SecurityDeveloping

Microsoft Shatters Patch Tuesday Record with 974 CVEs, Two Zero-Days Already Exploited

Record-breaking patch load driven by AI vulnerability discovery as Adobe also ships emergency fix for Magento/Commerce bug

edit
By LineZotpaper
Published
Updated
Read Time3 min
Sources3 outlets
Microsoft has shattered its own Patch Tuesday record with 974 security fixes this month, including two zero-day vulnerabilities already under active exploitation, as the company continues to grapple with a wave of vulnerabilities discovered by AI models. Adobe simultaneously issued 172 patches, including an emergency fix for a Magento and Adobe Commerce zero-day that is already being abused to compromise online stores.

The September 2026 Patch Tuesday release from Microsoft totals 974 CVEs — a figure that, according to Tenable, approaches the roughly 1,130 CVEs the company issued for all of 2025. It marks the third consecutive month of record-breaking patch volumes, following 421 fixes in August and 622 in July.

Two of the vulnerabilities are already under active exploitation as zero-days: CVE-2026-85880, a privilege escalation bug in the Windows Advanced Local Procedure Call (ALPC) that can give an attacker SYSTEM-level access, and CVE-2026-81963, another privilege escalation flaw in the Windows Update Stack that also allows SYSTEM access. Microsoft has provided few details on the latter, but Zero Day Initiative’s Dustin Childs warned: “More likely is that this bug is being combined with a code execution bug to spread malware or ransomware.” Both were added to CISA’s Known Exploited Vulnerabilities catalog on Tuesday, with a September 22 deadline for federal agencies to patch.

Childs singled out CVE-2026-55007, one of nine Exchange Server flaws patched this month, as the most important Exchange fix. The remote code execution bug requires no user interaction — an attacker simply sends an email with a malicious Visio attachment, and code executes when the server processes the attachment. “The attacker only needs to get it right once,” Childs said. “Schedule your downtime and update your Exchange servers with haste.” He also counted 20 patches for wormable bugs in this month’s release.

Adobe shipped 172 fixes across 10 bulletins, including StyleSmuggler (CVE-2026-75650), a maximum-severity zero-day in Magento and Adobe Commerce that gives unauthenticated attackers remote code execution. E-commerce security firm Sansec, which discovered the bug, reported attacks starting September 4. The flaw allows attackers to inject malicious PHP code inside Magento templates using “styles” properties to evade detection, installing a backdoor that connects to a command-and-control server. “So far, we have no indication that the backdoor has been weaponized,” Sansec’s forensics team wrote. CISA has set a September 11 deadline for federal agencies to patch this flaw.

The record-breaking patch load comes as AI models rapidly accelerate vulnerability discovery. According to The Verge, the trend began in April when Anthropic’s Mythos model found security vulnerabilities in every major operating system and web browser, followed by OpenAI’s release of a cybersecurity-focused model. “Sources tell me that Microsoft will set another patch Tuesday record today, the third in just a few months,” The Verge reported, noting that the summer has been unusually busy for Windows and security engineers.

Other vendors including Red Hat, SUSE, and Ubuntu also released security updates across a wide range of packages, though none of these were associated with active exploitation at the time of writing.

§

Analysis

Why This Matters

  • Organizations already processing a constant stream of patches from Microsoft and Adobe face an overwhelming update cadence, increasing the likelihood of exploits succeeding against unpatched systems.
  • Two Microsoft zero-days and one Adobe zero-day are actively exploited, giving attackers a head start; the Exchange Server flaw enables full server compromise without user interaction.
  • The record volumes, tied to AI-driven vulnerability discovery, signal a structural shift in the security patch landscape that is unlikely to reverse.

Background

Microsoft's Patch Tuesday volumes have surged dramatically since mid-2025, with the September 2026 release of 974 CVEs approaching the entire 2025 total of roughly 1,130 CVEs. The trend correlates with advanced AI models from Anthropic (Mythos) and OpenAI that systematically probe for vulnerabilities across major platforms, generating far more findings than traditional methods. August 2026 had 421 fixes, July had 622, and the pace continues to accelerate. Adobe typically issues monthly patches but its September bulletins included an emergency hotfix for StyleSmuggler due to active exploitation.

Key Perspectives

Microsoft: The company is releasing patches as fast as vulnerabilities are discovered, but the sheer volume is straining enterprise patching workflows and carries risk of deployment errors. Security researchers (ZDI, Sansec): They emphasize prioritizing the most dangerous bugs — the exploited zero-days, the Exchange Server RCE, and the Adobe Commerce flaw — while noting that wormable bugs require immediate attention. E-commerce site operators: The Magento/Adobe Commerce StyleSmuggler bug is being actively exploited since September 4, making patching an urgent priority for any online store on those platforms.

What to Watch

  • Whether additional zero-days emerge from the 974 CVE set in the coming weeks.
  • Adoption rates of the Exchange Server patch (CVE-2026-55007) given its high risk and low complexity of exploitation.
  • Further AI-driven vulnerability disclosures expected from Anthropic and OpenAI, which could drive even larger patch volumes in October 2026.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.