Microsoft Issues Record 974 CVEs in September Patch Tuesday

Microsoft's recent Patch Tuesday has set a new record with 974 CVEs addressed, including two actively exploited vulnerabilities. Adobe also contributed with critical updates.

In a significant security update, Microsoft has released a record-breaking 974 CVEs during its September Patch Tuesday. This marks a notable increase from the 421 fixes issued in August and 622 in July, reflecting a growing trend in vulnerability disclosures.

Active Exploits Identified

Among the vulnerabilities addressed, two have been confirmed as actively exploited zero-days. The first, CVE-2026-85880, is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (ALPC). Exploitation of this flaw can allow an attacker to gain SYSTEM privileges without requiring additional user interaction.

The second zero-day, CVE-2026-81963, also facilitates privilege escalation, this time within the Windows Update Stack. Details on the exploitation of this vulnerability remain limited.

Adobe’s Contributions

Alongside Microsoft, Adobe has released updates addressing 172 CVEs, including a critical vulnerability tracked as CVE-2026-75650, known as StyleSmuggler. This flaw allows unauthenticated attackers to execute remote code in Magento and Adobe Commerce, with confirmed attacks starting on September 4. Organizations operating online stores are advised to prioritize this patch due to its active exploitation.

Additional Vulnerabilities and Recommendations

Microsoft’s update also included numerous other vulnerabilities, with Tenable noting that the total number of CVEs issued is not far from the 1,130 CVEs released in 2025. Among these, CVE-2026-55007, affecting Exchange Server, has been highlighted as particularly critical. It allows remote, unauthenticated code execution via a malicious Visio attachment in emails.

While Microsoft has addressed a substantial number of vulnerabilities, there are concerns regarding CVE-2026-85046, a high-severity flaw in the V8 JavaScript engine used in both Google Chrome and Microsoft Edge. Although Google has issued a patch, Microsoft has yet to provide a security advisory for this vulnerability, leading to uncertainty about its status in Edge.

Conclusion

This month’s Patch Tuesday underscores the urgency for organizations to stay vigilant and prioritize updates, particularly for the vulnerabilities under active exploitation. The significant number of patches issued reflects ongoing challenges in managing software security and the need for timely responses to emerging threats.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 389