Wednesday, September 9, 2026

security

Adobe also brought goodies to the patch party and they deserve immediate attention

Microsoft delivered a record‑setting patch batch for September, fixing 974 Common Vulnerabilities and Exposures (CVEs) across its product line. Two of the flaws are already being exploited as zero‑days.

The September updates follow 421 fixes in August and 622 in July. In addition, Adobe released ten bulletins addressing 172 CVEs. One of these, CVE‑2026‑75650 (StyleSmuggler), is a maximum‑severity, unauthenticated remote code execution vulnerability affecting all versions of Magento and Adobe Commerce from 2.4.4 through 2.4.9. Adobe issued a hotfix on Monday.

StyleSmuggler

Organizations operating online stores should prioritize this issue, as attackers have already begun exploiting it to compromise sites, according to security firm Sansec. The vulnerability allows malicious PHP code to be injected into Magento templates via the “styles” property, bypassing detection and installing a backdoor that contacts a command‑and‑control server. No weaponized payload has been observed to date, but the flaw poses an immediate risk.

Microsoft’s Record‑Breaking CVEs

Among Microsoft’s 974 patches, two are already under active exploitation: CVE‑2026‑85880, a privilege‑escalation bug in Windows Advanced Local Procedure Call (ALPC) that enables an attacker with low‑privilege AppContainer code execution to escape the sandbox and obtain SYSTEM rights; and CVE‑2026‑81963, a Windows Update Stack elevation vulnerability that also grants SYSTEM access. Both were added to the U.S. CISA Known Exploited Vulnerabilities Catalog, with a September 22 compliance deadline for federal agencies.

Additional critical fixes include nine Exchange Server vulnerabilities, the most notable being CVE‑2026‑55007. This flaw allows remote, unauthenticated attackers to execute arbitrary code via a malicious Visio attachment sent as an email, without requiring user interaction. Although Microsoft notes the exploit is difficult to trigger, security researchers advise immediate patching.

Analysts identified roughly 20 wormable vulnerabilities in the release, underscoring the importance of swift deployment.

A Notable Omitted CVE

Google patched CVE‑2026‑85046—a high‑severity type‑confusion issue in the V8 JavaScript engine—on September 3, warning that exploits were already in the wild. The same flaw affects Microsoft Edge, yet Microsoft has not yet released a security advisory for it. Security experts caution that reliance on advisories alone can lead to missed exposures.

Source link

Exit mobile version