Back Theregister Microsoft breaks Patch Tuesday record with 974-CVE deluge
Adobe also brought goodies to the patch party and they deserve immediate attention
Bing Wallpaper app opens Harry Potter's chamber of ads 4 hours ago
Bing Wallpaper app opens Harry Potter's chamber of ads
BigBear phishing crew nets thousands of Microsoft 365 credentials 10 hours ago
BigBear phishing crew nets thousands of Microsoft 365 credentials
ASCII smuggling isn't just an AI security risk 4 days ago
ASCII smuggling isn't just an AI security risk
My Word. Microsoft's prepping Similarity Checker for retirement 4 days ago
My Word. Microsoft's prepping Similarity Checker for retirement
Microsoft to bounce mail from outdated Exchange servers 4 days ago
Microsoft to bounce mail from outdated Exchange servers
The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation.
September's record-breaking collection of security updates come after Microsoft served up 421 fixes in August , and 622 in July . We've seen the new normal and we are not impressed. Thanks, but no thanks, AI.
In addition to Microsoft’s massive patch drop, Adobe on Tuesday issued 10 bulletins addressing 172 CVEs , including a max-severity vulnerability exploited as a zero day in Magento and its successor product Adobe Commerce. Adobe on Monday shipped a hotfix for this one, tracked as CVE-2026-75650 and named StyleSmuggler, that gives unauthenticated attackers remote code execution.
If your organization has any type of online shop, prioritize this one first as it’s already being abused to compromise stores, according to e-commerce security shop Sansec.
Sansec discovered StyleSmuggler , and reports that attacks started on September 4. Every version of Magento and Adobe Commerce, from 2.4.4 up to and including 2.4.9, has the flaw.
The bug allows attackers to inject malicious PHP code inside Magento templates using the “styles” properties to evade safety detections. In confirmed attacks, the payload then installs a backdoor that connects to a command-and-control server and waits for instructions. “So far, we have no indication that the backdoor has been weaponized,” the Sansec Forensics Team wrote.
Don’t wait to find out on this one. Put it at the top of your mitigation list.
On to Microsoft’s record-breaking 974 CVEs , which according to Tenable is not many fewer than the 1,130 CVEs Redmond issued in 2025 .
Two are already being exploited as zero-days.
First up: CVE-2026-85880 , a privilege escalation bug in Windows Advanced Local Procedure Call (ALPC). Successful exploitation can result in the attacker gaining SYSTEM privileges.
“An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system,” Redmond warned. “No additional user interaction is required.”
No word yet on who is exploiting this bug, and to what end. The US Cybersecurity and Infrastructure Security Agency on Tuesday added CVE-2026-85880 plus a second Microsoft security hole (and the Adobe Commerce and Magento zero-day) to its Known Exploited Vulnerabilities Catalog , and set a September 22 deadline for federal agencies to fix both new Microsoft bugs and a September 11 deadline to patch the Adobe flaw.
The second Microsoft bug found and exploited as a zero-day is CVE-2026-81963 , another privilege escalation vulnerability. This one affects the Windows Update Stack. We also have very little detail this flaw, other than it also allows attackers to gain SYSTEM-level access.
“More likely is that this bug is being combined with a code execution bug to spread malware or ransomware,” opined Zero Day Initiative’s Dustin Childs, who advised users to “Patch this one quickly.”
While those are the only two (so far) under active exploitation, Childs rated CVE-2026-55007 , one of nine Exchange Server flaws disclosed this month, as “the most important” patch for the messaging server.
It allows a remote, unauthenticated attacker to execute code on a vulnerable Exchange server by sending an email with a malicious Visio attachment. No user interaction is required, and the code executes when the server processes the attachment during content indexing.
Redmond says it’s “difficult to reliably trigger,” but as Childs points out: “The attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.”
Childs also said he counts 20 patches for wormable bugs, so be sure to read his full Patch Tuesday review for those. “While some might be more exploitable than others, having 20 of them in a single release is something else.”
While Redmond addressed nearly 1,000 security holes this month alone, it’s also worth pointing out one that isn’t this month’s Patch Tuesday roundup: CVE-2026-85046. Google patched this bug in Chrome on September 3, and at the time warned that it “is aware that an exploit for CVE-2026-85046 exists in the wild.”
The high-severity, type confusion flaw exists in the V8 JavaScript engine used in both Google’s Chrome and Microsoft’s Edge browsers. And yet Microsoft still hasn’t published a security advisory for CVE-2026-85046.
“If you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether,” Adam Barnett, lead software engineer at Rapid7, told The Register .
“A patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward,” Barnett said. “Chrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it’s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.” ®
Microsoft breaks Patch Tuesday record with 974-CVE deluge
Adobe also brought goodies to the patch party and they deserve immediate attention
OpenAI GPT-6 Astra will run a retailer without cheating and sell more stuff than Anthropic
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
Google DeepMind rises above the AI scrum with genome atlas
See, AI can be used for good ... or at the very least, a useful distraction from the bad
OpenAI's rebel agent swarm died young, but its chilling logs live on
'The Collective' learned to communicate, organize, cheat, and apparently sacrifice its own
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
virtualization Broadcom pledges to lock down open source Python, Java libraries
Broadcom pledges to lock down open source Python, Java libraries
PERSONAL TECH Smartphone makers don't bother to comply with EU repairability requirements
Smartphone makers don't bother to comply with EU repairability requirements
SECURITY Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
virtualization VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade
VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade
OFF-PREM Google engineer unplugged every fiber they could see and – surprise! – took down a chunk of the G-Cloud
Google engineer unplugged every fiber they could see and – surprise! – took down a chunk of the G-Cloud
OS PLATFORM Windows 11 update sends some desktops into an unwanted goth phase
Windows 11 update sends some desktops into an unwanted goth phase
AI+ML Google DeepMind rises above the AI scrum with genome atlas See, AI can be used for good ... or at the very least, a useful distraction from the bad
Google DeepMind rises above the AI scrum with genome atlas
See, AI can be used for good ... or at the very least, a useful distraction from the bad
AI and ML Amazon ropes Qualcomm into something, something AI, networking chips Multi-generation chip collab is more buzzwords than compute
Amazon ropes Qualcomm into something, something AI, networking chips
Multi-generation chip collab is more buzzwords than compute
On-PREM AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk
AMD's Threadripper Halo is a local-AI workstation for researchers with deep pockets
AI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk
ai and ml Hugging Face is too important to fall into Nvidia's hands $12.9 billion deal will inevitably cement Nvidia's market dominance and harm competition in the process. Regulators should take note
Hugging Face is too important to fall into Nvidia's hands
$12.9 billion deal will inevitably cement Nvidia's market dominance and harm competition in the process. Regulators should take note
ai and ml Zuck's Muse to Spark joy with open weights release 'soon' While you wait, Meta says it’s taught the model to stop wasting tokens and ask for help a bit more often
Zuck's Muse to Spark joy with open weights release 'soon'
While you wait, Meta says it’s taught the model to stop wasting tokens and ask for help a bit more often
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast A real alternative to running some kind of FOSS Unix clone
Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
A real alternative to running some kind of FOSS Unix clone
Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15 Exeunt zVault stage right; enter FreeCORE and BSDnas
Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15
Exeunt zVault stage right; enter FreeCORE and BSDnas
Debian votes to let contributors code with AI Disclosure optional, quality mandatory
Debian votes to let contributors code with AI
Disclosure optional, quality mandatory
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
