微软9月补丁破纪录 972漏洞 2个已利用
时间:2026年9月9日
地点:美国华盛顿
人物:微软安全响应中心(MSRC)
事件详情:
微软于2026年9月发布月度安全更新,修复了创纪录的972个漏洞,其中112个被评为高危或严重。这是微软连续第二个月打破Patch Tuesday历史纪录。此次数值远超前记录——2026年7月的570个漏洞。
其中两个漏洞已被确认在野外部署利用:
CVE-2026-56164:微软SharePoint Server权限提升漏洞,因缺少身份验证检查,已被用于实际攻击。
CVE-2026-81963:Windows Update Stack权限提升漏洞,同样已在野被利用。
背景:
972个漏洞涵盖Windows操作系统、Azure AI Language、Azure Cosmos DB、Copilot Studio、Entra ID、DirectWrite等多个产品线。112个高危/严重漏洞包括多个远程代码执行(RCE)风险,潜在影响全球数亿Windows用户。
影响:
此次破纪录的漏洞数量凸显了几个重要趋势:AI驱动的代码生成工具正在加速软件迭代,随之带来更多安全缺陷;AI安全威胁已从理论走向实战——AI生成漏洞正在被恶意行为者快速武器化;企业IT安全团队面临巨大压力,需在AI加速的漏洞发现与修补周期中保持同步。
总结:
微软2026年9月安全更新以972个漏洞修复创下Patch Tuesday历史新高,其中2个漏洞已在野被积极利用,112个达到高危或严重等级。安全专家建议所有Windows和Microsoft 365用户立即安装最新补丁。
参考来源:
Ars Technica: https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/
The Record: https://therecord.media/microsoft-vulnerabilities-patch-tuesday-release
Zero Day Initiative: https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-update-review
CyCognito: https://www.cycognito.com/blog/emerging-threat-cve-2026-56164-sharepoint-server-privilege-escalation-via-missing-authentication/
Rapid7: https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026/
Help Net Security: https://www.helpnetsecurity.com/2026/09/04/september-2026-patch-tuesday-forecast/
Microsoft Security Response Center: https://msrc.microsoft.com/update-guide/









