The September 2026 Patch Tuesday release from Microsoft totals 974 CVEs — a figure that, according to Tenable, approaches the roughly 1,130 CVEs the company issued for all of 2025. It marks the third consecutive month of record-breaking patch volumes, following 421 fixes in August and 622 in July.
Two of the vulnerabilities are already under active exploitation as zero-days: CVE-2026-85880, a privilege escalation bug in the Windows Advanced Local Procedure Call (ALPC) that can give an attacker SYSTEM-level access, and CVE-2026-81963, another privilege escalation flaw in the Windows Update Stack that also allows SYSTEM access. Microsoft has provided few details on the latter, but Zero Day Initiative’s Dustin Childs warned: “More likely is that this bug is being combined with a code execution bug to spread malware or ransomware.” Both were added to CISA’s Known Exploited Vulnerabilities catalog on Tuesday, with a September 22 deadline for federal agencies to patch.
Childs singled out CVE-2026-55007, one of nine Exchange Server flaws patched this month, as the most important Exchange fix. The remote code execution bug requires no user interaction — an attacker simply sends an email with a malicious Visio attachment, and code executes when the server processes the attachment. “The attacker only needs to get it right once,” Childs said. “Schedule your downtime and update your Exchange servers with haste.” He also counted 20 patches for wormable bugs in this month’s release.
Adobe shipped 172 fixes across 10 bulletins, including StyleSmuggler (CVE-2026-75650), a maximum-severity zero-day in Magento and Adobe Commerce that gives unauthenticated attackers remote code execution. E-commerce security firm Sansec, which discovered the bug, reported attacks starting September 4. The flaw allows attackers to inject malicious PHP code inside Magento templates using “styles” properties to evade detection, installing a backdoor that connects to a command-and-control server. “So far, we have no indication that the backdoor has been weaponized,” Sansec’s forensics team wrote. CISA has set a September 11 deadline for federal agencies to patch this flaw.
The record-breaking patch load comes as AI models rapidly accelerate vulnerability discovery. According to The Verge, the trend began in April when Anthropic’s Mythos model found security vulnerabilities in every major operating system and web browser, followed by OpenAI’s release of a cybersecurity-focused model. “Sources tell me that Microsoft will set another patch Tuesday record today, the third in just a few months,” The Verge reported, noting that the summer has been unusually busy for Windows and security engineers.
Other vendors including Red Hat, SUSE, and Ubuntu also released security updates across a wide range of packages, though none of these were associated with active exploitation at the time of writing.