Microsoft's September 2026 Patch Tuesday has broken its own record with 974 CVEs, two of them already under active attack. Combined with a maximum-severity Adobe Commerce zero-day, UK infrastructure teams face one of the heaviest single-month patch burdens of the year — with government-set deadlines already ticking.
View the data behind this chart
| CVE count | July | August | September |
|---|---|---|---|
| Microsoft CVEs | 622 | 421 | 974 |
A record-breaking release, and not the first this year
Microsoft's latest Patch Tuesday delivers 974 CVEs, according to The Register, eclipsing July's 622 and August's 421 fixes. Tenable notes the September total is not far off the 1,130 CVEs Microsoft issued across the whole of 2025 — which means, as The Register points out, this one month's release almost matches a full year of 2025 CVEs. For UK teams still running quarterly or even monthly patch cycles, that pace is simply not sustainable without a triage model that separates urgent exploited flaws from the long tail of theoretical risk.
Adobe added to the load with 10 bulletins covering 172 CVEs on the same day, including a maximum-severity zero-day in Magento and Adobe Commerce. Between the two vendors, security teams are looking at well over 1,100 new CVEs disclosed between Monday's Adobe hotfix and Tuesday's Microsoft release.
Two Microsoft zero-days already being exploited
The two flaws Microsoft confirms are under active exploitation are both privilege escalation bugs. CVE-2026-85880 affects Windows Advanced Local Procedure Call and lets an attacker who can already run code in a low-privilege AppContainer escape the sandbox and reach SYSTEM level with no further user interaction. CVE-2026-81963 hits the Windows Update Stack and again grants SYSTEM-level access; Zero Day Initiative's Dustin Childs suggested it is more likely being chained with a separate code-execution bug to spread malware or ransomware.
CISA added both to its Known Exploited Vulnerabilities catalogue on Tuesday, setting federal agencies a 22 September deadline to remediate. UK organisations don't answer to CISA, but the catalogue is a useful proxy for real-world urgency — if a US federal deadline exists, treat it as the outer limit for your own Windows Server patching, not the target.
StyleSmuggler: the Adobe Commerce flaw to fix first
Every version of Magento and Adobe Commerce from 2.4.4 through 2.4.9 carries CVE-2026-75650, dubbed StyleSmuggler by discoverer Sansec. It allows unauthenticated attackers to smuggle malicious PHP through a template's "styles" property, evading detection, and then drop a backdoor that phones home to a command-and-control server. Sansec says exploitation began on 4 September, days before Adobe's Monday hotfix and this week's disclosure. CISA has given federal agencies until 11 September — effectively immediately — to patch.
Any organisation running an online storefront on Magento or Adobe Commerce should treat this as the top item on this month's list, ahead of even the Microsoft zero-days, given confirmed in-the-wild compromise. Sansec says there's no evidence yet that the backdoor itself has been weaponised for further payloads, but that is not a reason to wait. Read more on the StyleSmuggler zero-day for the technical detail behind the attack chain.

Exchange Server and 20 wormable bugs
Buried among nine Exchange Server flaws this month is CVE-2026-55007, which Childs rates as the release's most important Exchange patch. A remote, unauthenticated attacker can trigger code execution simply by sending an email with a malicious Visio attachment — no clicks required, since the payload fires when the server indexes the attachment's content. Microsoft describes it as difficult to reliably trigger, but as Childs puts it, "the attacker only needs to get it right once." Exchange administrators should schedule downtime for this patch specifically rather than folding it into a routine maintenance window.
Childs also counts 20 patches this month addressing wormable vulnerabilities — flaws capable of self-propagating across a network without user interaction. Twenty in a single release is an unusually high number, and it strengthens the case for organisations running vulnerability management solutions that can flag and sequence wormable-class bugs automatically rather than relying on manual triage of a 974-item list.
The advisory Microsoft hasn't published
Google patched a high-severity type confusion flaw in Chrome's V8 engine, CVE-2026-85046, on 3 September, warning that an exploit already existed in the wild. That same V8 engine underpins Microsoft Edge — yet Microsoft has still not issued a security advisory for it. Rapid7's Adam Barnett told The Register that patched systems are protected regardless, but teams that rely on advisories to track exposure could miss the issue entirely. He also flagged that it's unclear whether 11 other Chrome fixes issued alongside CVE-2026-85046, including CVE-2026-85045, have reached Edge at all.
The safe assumption for UK teams: patch Chrome installations immediately on Google's own timetable, and treat Edge as unpatched against this batch until Microsoft confirms otherwise. This is a good moment to check that browser update policies aren't silently gated behind a Microsoft advisory that never arrives.
View the data behind this chart
| Status | Deadline | Action | |
|---|---|---|---|
| Adobe Commerce zero-day | Exploited | Sept 11 | Patch+rotate keys |
| Windows ALPC EoP | Exploited | Sept 22 | Patch now |
| Update Stack EoP | Exploited | Sept 22 | Patch now |
| Exchange Visio RCE | Not seen yet | No CISA deadline | Schedule downtime |
| Chrome/Edge V8 flaw | Exploited (Chrome) | No advisory yet | Patch Chrome/Edge |
Sequencing the patch run across mixed UK estates
With 974 Microsoft CVEs, 172 Adobe CVEs and an unresolved Chrome/Edge gap, a full-sweep patch cycle this month isn't realistic for most estates. A practical sequence: patch the Adobe Commerce/Magento zero-day today if you run any storefront, then the two exploited Microsoft privilege-escalation bugs across Windows Server and endpoints, then Exchange Server's Visio-triggered flaw with a scheduled maintenance window, then Chrome, then the remaining wormable-class bugs Childs has flagged, before working through the rest of the 974.
For organisations running legacy or end-of-life hardware that can no longer take the latest cumulative updates cleanly, third-party maintenance for mixed estates can buy time to test patches properly rather than rushing a fix onto production. Where systems have already fallen out of vendor support entirely, the guidance on securing end-of-support servers is worth revisiting alongside this release, since neither of the two exploited zero-days will be backported to unsupported branches. Layering ransomware protection strategies and managed detection & response around the patch window also reduces the blast radius if any of the 974 CVEs are exploited before your rollout completes.
- 01The Register — Microsoft breaks Patch Tuesday record with 974 CVE deluge · 9 September 2026
- 02Computer Weekly — Patch Tuesday: Microsoft updates address almost 1,000 flaws · 9 September 2026
- 03Dark Reading — Patch Tuesday Sets Another Record With 974 CVEs · 9 September 2026
- 04The Hacker News — Microsoft Patches Record 974 Flaws · 9 September 2026
- 05The Hacker News — Adobe Patches Magento Zero-Day · 9 September 2026
- 06The Register — Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC · 3 September 2026
- 07bleepingcomputer.com
- 08thehackernews.com
