Microsoft releases its September Patch Tuesday update covering 974 security vulnerabilities across its software. The company says two of the fixed issues are privilege-escalation zero-days that are actively exploited in the wild, and it also addresses additional weaknesses that could enable further compromise.

Across coverage, sources note the scale and distribution of the flaws by product area. One outlet reports the update includes 723 vulnerabilities in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Another source highlights that, in addition to the two exploited zero-days, the release includes 20 potentially wormable vulnerabilities.

Both accounts emphasize that more than 110 issues are rated critical, but they focus on different aspects of the release—one on the record count and exploitation status, the other on the number of potentially wormable flaws and the nature of the two exploited privilege-escalation problems.