Skip to main content
CybersecurityVulnerability Management

Microsoft Delivers Record 974 Patches, Warns of Zero-Day Exploits

Rows of computer equipment racks in a server room with technicians working in the background and a single server in focus.

"The vulnpocalypse is upon us, dear reader," The Register wrote — and this month Microsoft supplied the evidence.

Microsoft’s 974-CVE patch drop — scale and context

On September 9, Microsoft released a record 974 CVE fixes in its monthly Patch Tuesday collection, a jump after August’s 421 fixes and July’s 622. Tenable noted that the total is not far off the 1,130 CVEs Microsoft issued in 2025. Of the 974, Redmond identified two vulnerabilities already under active exploitation as zero-days. The scale of the drop — and the presence of exploited flaws — forced rapid triage decisions across enterprises and agencies.

StyleSmuggler (CVE-2026-75650): Adobe, Magento and active exploitation

Adobe issued 10 bulletins addressing 172 CVEs alongside Microsoft’s torrent. One Adobe fix stands out: a hotfix shipped Monday for CVE-2026-75650, tracked and named StyleSmuggler, which gives unauthenticated attackers remote code execution. Sansec, the e-commerce security shop that discovered the bug, reported attacks began on September 4 and warned that every version of Magento and Adobe Commerce from 2.4.4 through 2.4.9 contains the flaw.

According to Sansec, the bug lets attackers inject malicious PHP code inside Magento templates using the “styles” properties to evade safety detections; in confirmed attacks the payload installs a backdoor that connects to a command-and-control server and waits for instructions. The Sansec Forensics Team wrote, “So far, we have no indication that the backdoor has been weaponized.” CISA added the Adobe Commerce/Magento zero-day to its Known Exploited Vulnerabilities Catalog and set a September 11 deadline for federal agencies to patch the flaw.

Two Microsoft zero-days: CVE-2026-85880 and CVE-2026-81963

Microsoft identified two of its September fixes as exploited in the wild. CVE-2026-85880 is a privilege escalation bug in Windows Advanced Local Procedure Call (ALPC). Redmond warned: “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system,” and added that “No additional user interaction is required.”

The second exploited issue, CVE-2026-81963, is another privilege escalation that affects the Windows Update Stack and likewise allows SYSTEM-level access. Public detail on the latter is thin; Zero Day Initiative’s Dustin Childs wrote that “More likely is that this bug is being combined with a code execution bug to spread malware or ransomware,” and advised users: “Patch this one quickly.” CISA added both Microsoft bugs to its Known Exploited Vulnerabilities Catalog and set a September 22 deadline for federal agencies to remediate them.

Exchange server risk, wormable counts, and the missing browser advisory

Among Microsoft’s fixes are nine Exchange Server vulnerabilities. Dustin Childs called CVE-2026-55007 “the most important” Exchange patch: it allows a remote, unauthenticated attacker to execute code by sending an email with a malicious Visio attachment; the code runs when the server processes the attachment during content indexing. Redmond described the flaw as “difficult to reliably trigger,” but Childs cautioned: “The attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.”

Childs also counted 20 patches for wormable bugs in the release, a concentration he stressed as notable. Separately, Google patched CVE-2026-85046 in Chrome on September 3 and warned an exploit exists in the wild; the bug is a type confusion issue in the V8 JavaScript engine used in Chrome and Microsoft Edge. Microsoft had not published a corresponding advisory at the time of the Register’s reporting. Adam Barnett, lead software engineer at Rapid7, told The Register: “If you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether.” Barnett added that Chrome patched 11 other vulnerabilities alongside CVE-2026-85046 and said it was unclear whether those are patched in Edge, noting that “Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.”

What this means for federal agencies, e-commerce operators, and security teams

  • Federal agencies: CISA’s inclusion of the Adobe and the two Microsoft zero-days in its Known Exploited Vulnerabilities Catalog carries firm remediation dates — September 11 for the Adobe Commerce zero-day, September 22 for the two Microsoft privilege-escalation bugs — creating immediate compliance and patching deadlines.
  • E‑commerce operators (Magento / Adobe Commerce): Sansec’s discovery and confirmed attacks beginning September 4 place the StyleSmuggler fix at the top of operational priorities; affected shops running Magento/Adobe Commerce 2.4.4–2.4.9 should treat the hotfix as urgent to prevent backdoor installation and C2 communications.
  • Security teams and platform owners: The sheer volume — 974 Microsoft CVEs, 172 Adobe CVEs — plus Childs’ count of 20 wormable fixes and multiple privilege-escalation zero-days, means triage must prioritize exploited bugs, wormable issues, and internet-exposed services such as Exchange.

September’s Patch Tuesday is a blunt reminder: the quantity of fixes can be as consequential as their severity. Two Microsoft bugs are already being exploited and Adobe’s StyleSmuggler is being used to compromise stores; CISA has set remediation deadlines for federal agencies; and questions remain — notably who is exploiting the Microsoft zero-days and to what end — that only further patching, monitoring, and forensics will answer.

Original story: https://www.theregister.com/security/2026/09/09/microsoft_breaks_patch_tuesday_record_with_974_cve_deluge/5295160