Record Microsoft Patch Tuesday: 974 Flaws, Two Zero-Days

What happened
Microsoft used this month's Patch Tuesday to fix an unprecedented 974 vulnerabilities across its product portfolio, and two of them were already being exploited in the wild as Windows zero-days. According to reporting from feeds.feedburner.com — Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days — the total breaks down to roughly 723 Windows issues, 111 in Office and Office 2016, 62 in SQL Server, and 22 in developer tooling, with more than 110 rated critical.
That is not a typo, and it is not a normal month. For context, a heavy Patch Tuesday is usually well under 200 CVEs. The specific CVE identifiers, affected build numbers, and whether either zero-day has a workaround are details you should verify directly in Microsoft's security update guide rather than assume — we are not going to guess at exploit mechanics that the source did not spell out.

Why this matters for Pittsburgh small and mid-sized businesses
A record patch volume creates two distinct problems for a 10-to-200-person firm, and they pull in opposite directions.
First, the exploited zero-days mean speed matters. "Actively exploited" is the phrase that should move a Windows patch from your normal monthly cycle to a same-week deployment. Attackers who are already using a Windows flaw do not care whether you're a 22-person CPA practice in Wexford or a 140-person machine shop in the Mon Valley — they scan broadly and follow up on whatever answers. Local SMBs remain attractive precisely because patch windows tend to slip when there's no dedicated IT staff and Q4 planning is underway.
Second, the sheer breadth raises the odds that something in your environment breaks. With 723 Windows fixes landing at once, the blast radius touches print, authentication, RDP, and networking components that line-of-business software depends on. If you're a law firm running a document management server, a healthcare practice on a legacy EHR client, or a manufacturer with a Windows box tethered to shop-floor equipment, "patch everything tonight" is a real operational risk. The answer is sequencing, not stalling.
Three verticals should pay extra attention. Defense contractors under CMMC obligations have explicit expectations around flaw remediation timeliness — the 62 SQL Server fixes matter here too, because SQL instances often hold or index CUI without anyone documenting it. Healthcare and financial services firms operating under HIPAA and the FTC Safeguards Rule need to show that vulnerability management is a running program, not a reaction. And accounting and legal firms with SOC 2 commitments will be asked, at the next audit, to produce evidence that critical patches were applied inside your stated SLA.
One more Pittsburgh-specific note: the Office and Office 2016 fixes are a reminder that a surprising number of local firms still have perpetual Office licenses sitting alongside their Microsoft 365 tenant. Those older installs frequently fall outside cloud-managed update channels. If nobody has inventoried them recently, that's this month's blind spot.
What to do about it this week
- Confirm the two exploited Windows zero-days are covered first. Pull the CVE numbers from Microsoft's advisory, map them to your OS builds, and deploy to internet-facing and high-privilege systems ahead of everything else. Do not wait for a full regression test on flaws that are already being used.
- Get a real inventory number before you report progress. You cannot claim 95% patched if 15% of endpoints haven't checked in for a month. Ask your provider for the count of devices with no successful update in 30+ days — stale agents, not missing patches, are the usual gap in patch management reporting.
- Ring-fence your fragile systems. Identify the servers and workstations tied to EHR clients, practice management platforms, CAD, or shop-floor controllers. Put them in a later deployment ring with a tested rollback, and compensate in the meantime with tighter network segmentation and stricter access.
- Patch SQL Server deliberately. The 62 SQL fixes will need maintenance windows and, in many cases, coordination with your application vendor. Schedule those now rather than discovering the dependency during a Friday reboot.
- Hunt for unmanaged Office installs. Standalone Office 2016 and older suites, terminal servers, and contractor-owned laptops that touch your data all need explicit attention. Anything you can't patch should be scheduled for replacement on your technology roadmap.
- Verify your detection layer is actually reporting. Patching reduces exposure; EDR catches what slips through the gap between disclosure and deployment. Confirm coverage percentage, that alerts route to a human who is awake, and that isolation actions work.
- Write down what you did. Capture the deployment date, exception list, business justification for each exception, and remediation target. If you're facing a CMMC assessment, SOC 2 audit, or Safeguards Rule review in the next quarter — meaning anything before mid-December — this month's record patch cycle is exactly the sample an assessor will pick.
A closing caution for anyone piloting AI tooling: a month like this is a good moment to re-check that Copilot and any internal AI tool you've deployed sit behind patched, properly licensed infrastructure with documented data boundaries. New capability on unpatched foundations is how good projects turn into incidents.
How we help
PGH Networks handles this cycle for Pittsburgh-area firms every month: ringed patch deployment through our RMM, exception tracking with documented business justification, managed detection to cover the exposure window, and audit-ready evidence mapped to HIPAA, SOC 2, CMMC, and FTC Safeguards requirements. If you're not certain who owns patching in your environment, or whether the zero-days are already closed, that's a fifteen-minute conversation, not a project.
Call us at 724.888.7007 or reach out through the contact form and we'll review your current patch posture with you.
Related reading

Unpatched ScreenConnect Flaw: What Pittsburgh SMBs Should Do
ConnectWise warns of a ScreenConnect remote access flaw with no patch yet. What Pittsburgh SMBs in legal, CPA, healthcare and defense should verify now.

Actively Exploited Chrome Zero-Day: Restart Browsers Today
Google patched an actively exploited Chrome zero-day in the V8 engine plus 11 other flaws. Here is what Pittsburgh SMBs should verify and fix this week.

TerminalFix: Fake CAPTCHA Prompts Target Windows Users
Microsoft warns of TerminalFix, a ClickFix variant using fake Cloudflare CAPTCHA prompts to run malicious PowerShell. What Pittsburgh SMBs should do now.