Particle.news

Microsoft Issues Record 974 Patches in Largest-Ever Patch Tuesday

AI-assisted vulnerability discovery has driven a surge in disclosures that is forcing defenders to shift to exploit-focused, risk-based patching and faster, tested deployments.

Overview

  • Microsoft released an unprecedented monthly update bundle that addresses roughly 974 vulnerabilities across Windows and other Microsoft software.
  • The package includes two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880) and 113 Microsoft-rated critical flaws, meaning many bugs could let attackers take control with little or no user action.
  • Among the highest-risk fixes are a DNS weakness that can be reached without authentication (CVE-2026-69730) and a Windows Shell remote-code-execution flaw with a 9.8 CVSS score (CVE-2026-69829).
  • Security teams face strain triaging, testing, and deploying the much larger monthly volumes, and experts advise focusing first on actively exploited and critical vulnerabilities, maintaining inventories and backups, and validating patches in safe test environments.
  • The surge is part of a broader industry trend tied to AI-accelerated research that has put Microsoft past 2,600 fixes year-to-date and prompted other vendors to increase update cadence, raising the risk that unattended systems will remain exposed.