{
  "id": 6367556,
  "title": "Microsoft breaks Patch Tuesday record with 974-CVE deluge",
  "url": "https://urgent.news/2026/09/09/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-09T00:25:22.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/09/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge/5295160"
  },
  "original_language": "en",
  "account": "Microsoft set a startling record in September with 974 CVE (Common Vulnerabilities and Exposures) patches, more than doubling its previous monthly record. This surge comes amid reports that two of these vulnerabilities are already being exploited in the wild. The record-breaking patch drop follows a series of monthly increases, with August seeing 421 patches and July delivering 622. Meanwhile, Adobe issued 10 bulletins for 172 CVEs, including a critical zero-day vulnerability known as StyleSmuggler that is already being actively exploited. The flaw allows attackers to execute remote code on Magento and Adobe Commerce platforms, posing a significant risk to online businesses and necessitating immediate action. Furthermore, Microsoft's record includes two high-severity bugs, CVE-2026-85880 and CVE-2026-81963, both of which grant attackers SYSTEM-level access. These vulnerabilities, along with nine other Exchange Server flaws, are particularly concerning as they can be triggered remotely without user interaction. Despite addressing nearly 1,000 security issues, Microsoft has notably omitted a patch for the Google Chrome vulnerability CVE-2026-85046, which is already known to be in use despite the company's lack of official acknowledgment of its exploitation.",
  "summary": "Adobe also brought goodies to the patch party and they deserve immediate attention",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 4,
    "also_reported_by": [
      {
        "outlet": "Ars Technica",
        "title": "Why this month's Microsoft patch release is a doozy",
        "url": "https://urgent.news/2026/09/08/why-this-months-microsoft-patch-release-is-a-doozy",
        "published": "2026-09-08T21:11:46.000Z"
      },
      {
        "outlet": "The Record",
        "title": "Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited",
        "url": "https://urgent.news/2026/09/08/microsoft-posts-nearly-1-000-bugs-for-patch-tuesday-as-cisa-warns-two",
        "published": "2026-09-08T22:40:00.000Z"
      },
      {
        "outlet": "The Register Science",
        "title": "Microsoft breaks Patch Tuesday record with 974-CVE deluge",
        "url": "https://urgent.news/2026/09/09/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge-6370973",
        "published": "2026-09-09T00:25:22.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}