Microsoft Breaks Another Patch Tuesday Record (bleepingcomputer.com)
- Reference: 0185546816
- News link: https://it.slashdot.org/story/26/09/09/0626256/microsoft-breaks-another-patch-tuesday-record
- Source link: https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
> This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass.
>
> The approximate number of bugs in each vulnerability category is listed below:
> - 438 Elevation of Privilege Vulnerabilities
> - 19 Security Feature Bypass Vulnerabilities
> - 258 Remote Code Execution Vulnerabilities
> - 173 Information Disclosure Vulnerabilities
> - 56 Denial of Service Vulnerabilities
> - 16 Spoofing Vulnerabilities
Last month, Microsoft's Patch Tuesday updates [2]fixed 570 security flaws, following 400 vulnerabilities [3]patched in August.
[1] https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
[2] https://tech.slashdot.org/story/26/07/15/042220/microsoft-patches-a-record-570-security-flaws
[3] https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/
Hospital (Score:2)
Also took down the PACS server at our local hospital. The D drive didn't mount after this update.
Re: (Score:2)
Any luck with that? I see a bunch of changes that could touch it. AD, DNS, credentialguard, LSA, Netlogon...
Re: Hospital (Score:2)
I wonder what the record is for most bugs introduced on a patch Tuesday?
Re: (Score:2)
> How many recent bugs is this now 3000?
Don't know, but I use to make jokes about how often Windows needed a reboot. If I apply every Linux kernel patch when it comes out now it makes MS look good.
Re: (Score:3)
Having LLMs check the code for vulnerabilities seems to be helping all around.
I don't know why this is being treated as a bad thing. I mean, it's bad that attackers can do the same, but that's a Red Queen's Race anyhow.
Re: (Score:2)
They may be introducing more problems now than they fix. Above some level of technological debt and complexity that happens.
Re: (Score:2)
Very true, but we don't know where that level is with AI assisted debugging yet. It's likely higher than it used to be.
Re: (Score:2)
Yeah, but what is anyone supposed to do, not even try to fix the holes? Giving up isn't really a viable option.
Re: (Score:2)
> Having LLMs check the code for vulnerabilities seems to be helping all around.
> I don't know why this is being treated as a bad thing. I mean, it's bad that attackers can do the same, but that's a Red Queen's Race anyhow.
I did not say it is a bad thing, just that this is hardly unique to MS. My Ubuntu 24.04 server for instance had ~70 patches two weeks ago and 100 more last week, and it does not even have a GUI. I fully expect similar numbers this week, and this has been going on for a while. But yes, hopefully even the most obscure bugs in all the popular existing code will eventually be found and then the pace of discovery will slow down and we will all get to enjoy exceptionally secure software going forward. Cough.
Re: (Score:2)
> I don't know why this is being treated as a bad thing.
Because it's Microsoft, and is, therefore, Satan's urine on the heads of smart people like AC. Just ask him.
If they literally started raising the dead on live television, the "I hate M$" crowd would bitch about them desecrating a corpse.
Re: (Score:2)
Hah! "Screw you M$, I didn't even like my grandma!"
It's kinda sad though to see people letting the bugs in their ass override reason. If someone wants to have a software company, fine, but learn to compartmentalize. Don't act like it's bad that vulnerabilities are being fixed. But, there are people who treat OS selection like a virtue signal, so... I don't know, c'est la vie.
Re: (Score:2)
I've seen a lot of updates on several Linux servers recently, but only two in the last couple of months that required a reboot.
Re: (Score:2)
Depends how often you look I guess. I've had multiple kernel updates in a single week on some boxes recently.
Re: (Score:3)
> How many recent bugs is this now 3000?
Yeah, but that unlocked the YouTube channel level called Mystery Patch Theatre 3000..
Too many words (Score:3)
You could have stopped at Microsoft Breaks. We just found a previous update from Microsoft breaks the cellular connection in some of our HP laptops. The update flips the IMEI back to the default. We had to get a patch from HP to fix the update.
Reframing the security holes (Score:2)
They are FEATURES designed to share all your data with the entire world. People just need to figure out how.
Keeping my Windows 11 laptop off for a few days. (Score:2)
I have a Windows 11 laptop that I use occasionally. My daily driver runs Linux.
I'll keep the Windows 11 laptop turned off for a few days for any fallout to occur and bad patches to be pulled.
crap (Score:2)
I wonder how many things they break. :(
Lets not overlook.... (Score:1)
The fact that there were over 100 patches and 80 of them were for remotely exploitable bugs. The average ratio had been exactly the reverse the entire lifetime of the web for all OS's until now.
Loving Linux more and more :) (Score:1)
I'm loving Linux more and more. I have Linux Mint Cinnamon on 2 Laptops and Linux Zorin on another. Now Windows 11 is my bottom third OS only because there's a few Windws Apps still needed. It's so relaxing to NOT to have Windows stop me for very rude updates, in the middle of my work that can take hours to setup, reboot then reboot again.
This is a good thing (Score:2)
The new AI tools are making it easier to find problems
And.... (Score:2)
Update on one computer nuked internet access.
On another, it nuked the camera, PIN, password, the password recovery questions. Wouldn't let me past the login screen.
But it served up advertisements on the login screen. Took a week with my IT guy to fix it. Still not quite right, keeps nagging me about Teams and Onedrive.
81 remote code execution? WTF? (Score:3)
That seems very bad even for Microsoft. Have they been vibe-coding or what?
Re: (Score:2)
> That seems very bad even for Microsoft. Have they been vibe-coding or what?
Yes, but only the patches.
They found vibe-coding the core code only created..more patches.
Which someone finally bitch-slapped the shit out of the marketeer who was selling that crap as a good thing.
Re: (Score:2)
Yes, probably. There is evidence making patches with LLMs often opens other issues, unless you review very carefully.
Re: (Score:2)
That said, with the mountain of technological debt that MS is lugging around, we may have a case here where patching by LLM (or even manually) cannot bring the number of bugs down or reduce their severity, but can only make things worse. This was, as far as I know, only a theoretical scenario for any mainstream software so far. Well, looks like MS may have done something for Science. If so, the only thing that can fix this is throwing it away and starting over. With a time-frame of 10-20 years or longer. Th
Re: (Score:3)
> If so, the only thing that can fix this is throwing it away and starting over. With a time-frame of 10-20 years or longer. That will not go well.
That go-back-and-rebuild-better will never happen for any currently deployed aspect of our global civilization again. At least not by human choice. It would only happen after some tangible event like some silicon-melting alien EMP attack or circuit-devouring nanobot swarm goes rogue.
It's the same thing as that quote that goes something like, "The economy can stay irrational longer than you can stay solvent".
The data centers can stay cycle through coprophagic tokens faster/longer than you can stay solvent.
Tw
Re: (Score:2)
Truth is, MS has been outsourcing their coding for over 20 years now.
And the next truth is, they dont care about OS anymore. Cloud is all they care about. If you notice, not much has been innovated or iterated on Windows OS in the past 5-10 years. Its been more of a maintain and then slap in some online related bullshit to feed their ad revenue, or link to their online services that they want you to eventually move to.
MS is not doing much as a company in the home space, except to try and pull as much info
Re: (Score:2)
I recall seeing a study many years ago into how likely a bug fix was to introduce a bugs. Their conclusion was that the more lines of code you have, the more likely that was to happen. The numbers given were that at one millions lines of code, each bug fix would, on average, introduce 1.2 new bugs. Windows, at that point (XP?) had 400 million lines of code.
Re: (Score:2)
> That seems very bad even for Microsoft. Have they been vibe-coding or what?
More than likely these vulnerabilities have been there for a while, but they started to use AI to find them. Hence why they were able to find so many in this cycle.
Re: (Score:2)
Even Linus has recognized the value of using AI to find vulnerabilities - provided that actual programmers review every single line before submitting it.