Microsoft Smashes Patch Tuesday Record with 974 CVEs, Including Two Zero-Day Exploits
Microsoft broke its own Patch Tuesday record by releasing patches for 974 CVEs in September. This is on top of the 421 fixes issued in August and 622 in July, which have become a new normal. The company also warned that two of these bugs are already being exploited as zero-days.
The first bug, CVE-2026-85880, is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows attackers to gain SYSTEM privileges without additional user interaction. The second bug, CVE-2026-81963, affects the Windows Update Stack and also allows attackers to gain SYSTEM-level access.
Adobe also released 10 bulletins addressing 172 CVEs, including a max-severity vulnerability exploited as a zero day in Magento and its successor product Adobe Commerce. This vulnerability, tracked as CVE-2026-75650 and named StyleSmuggler, gives unauthenticated attackers remote code execution and has already been used to compromise online shops.
Sansec discovered StyleSmuggler and reports that attacks started on September 4. Every version of Magento and Adobe Commerce from 2.4.4 up to and including 2.4.9 has the flaw, which allows attackers to inject malicious PHP code inside Magento templates using the “styles” properties.