The full story
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords. Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880). A security weakness in Windows is being tracked as CVE-2026-81963.
This month’s updates include patches for two zero-days that were exploited in the wild. Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days.
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. 104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. Attackers are already using this issue in real-world attacks, so exposed systems may need both remediation and investigation for earlier compromise.
What the reporting is based on
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April.
Open sourceMicrosoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.
Open sourceMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
Open sourceReporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What this means
Risk depends on whether the affected technology and the affected component are deployed and reachable, because the reported flaw can lead to privilege escalation. Exposure, privilege, business criticality and compensating controls should determine remediation priority.
What security teams should check now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-81963 and validate the affected path after remediation.
What is not yet confirmed
- Who was responsible has not yet been confirmed publicly.