safety Adobe also brought some goodies to the patch party, and they deserve immediate attention. Dear reader, we are facing a vulnerable apocalypse. Microsoft has released a record number of patches this month to address 974 CVEs in its products, including two bugs that Redmond said are already in use. September’s record set of security updates comes after Microsoft released 421 patches in August and 622 in July. We saw the new normal and were not impressed. Thanks, but no thanks, AI. In addition to Microsoft’s massive update rollout, Adobe on Tuesday issued 10 bulletins covering 172 CVEs, including a maximum severity zero-day vulnerability in Magento and its successor Adobe Commerce. Adobe on Monday released a fix for the issue, numbered CVE-2026-75650 and called StyleSmuggler, which allows unauthenticated attackers to remotely execute code. StyleSmuggler If your organization has any online store, prioritize it first as it is already being used to compromise stores, according to e-commerce security store Sansec. Sansec discovered StyleSmuggler and reports that the attacks began on September 4th. Every version of Magento and Adobe Commerce, from 2.4.4 to 2.4.9 inclusive, has this flaw. This bug allows attackers to inject malicious PHP code into Magento templates using the “styles” properties to evade security detection. In the case of confirmed attacks, the payload then installs a backdoor that connects to the command and control server and listens for instructions. “So far we have no indication that the backdoor was used as a weapon,” wrote forensics group Sansec. Don’t wait to find out. Put this at the top of your list of mitigation measures. 974 CVE from Microsoft Moving on to Microsoft’s record 974 CVEs, which is slightly less than the 1,130 CVEs issued in Redmond in 2025, according to Tenable. Two of them are already used as “zero days”. First up: CVE-2026-85880, a privilege escalation issue in Windows Advanced Local Procedure Call (ALPC). Successful exploitation could result in the attacker gaining SYSTEM privileges. “An attacker who is able to execute code in an AppContainer with low privileges could exploit this vulnerability locally to escape the sandbox and escalate privileges on the affected system,” Redmond warned. “No additional user interaction is required.” There is no information yet about who is using this bug and for what purpose. The U.S. Cybersecurity and Infrastructure Security Agency on Tuesday added CVE-2026-85880, as well as a second Microsoft security hole (as well as the Adobe Commerce and Magento zero-day) to its Catalog of Known Exploitable Vulnerabilities and set a Sept. 22 deadline for federal agencies to patch both the new Microsoft bugs and a Sept. 11 deadline for Adobe to patch the vulnerability. The second Microsoft bug discovered and exploited as a zero-day is CVE-2026-81963, another privilege escalation vulnerability. This affects the Windows update stack. We also have very few details about this vulnerability, except that it also allows attackers to gain SYSTEM-level access. “It’s more likely that this bug is combined with a code execution bug to spread malware or ransomware,” opined Dustin Childs of the Zero Day Initiative, who advised users to “fix this bug quickly.” While these are the only two (currently) vulnerabilities in active exploitation, Childs rated CVE-2026-55007, one of nine Exchange Server vulnerabilities discovered this month, as the “most important” patch for the messaging server. It allows an unauthenticated, remote attacker to execute code on a vulnerable Exchange server by sending an email containing a malicious Visio attachment. No user intervention is required and the code is executed when the server processes the attachment while content is indexed. Redmond says it’s “difficult to run reliably,” but as Childs notes, “An attacker only needs to get it right once. Plan for downtime and upgrade your Exchange servers quickly.” Childs also said he has 20 patches to address dangerous bugs, so be sure to read his full patch review on Tuesday. “While some of them may be more vulnerable to exploitation than others, having 20 of them in one release is something else entirely.” Missing CVE While Redmond has patched nearly 1,000 security holes this month alone, it’s also worth noting one that isn’t included in this month’s Patch Tuesday roundup: CVE-2026-85046. Google fixed the bug in Chrome on September 3 and warned at the time that it was “aware of the existence of an exploit for CVE-2026-85046.” A serious type confusion bug exists in the V8 JavaScript engine used in both the Google Chrome and Microsoft Edge browsers. And yet Microsoft has still not published a security advisory for CVE-2026-85046. “If you’re patched, you’re protected, but if you rely on recommendations to know what vulnerabilities exist, you might miss this zero-day vulnerability altogether,” said Adam Barnett, lead software engineer at Rapid7. Register. “A patch without a patch is probably a little better than a patch without a patch, but monitoring risks without good advisory materials is not easy,” Barnett said. “Chrome has patched 11 additional vulnerabilities at the same time as CVE-2026-85046, but it is not yet clear whether they are patched in Edge. Until Microsoft provides clarity, the only safe assumption is that these vulnerabilities (such as CVE-2026-85045) will remain unpatched in Edge.” ® Post navigation Games Inbox: Оправдал ли ремейк Zelda: Ocarina Of Time ожидания? Hotel valet theft: Fake basketball player stole BMW for $155,000