← Back to Feed

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

September 8, 2026 · The Record · Severity: HIGH

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time. The federal cyberdefense agency, CISA, confirmed that two of them — CVE-2026-81963 and CVE-2026-85880 — are being exploited by hackers. Federal agencies have until September 22 to patch them.

Key Takeaways

  • Security patches address multiple CVEs across affected product lines
  • Critical and high-severity vulnerabilities require prioritized deployment
  • Review full advisory for product-specific patch guidance and mitigations
☕ Buy a Coffee