Microsoft breaks Patch Tuesday record with 974-CVE deluge
AI Signal Decode
Microsoft's September Patch Tuesday has set a new record with 974 CVEs addressed, far exceeding the 421 and 622 from the preceding months. This deluge underscores a persistent and escalating security threat landscape for Microsoft products. The presence of two zero-day vulnerabilities, CVE-2026-85880 (ALPC privilege escalation) and CVE-2026-81963 (Windows Update Stack privilege escalation), which are already being exploited, elevates the urgency for immediate patching. These flaws permit attackers to gain SYSTEM privileges, posing a severe risk to system integrity and data security. The Cybersecurity and Infrastructure Security Agency (CISA) has already added these to its Known Exploited Vulnerabilities Catalog, mandating swift remediation for federal agencies.
Adobe's contribution to the patch cycle includes 10 bulletins covering 172 CVEs, most critically a zero-day in Magento and Adobe Commerce, CVE-2026-75650, also known as 'StyleSmuggler.' This vulnerability allows unauthenticated attackers remote code execution and is actively exploited, particularly impacting e-commerce platforms. Its ability to evade detection through malicious PHP code injection via 'styles' properties, leading to backdoor installation, demands immediate prioritization for affected online retailers. The combined patch load from both Microsoft and Adobe represents a substantial operational burden, requiring organizations to allocate significant resources for comprehensive vulnerability management.
Beyond the actively exploited flaws, Microsoft also released patches for numerous other critical vulnerabilities, including 20 potentially wormable bugs and a highly concerning Exchange Server flaw (CVE-2026-55007). This latter vulnerability allows unauthenticated attackers to execute code via malicious Visio attachments in emails during content indexing, presenting a significant risk to messaging infrastructure. The sheer quantity and varied nature of the vulnerabilities highlight the complexity of securing Microsoft's extensive product ecosystem. Furthermore, the delayed or missing advisories for certain vulnerabilities, like CVE-2026-85046 patched by Google in Chrome but not yet officially detailed by Microsoft for Edge, adds another layer of challenge for security teams trying to maintain comprehensive visibility and protection.