A while ago, Microsoft launched this year's annual feature update, Windows 11 26H2 (Build 22635.4225), on the preview channel, with an official release planned for later this year. However, prior to that, Microsoft has continued to push various security and quality updates, fixing a large number of vulnerabilities. This applies not only to Windows but also to other software.
According to TECHPOWERUP, Microsoft has released 999 vulnerability patches since September, marking one of the largest batch repair efforts in history. Of these 999 patches, Windows accounted for the majority with 723, Office received 111, SQL Server got 62, and third-party projects received 25. It is evident that Microsoft's focus remains on Windows. Among these, two critical vulnerabilities have been fixed: CVE-2026-81963 and CVE-2026-85880, which could be exploited by attackers to gain local privileges and execute code and programs.
Recently, Microsoft announced plans to roll out the Memory Integrity feature to a wider range of devices starting in October. Eligible Windows 11 devices will have Memory Integrity enabled by default. This is a kernel-level protection feature, also known as "Hypervisor-Protected Code Integrity (HVCI)." Based on Virtualization-Based Security (VBS), it uses hardware virtualization to isolate and verify kernel code and drivers, allowing only trusted components to run. This prevents malicious code or drivers from executing on the system, thereby enhancing underlying system security.
Microsoft stated that it will continue to stress-test the security of the Windows kernel, and the large-scale release of vulnerability patches is an important step in the right direction.

