Microsoft breaks Patch Tuesday record with 974-CVE deluge
Adobe also brought goodies to the patch party and they deserve immediate attention
Microsoft set a startling record in September with 974 CVE (Common Vulnerabilities and Exposures) patches, more than doubling its previous monthly record. This surge comes amid reports that two of these vulnerabilities are already being exploited in the wild. The record-breaking patch drop follows a series of monthly increases, with August seeing 421 patches and July delivering 622.
Meanwhile, Adobe issued 10 bulletins for 172 CVEs, including a critical zero-day vulnerability known as StyleSmuggler that is already being actively exploited. The flaw allows attackers to execute remote code on Magento and Adobe Commerce platforms, posing a significant risk to online businesses and necessitating immediate action.
Furthermore, Microsoft's record includes two high-severity bugs, CVE-2026-85880 and CVE-2026-81963, both of which grant attackers SYSTEM-level access. These vulnerabilities, along with nine other Exchange Server flaws, are particularly concerning as they can be triggered remotely without user interaction. Despite addressing nearly 1,000 security issues, Microsoft has notably omitted a patch for the Google Chrome vulnerability CVE-2026-85046, which is already known to be in use despite the company's lack of official acknowledgment of its exploitation.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 3 other outlets
- Microsoft breaks Patch Tuesday record with 974-CVE deluge theregister.com
- Why this month's Microsoft patch release is a doozy arstechnica.com
- Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited therecord.media