INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Fixes Record 964 Flaws Including Zero-Days

| 2026-09-09 10:01 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The latest patch Tuesday brings fixes for two high-severity zero-day vulnerabilities in Windows, including a critical buffer overflow exploit that can elevate privileges locally. Microsoft describes the vulnerability as "heap-based buffer overflow" and notes it has a CVSS score of 7.8 out of 10. The affected software includes Windows Update Stack, Remote Desktop Services, Exchange Server, SharePoint, SQL Server, and core Windows components. Users are advised to download Malwarebytes today to protect their devices from these threats.
Technical Mitigations AI-generated
* Use an up-to-date operating system and software, such as Windows 11 or macOS High Sierra or later. * Keep your operating system and software applications updated to the latest versions. * Avoid opening malicious documents or clicking on suspicious links, which can lead to local privilege escalation vulnerabilities like those mentioned in the article. * Be cautious when using cloud services, especially if they are not properly configured or monitored for security risks. * Use a reputable antivirus program and keep it up-to-date to protect against malware and other types of cyber threats.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81963CVE-2026-81963 CVE-2026-80097CVE-2026-80097 CVE-2023-21674CVE-2023-21674 CVE-2026-69465CVE-2026-69465 CVE-2026-69730CVE-2026-69730 CVE-2026-72979CVE-2026-72979 CVE-2026-85880CVE-2026-85880 CVE-2026-55007CVE-2026-55007 CVE-2026-69829CVE-2026-69829 CVE-2026-69595CVE-2026-69595 CVE-2026-69525CVE-2026-69525 CVE-2026-65669CVE-2026-65669
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎Office 2016
Threat actors exploited zero-day vulnerabilities in Microsoft's Windows and Office software to target various versions of these applications.
infrastructure Windows
general_metric 723 flaws
general_metric 111 flaws
general_metric 22 flaws
organisation SQL
general_metric 62 vulnerabilities
‎January 2023
Threat actors exploited CVE-2023-21674, a previously unpatched vulnerability, to target systems affected by the newly released Microsoft patch for CVE-2026-85880.
vulnerability CVE-2026-85880
vulnerability CVE-2023-21674
‎2026/09/09
Threat actors exploited a zero-day vulnerability in Microsoft's latest software update, targeting users on September 9.
‎2026/09/09
Microsoft addressed 974 security flaws across its product suite, including two actively exploited zero-day vulnerabilities.
infrastructure Windows
organisation Windows Update
organisation Remote Desktop Services
organisation SharePoint
infrastructure 7.8
organisation Microsoft
organisation Office and Office 2016
organisation Windows Advanced Local Procedure Call
organisation AppContainer
organisation the Windows Update Stack
organisation Windows Remote Desktop Services
organisation NFS
organisation CVE-2026
organisation Microsoft Exchange
organisation CVSS
organisation The Hacker News
organisation Patch Tuesday
organisation Microsoft Authenticator
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
data_breach 569 previous record
organisation Fortra
organisation Exchange
infrastructure 22,000 Exchange servers
organisation Automox
organisation Adobe
organisation Adobe Commerce
organisation Trend Micro’s Zero Day Initiative
organisation Microsoft’s Security Response Center
‎September 2026
Threat actors exploited zero-day vulnerabilities in Microsoft's September 2026 Patch Tuesday patches.
organisation Critical
organisation Important
general_metric 104 CVEs
‎September 22, 2026
Threat actors exploited zero-day vulnerabilities in Microsoft software to target the Federal Civilian Executive Branch.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎September 22
Microsoft's zero-day exploits were used to target federal agencies on Patch Tuesday.
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎7.8
Software Version
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
data_breach
569
Previous Record
Metrics
infrastructure
22,000
Exchange Servers