Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
C CyberScoop ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
Microsoft is central to the company's IT infrastructure; two actively exploited zero-days require attention, but the alert contains no geopolitical or nation-state implications.
Description
Microsoft has disclosed two actively exploited zero-days among a total of 974 reported vulnerabilities as part of its monthly patch report. The alert confirms that despite the high number of disclosed vulnerabilities, no widespread exploitation wave has been observed thus far. Security experts recommend organizations prioritize their exposure and risk areas rather than address all 974 patches simultaneously.
Risk score
- strategic relevance
- 0.30
Path: strategic