NoticiasNews

974 CVE en un solo martes: el parche más grande en la historia de Microsoft llega con 20 fallas gusaneables y dos zero-days ya explotados974 CVEs in a Single Tuesday: Microsoft’s Largest Patch Ever Arrives With 20 Wormable Flaws and Two Zero-Days Already Exploited

2026-09-10

El 8 de septiembre de 2026 Microsoft publicó el Patch Tuesday más grande de su historia. La cifra exacta depende de cómo se cuenten los CVE externos y los de Chromium: entre 966 y 997 vulnerabilidades corregidas, con la Zero Day Initiative contando 972 nuevas. A eso hay que sumar otras 204 vulnerabilidades ya corregidas ese mismo mes en Azure, Entra ID, Edge y otros servicios. El total real de septiembre supera con holgura el titular.

Lo que hay que parchear primero

Dos vulnerabilidades ya están siendo explotadas activamente, ambas de escalada de privilegios:

  • CVE-2026-85880 (CVSS 7.8): desbordamiento de buffer en heap en Windows Advanced Local Procedure Call (ALPC). Permite a un atacante local obtener privilegios de SYSTEM. Es apenas el segundo zero-day de ALPC que Microsoft parcha desde enero de 2023.
  • CVE-2026-81963 (CVSS 7.8): falla en el Windows Update Stack que permite escalar privilegios siguiendo un enlace malicioso. Es la primera vulnerabilidad del Update Stack que Microsoft confirma como explotada activamente.

Ambas requieren acceso local, así que se usan después de un primer punto de apoyo, no para entrar. Pero hay tres fallas que merecen prioridad incluso por encima de ellas:

  • CVE-2026-55007: ejecución remota de código en Exchange Server. Un atacante no autenticado envía un adjunto de Visio manipulado; el servidor lo procesa durante la indexación de contenido y ejecuta código. No requiere interacción del usuario. Microsoft advierte que la explotación exige que el sistema esté bajo presión de memoria sostenida, lo que la hace poco confiable, pero un atacante que reintenta solo necesita acertar una vez.
  • CVE-2026-69380 (CVSS 8.1): segunda falla de Exchange. Permite a un atacante autenticado con privilegios bajos suplantar a cualquier usuario de la organización y tomar control de todos los buzones.
  • CVE-2026-69525 (CVSS 9.8): use-after-free en Remote Desktop Services que permite a un atacante no autenticado dentro de la red ejecutar código arbitrario. RDP está en todas partes en entornos empresariales.

Veinte fallas gusaneables

Microsoft corrigió 20 vulnerabilidades clasificadas como gusaneables: permiten a un atacante remoto y no autenticado ejecutar código sin ninguna interacción del usuario, la condición exacta que necesita el malware para propagarse solo de sistema a sistema. Los componentes afectados incluyen servidor DHCP, Active Directory, servidor DNS de Windows, cliente SMB, Netlogon, NFS, RRAS, IP Helper y Message Queuing. Una de ellas, CVE-2026-69730 en DNS (CVSS 9.8), fue descrita por la ZDI como la sucesora espiritual de SigRed, la falla crítica de DNS explotada en 2020.

Por qué el número explotó

El dato interesante no es el récord, sino su causa. Según la ZDI, el volumen viene subiendo de forma sostenida durante 2026 por el uso de IA en la auditoría de código. Los modelos encuentran vulnerabilidades a una velocidad que ningún equipo humano igualaba. Y aquí está la parte incómoda: la ZDI señala explícitamente que todavía no se ve un aumento correlativo de explotación activa. Todavía. 58 de los parches de este mes están marcados por Microsoft como de explotación más probable.

La asimetría es evidente. Si la IA acelera el descubrimiento de fallas para los defensores, lo hace igual para el otro lado. Lo que no escala al mismo ritmo es la capacidad de una organización mediana para probar, priorizar y aplicar casi mil parches.

Qué hacer cuando el volumen supera al equipo

  • Priorizar por exposición real, no por CVSS: un Exchange con cara a internet vale más atención que cien fallas internas de severidad media.
  • Tener un inventario actualizado de activos. No se puede priorizar lo que no se sabe que existe.
  • Instrumentar el proceso de parcheo como flujo con responsable, fecha y evidencia, no como una tarea que alguien recuerda hacer.
  • Aislar lo que no se puede parchear rápido: segmentación de red para RDP, SMB y servicios expuestos.

En TEKFENIX vemos este patrón repetido en las mesas de ayuda que atendemos: cuando el volumen de trabajo técnico supera la capacidad del equipo, lo primero que se pierde no es la ejecución sino el registro de qué se hizo y qué quedó pendiente. Servigo365, nuestra plataforma de mesa de ayuda y atención multicanal con IA, convierte ciclos de parcheo y remediación en tickets con SLA, responsable y trazabilidad, de modo que cuando alguien pregunte por qué ese servidor quedó sin actualizar, la respuesta esté en el sistema y no en la memoria de un técnico. Si su equipo de TI está enfrentando un backlog de seguridad que crece más rápido de lo que se resuelve, conversemos.

On September 8, 2026 Microsoft shipped the largest Patch Tuesday in its history. The exact figure depends on how external and Chromium CVEs are counted: between 966 and 997 vulnerabilities fixed, with the Zero Day Initiative counting 972 new ones. Add another 204 vulnerabilities already patched earlier that month across Azure, Entra ID, Edge and other services, and September’s real total comfortably exceeds the headline.

What to patch first

Two vulnerabilities are already under active exploitation, both privilege escalation:

  • CVE-2026-85880 (CVSS 7.8): heap buffer overflow in Windows Advanced Local Procedure Call (ALPC). Lets a local attacker gain SYSTEM privileges. It is only the second ALPC zero-day Microsoft has patched since January 2023.
  • CVE-2026-81963 (CVSS 7.8): flaw in the Windows Update Stack allowing privilege escalation via a malicious link. It is the first Update Stack vulnerability Microsoft has confirmed as actively exploited.

Both require local access, so they are used after an initial foothold rather than to gain one. But three flaws deserve priority even above them:

  • CVE-2026-55007: remote code execution in Exchange Server. An unauthenticated attacker sends a crafted Visio attachment; the server processes it during content indexing and executes code. No user interaction required. Microsoft notes exploitation requires the system to be under sustained memory pressure, making it unreliable, but an attacker who keeps trying only needs to succeed once.
  • CVE-2026-69380 (CVSS 8.1): a second Exchange flaw. Lets a low-privileged authenticated attacker impersonate any user in the organization and hijack every mailbox.
  • CVE-2026-69525 (CVSS 9.8): use-after-free in Remote Desktop Services allowing an unauthenticated in-network attacker to execute arbitrary code. RDP is everywhere in enterprise environments.

Twenty wormable flaws

Microsoft fixed 20 vulnerabilities classified as wormable: they let a remote, unauthenticated attacker execute code with no user interaction, exactly the condition malware needs to spread on its own from system to system. Affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper and Message Queuing. One of them, CVE-2026-69730 in DNS (CVSS 9.8), was described by ZDI as SigRed’s spiritual successor, referring to the critical DNS flaw exploited in 2020.

Why the number exploded

The interesting data point is not the record but its cause. According to ZDI, volume has been climbing steadily through 2026 because of AI-assisted code auditing. Models find vulnerabilities at a speed no human team matched. And here is the uncomfortable part: ZDI explicitly notes there is not yet a corresponding spike in active exploitation. Not yet. 58 of this month’s fixes are rated by Microsoft as more likely to be exploited.

The asymmetry is obvious. If AI accelerates flaw discovery for defenders, it does the same for the other side. What does not scale at the same rate is a mid-sized organization’s capacity to test, prioritize and deploy nearly a thousand patches.

What to do when volume outpaces the team

  • Prioritize by real exposure, not by CVSS: an internet-facing Exchange server deserves more attention than a hundred internal medium-severity flaws.
  • Keep an updated asset inventory. You cannot prioritize what you do not know exists.
  • Instrument the patching process as a workflow with an owner, a date and evidence, not as a task somebody remembers to do.
  • Isolate what cannot be patched quickly: network segmentation for RDP, SMB and exposed services.

At TEKFENIX we see this pattern repeatedly in the help desks we support: when technical workload exceeds team capacity, the first thing lost is not execution but the record of what was done and what remains open. Servigo365, our AI-powered helpdesk and multichannel service platform, turns patching and remediation cycles into tickets with SLAs, owners and traceability, so that when someone asks why that server went unpatched, the answer is in the system rather than in a technician’s memory. If your IT team is facing a security backlog growing faster than it is resolved, let’s talk.

← Volver al blog← Back to blog