www.zerodayinitiative.com
September 2026 Security Update: Major CVEs from Adobe and Microsoft
Article Content
On September 8, 2026, Microsoft released a record 972 new CVEs, while Adobe issued 10 bulletins addressing 172 unique CVEs. Notably, Adobe's CVE-2026-75650, a critical template-engine injection vulnerability with a CVSS score of 10.0, is actively exploited in the wild. This vulnerability affects Adobe Commerce and was reported as being exploited just before the patch release. Microsoft’s updates cover a wide range of products, including Windows, Office, and Azure, with 114 CVEs rated as Critical. The overall CVE count for Microsoft this month totals 997. The majority of Adobe's vulnerabilities are not publicly known or under active attack at the time of release. Security professionals are urged to prioritize patching the critical vulnerabilities, especially those under active exploitation.
Key Points: • Microsoft released 972 new CVEs, totaling 997 for September 2026. • Adobe's CVE-2026-75650 is a critical vulnerability under active exploitation. • Security professionals should prioritize patching critical vulnerabilities immediately.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.