#microsoftPatchTuesdayt#nightmareEcl
July 17, 2026 at 11:45 AM
Microsoft Issues Record 622 Security Fixes in July Patch Tuesday, Urges Immediate Action on Two Exploited Zero-Day Flaws #MicrosoftJulyPatchTuesday #MicrosoftPatchTuesday
Microsoft Issues Record 622 Security Fixes in July Patch Tuesday, Urges Immediate Action on Two Exploited Zero-Day Flaws
  Microsoft has rolled out its largest-ever Patch Tuesday update, addressing 622 vulnerabilities across its software ecosystem. The July release significantly surpasses June's update, which fixed around 200 vulnerabilities, making it the company's most extensive security update to date. Among the fixes are two zero-day vulnerabilities that Microsoft confirmed are already being actively exploited. The flaws impact on-premises SharePoint Server and Active Directory Federation Services (AD FS), making them the highest-priority patches for organizations. The first flaw, CVE-2026-56164, affects Microsoft SharePoint Server. According to Microsoft, attackers can exploit the vulnerability remotely to gain elevated privileges without requiring authentication, user interaction, or valid credentials. The company credited Mandiant's incident response team and Google's FLARE team for identifying the issue during active attacks, although it has not disclosed details about the threat actors or attack techniques involved. Organizations running self-hosted SharePoint servers are advised to deploy the update immediately. Microsoft also noted that enabling Antimalware Scan Interface (AMSI) in Full Mode provides additional protection against exploitation. The timing is particularly significant as SharePoint Server 2016 and 2019 have reached the end of extended support, with no Extended Security Updates (ESU) program available for either version. The second exploited vulnerability, CVE-2026-56155, impacts Active Directory Federation Services (AD FS). The flaw enables an authenticated attacker to elevate privileges locally due to weak access controls. Microsoft's Detection and Response Team (DART) discovered the issue. While Microsoft has not revealed how attackers are leveraging the flaw or the privileges it grants, AD FS plays a critical role in enterprise authentication by issuing security tokens across trusted environments, making the vulnerability particularly important. Although neither of the two vulnerabilities has been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog at the time of writing, Microsoft has already classified both as actively exploited. Security experts recommend organizations prioritize these patches without waiting for a KEV listing. Microsoft also fixed CVE-2026-50661, a publicly disclosed vulnerability affecting BitLocker. The issue allows attackers with physical access to bypass BitLocker protections. Since the flaw cannot be exploited remotely, it is considered less urgent than the actively exploited zero-days but should still be addressed as part of routine patch management. Another notable update addresses CVE-2026-55040, a SharePoint JWT authentication bypass vulnerability disclosed by Rapid7 Labs. Researchers demonstrated that the flaw could be chained with a separate remote code execution (RCE) vulnerability to achieve unauthenticated code execution on vulnerable servers. Microsoft has confirmed that the authentication bypass is fixed in July, while the associated RCE vulnerability is scheduled to receive a patch in August. Kerberos RC4 Hardening Completed The July release also marks the completion of Microsoft's long-running effort to phase out RC4 encryption within Kerberos authentication. The update removes the rollback mechanism that administrators had been using since January. After installing the update, RC4 authentication will only function for accounts specifically configured to allow it. Organizations are advised to audit service accounts using Microsoft's RC4 audit events and rotate passwords where necessary so that modern AES encryption keys are generated before deploying the update. Failure to prepare legacy systems could lead to authentication failures after patching. AI-Driven Security Research Expands Patch Volume Microsoft previously indicated that customers should expect larger Patch Tuesday releases as artificial intelligence improves vulnerability discovery. In a July 9 announcement, the company said it anticipated a "higher volume of security updates included in each security release" due to AI-assisted security research. The company highlighted its MDASH multi-model agentic scanning platform, which previously identified multiple vulnerabilities in earlier Patch Tuesday releases. However, Microsoft has not disclosed how many of July's 622 vulnerabilities were discovered using the system. Faster Patching Becoming Increasingly Important Security experts warn that the growing number of vulnerabilities makes traditional severity-based prioritization less effective. Once patches become publicly available, attackers can rapidly analyze them to develop exploits, significantly reducing the time organizations have to respond. Rather than relying solely on CVSS scores, experts recommend prioritizing vulnerabilities based on active exploitation indicators, including Microsoft's exploited status, CISA's Known Exploited Vulnerabilities catalog, and Exploit Prediction Scoring System (EPSS) data. Microsoft's July Patch Tuesday demonstrates how AI-driven vulnerability discovery is accelerating both defensive and offensive security efforts, making timely patch deployment increasingly critical for organizations.
dlvr.it
July 17, 2026 at 3:44 PM
Dunno why it took me so long to recognise that my reaction to the Windows "reboot required" system tray icon is *exactly* the same as when I'd be caught off guard by spots of blood on my underwear and think, "Oh, *gawd*, is it that time of the month already?!" #MicrosoftPatchTuesday
August 14, 2024 at 3:20 PM
Microsoft's April 2026 Patch Tuesday addresses 168 vulnerabilities, including an actively exploited zero-day in SharePoint. Prioritize patching to safeguard your systems. #CyberSecurity #MicrosoftPatchTuesday #ZeroDay Link: thedailytechfeed.com/microsoft-ap...
April 15, 2026 at 7:13 PM
Microsoft's February 2026 Patch Tuesday addresses 54 vulnerabilities, including 6 zero-days. Immediate patching is crucial to safeguard systems. #CyberSecurity #MicrosoftPatchTuesday #ZeroDay Link: thedailytechfeed.com/microsoft-pa...
February 11, 2026 at 5:17 PM
Patch Tuesday novembre 2025 risolve una zero-day AppLocker e 63 vulnerabilità in Windows, Office, Azure e Visual Studio.

#evidenza #MicrosoftPatchTuesday #Windows #zeroday
www.matricedigitale.it/2025/11/12/m...
November 12, 2025 at 7:58 AM
Microsoft rilascia Patch Tuesday ottobre 2025 con 6 zero-day corretti, 172 vulnerabilità risolte, aggiornamenti per Windows 11 e fine supporto per Windows 10 ed Exchange Server.

#evidenza #MicrosoftExchangeServer #MicrosoftPatchTuesday #Windows #zeroday
www.matricedigitale.it/2025/10/14/m...
October 14, 2025 at 8:27 PM
Microsoft Patch Tuesday agosto 2025 corregge zero-day e 107 vulnerabilità in Windows 11, Windows 10, con fix per ESU e miglioramenti UI.

#MicrosoftPatchTuesday #windows #zeroday
www.matricedigitale.it/2025/08/13/m...
August 13, 2025 at 7:17 AM
Microsoft’s April 2025 Patch Tuesday: 134 Flaws, One Sneaky Zero-Day, and A Dash of Suspense!

Microsoft's April 2025 Patch Tuesday tackles 134 flaws, including a zero-day. Upgrade now or risk a cyber surprise party! #MicrosoftPatchTuesday
thenimblenerd.com?p=1042064
Microsoft’s April 2025 Patch Tuesday: 134 Flaws, One Sneaky Zero-Day, and A Dash of Suspense!
Microsoft's April 2025 Patch Tuesday delivers a whopping 134 security updates, including one actively exploited zero-day vulnerability. With fixes for 11 critical remote code execution flaws, the patch is like a superhero cape for your computer, shielding it from elevation of privilege, spoofing, and denial of service attacks.
thenimblenerd.com
April 8, 2025 at 6:12 PM
Microsoft's Sept Patch Tuesday rollout addresses more than 80 vulnerabilities across its product suite, including 8 rated critical and two zero-day issues that were publicly disclosed ahead of the update.
redmondmag.com/Articles/202...

#MicrosoftPatchTuesday #Potatosecurity #VulnerabilityManagement
September 11, 2025 at 1:42 PM