security
Adobe also brought goodies to the patch party and they deserve immediate attention
Microsoft delivered a record‑setting patch batch for September, fixing 974 Common Vulnerabilities and Exposures (CVEs) across its product line. Two of the flaws are already being exploited as zero‑days.
The September updates follow 421 fixes in August and 622 in July. In addition, Adobe released ten bulletins addressing 172 CVEs. One of these, CVE‑2026‑75650 (StyleSmuggler), is a maximum‑severity, unauthenticated remote code execution vulnerability affecting all versions of Magento and Adobe Commerce from 2.4.4 through 2.4.9. Adobe issued a hotfix on Monday.
StyleSmuggler
Organizations operating online stores should prioritize this issue, as attackers have already begun exploiting it to compromise sites, according to security firm Sansec. The vulnerability allows malicious PHP code to be injected into Magento templates via the “styles” property, bypassing detection and installing a backdoor that contacts a command‑and‑control server. No weaponized payload has been observed to date, but the flaw poses an immediate risk.
Microsoft’s Record‑Breaking CVEs
Among Microsoft’s 974 patches, two are already under active exploitation: CVE‑2026‑85880, a privilege‑escalation bug in Windows Advanced Local Procedure Call (ALPC) that enables an attacker with low‑privilege AppContainer code execution to escape the sandbox and obtain SYSTEM rights; and CVE‑2026‑81963, a Windows Update Stack elevation vulnerability that also grants SYSTEM access. Both were added to the U.S. CISA Known Exploited Vulnerabilities Catalog, with a September 22 compliance deadline for federal agencies.
Additional critical fixes include nine Exchange Server vulnerabilities, the most notable being CVE‑2026‑55007. This flaw allows remote, unauthenticated attackers to execute arbitrary code via a malicious Visio attachment sent as an email, without requiring user interaction. Although Microsoft notes the exploit is difficult to trigger, security researchers advise immediate patching.
Analysts identified roughly 20 wormable vulnerabilities in the release, underscoring the importance of swift deployment.
A Notable Omitted CVE
Google patched CVE‑2026‑85046—a high‑severity type‑confusion issue in the V8 JavaScript engine—on September 3, warning that exploits were already in the wild. The same flaw affects Microsoft Edge, yet Microsoft has not yet released a security advisory for it. Security experts caution that reliance on advisories alone can lead to missed exposures.
Also Read
- US Army Awards $465 Million Contract for AeroVironment’s LOCUST X3 Anti-Drone Laser, Featuring Xbox Controller Interface
- Supreme Court Orders TV Stations to Offer More Election Ads at Deep Discounts
- Google Research Finds Linking Removal of AI Consciousness Safeguards to Enhanced Supernatural And Animal-Minded Perceptions
- OpenAI AI Agents Solve Decades-Old Fluid Dynamics Puzzle in Under Four Days


