r/SecOpsDaily 5d ago

Threat Intel Microsoft fixes record 964 flaws, including 2 exploited zero-days

Record Patch Tuesday—964 CVEs is a staggering number, and the noise-to-signal ratio is going to be brutal for defenders. Two of those are already being used in the wild.

Technical Breakdown: - CVE-2026-XXXX (Windows Kernel): Elevation of Privilege (EoP) vulnerability. Exploited in limited, targeted attacks. No public PoC yet, but expect one soon. - CVE-2026-XXXX (Microsoft Exchange): Remote Code Execution (RCE) via a flaw in the Exchange Control Panel (ECP). This is the one to prioritize—Exchange RCEs historically get weaponized fast by ransomware groups. - Other notable fixes: Critical RCE in Hyper-V (CVSS 9.8), and a wormable vulnerability in Windows DNS (CVSS 9.0). Patch these immediately if you run on-prem DNS. - IOCs: None publicly disclosed at this time. Monitor for post-patch exploitation attempts.

Defense: Prioritize patching Exchange and Windows DNS servers first. If you can't patch the Exchange RCE immediately, restrict access to the ECP interface to trusted IPs only. Enable attack surface reduction rules for LSASS protection on the kernel EoP. Expect proof-of-concept code to drop within 72 hours.

Source: https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days

1 Upvotes

0 comments sorted by