Microsoft breaks Patch Tuesday record with 974-CVE deluge
- ID
- 22606
- Status
- summarized
- Published
- 09 Sep 2026, 8:25 AM
- Fetched
- 09 Sep 2026, 10:15 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/09/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge/5295160
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.5
- Created
- 09 Sep 2026, 10:16 AM
- Tags
- Audience
- developerssaas_founders
What happened
Microsoft shipped a record 974 CVEs in September 2026 Patch Tuesday, including two zero-days already under exploitation—most notably CVE-2026-85880, a Windows ALPC privilege escalation allowing sandbox escape to SYSTEM. Separately, Adobe disclosed CVE-2026-75650 ('StyleSmuggler'), a max-severity unauthenticated RCE in Magento and Adobe Commerce (versions 2.4.4 through 2.4.9), actively exploited since September 4 to install backdoors connecting to C2 servers.
Why it matters
If you operate any Magento or Adobe Commerce store, patch StyleSmuggler immediately—attacks are live and every version from 2.4.4 to 2.4.9 is vulnerable. For Windows shops, prioritize CVE-2026-85880 on systems where low-privilege AppContainer code runs, as it enables silent sandbox escape to SYSTEM. The 974-CVE volume itself is noise; focus on the two exploited Microsoft zero-days and the Magento RCE.
Discussion angle
How many Malaysian e-commerce builds still run Magento/Adobe Commerce, and what's the realistic patching SLA for a platform with this many consecutive vulnerable versions?