In a significant security update, Microsoft has released a record-breaking 974 CVEs during its September Patch Tuesday. This marks a notable increase from the 421 fixes issued in August and 622 in July, reflecting a growing trend in vulnerability disclosures.
Active Exploits Identified
Among the vulnerabilities addressed, two have been confirmed as actively exploited zero-days. The first, CVE-2026-85880, is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (ALPC). Exploitation of this flaw can allow an attacker to gain SYSTEM privileges without requiring additional user interaction.
The second zero-day, CVE-2026-81963, also facilitates privilege escalation, this time within the Windows Update Stack. Details on the exploitation of this vulnerability remain limited.
Adobe’s Contributions
Alongside Microsoft, Adobe has released updates addressing 172 CVEs, including a critical vulnerability tracked as CVE-2026-75650, known as StyleSmuggler. This flaw allows unauthenticated attackers to execute remote code in Magento and Adobe Commerce, with confirmed attacks starting on September 4. Organizations operating online stores are advised to prioritize this patch due to its active exploitation.
Additional Vulnerabilities and Recommendations
Microsoft’s update also included numerous other vulnerabilities, with Tenable noting that the total number of CVEs issued is not far from the 1,130 CVEs released in 2025. Among these, CVE-2026-55007, affecting Exchange Server, has been highlighted as particularly critical. It allows remote, unauthenticated code execution via a malicious Visio attachment in emails.
While Microsoft has addressed a substantial number of vulnerabilities, there are concerns regarding CVE-2026-85046, a high-severity flaw in the V8 JavaScript engine used in both Google Chrome and Microsoft Edge. Although Google has issued a patch, Microsoft has yet to provide a security advisory for this vulnerability, leading to uncertainty about its status in Edge.
Conclusion
This month’s Patch Tuesday underscores the urgency for organizations to stay vigilant and prioritize updates, particularly for the vulnerabilities under active exploitation. The significant number of patches issued reflects ongoing challenges in managing software security and the need for timely responses to emerging threats.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








