Microsoft just had its biggest Patch Tuesday ever: 974 vulnerabilities fixed in one release.
Buried in that pile are two zero-days that attackers are already using. Neither one is flashy. Neither one is rated "Critical." That's exactly why they're dangerous — they're the kind of thing a busy admin scrolls past.
974
vulnerabilities patched in a single release — a new record
Here's what's actually going on, and the triage method I use to get through a patch list this size without burning a whole day on it.
CVE-2026-85880 — Windows ALPC Heap Buffer Overflow
- Affected: Windows Advanced Local Procedure Call (ALPC)
- Requirement: Attacker already has code execution in a low-privilege sandbox (e.g. a malicious script past endpoint controls, or a compromised browser sandbox)
- Notable: First ALPC zero-day patched since January 2023 — rare enough that its reappearance is worth flagging on its own
CVE-2026-81963 — Windows Update Stack Link-Following Flaw
- Affected: Windows Update Stack
- Mechanism: Improper link resolution before file access enables local privilege escalation to System level
- Notable: First Update Stack CVE flagged as a zero-day in five years of patches to that component
Notice the pattern: both are rated "Important," not "Critical" — but both are confirmed being exploited in the wild. Severity rating tells you blast radius. It doesn't tell you what attackers are actually reaching for this week. Treat "actively exploited" as its own top-priority lane, independent of the CVSS score.
What else is in the pile
Twenty of the 974 fixes are "wormable" — remotely exploitable without authentication, the category that produces the worst outbreaks. The ones worth knowing by name:
| CVE | Product | Why it matters |
|---|---|---|
| CVE-2026-55007 | Exchange Server | RCE — still on-prem? Jump this to the front. |
| CVE-2026-69465 | SharePoint | RCE — classic lateral-movement target. |
| CVE-2026-69525 | Remote Desktop Services | RCE — same category. |
| CVE-2026-65669 | SQL Server | Elevation of privilege — quiet, but a direct line to your data. |
| CVE-2026-81959 / 81953 | Excel | RCE via malicious document. |
| CVE-2026-81952 | Word | RCE via malicious document — still the most common ransomware foothold. |
The 10-minute triage
You're never going to read all 974 advisories, and you don't need to. Here's the order I work through a Patch Tuesday this size:
- Filter for "exploited in the wild" first, severity second. This month that's the ALPC and Update Stack zero-days — patch every endpoint that can reach them before anything else.
- Then filter for wormable + internet-facing. Exchange, SharePoint, RDS — if it's exposed, it moves to the front of the line.
- Then Office RCEs, because phishing doesn't care about your patch schedule.
- Everything else gets your normal maintenance window. Not every elevation-of-privilege bug in a niche service needs an emergency change request — that's how patch fatigue turns into nobody patching anything.
- Reboot. Actually reboot. A surprising number of these fixes don't take effect until the next restart.
If your patch management workflow doesn't already sort by "exploited in the wild" as its own field, that's worth fixing before the next record-breaking Tuesday — and it's exactly the kind of gap a structured audit catches before an attacker does.
Need a repeatable way to prioritize checks like this?
Our Network Security Audit Checklist is built around exactly this kind of prioritization — mapped to CIS Controls v8, NIST CSF 2.0, and DORA, so "what do I check first" stops being a judgment call every month.
View the Checklist
This month's patch list is brutal. What's on yours? I read all comments and reply to questions.
No comments yet. Be the first to share your thoughts!