AuraTracer智迹闻
中文

EVENT DOSSIER

Microsoft released a record number of 974 security patches, including two vulnerabilities that have been exploited.

2026-09-09 08:25 Cybersecurity 🔥 44.2 heat score
1sources
1days unfolding
44.2heat score
5mentions
SummaryAI generated

In September 2026, Microsoft released 974 security patches, hitting a record high, including two zero-day vulnerabilities that had been exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed these two vulnerabilities in its known exploitable vulnerabilities list and set deadlines for federal agencies to fix them. One of the vulnerabilities (CVE-2026-85880) was located in the Windows ALPC component, allowing privilege escalation to the SYSTEM level without user interaction; another vulnerability (CVE-2026-81963) affected the Windows Update Stack, also providing system-level access. Additionally, the CVE-2026-55007 vulnerability in Exchange Server allowed attackers to remotely execute code through malicious Visio attachments. In the same month, Adobe released 172 CVE announcements, covering security updates related to Magento and Adobe Commerce systems that had been exploited as zero-day vulnerabilities.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
AdobeMicrosoftSansecTenableUS Cybersecurity and Infrastructure Security Agency

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Adobe × Microsoft1Adobe × Sansec1Adobe × Tenable1Adobe × US Cybersecurit…1Microsoft × Sansec1Microsoft × Tenable1

SignalsSIGNALS

Keyword heat
  • Microsoft1
  • Adobe1
  • Sansec1
  • Tenable1
  • US Cybersecurity and Infrastructure Security Agency1

All reports (1)SOURCES

T The Register en 2026-09-09 08:25

Microsoft breaks Patch Tuesday record with 974-CVE deluge

微软本月发布 974 个安全补丁,创历史新高,其中包含两个已被利用的零日漏洞。Adobe 同日发布 172 个 CVE 公告,涵盖已作为零日漏洞被滥用的 Magento 和 Adobe Commerce 系统。美国网络安全与基础设施安全局已将微软的两个漏洞及 Adobe 漏洞列入已知利用漏洞目录,并设定了联邦机构修复期限。其中,CVE-2026-85880 是 Windows ALPC 中的提权漏洞,无需用户交互即可导致 SYSTEM 权限提升;另一漏洞 CVE-2026-81963 影响 Windows Update Stack,同样允许获取系统级访问权限。此外,Exchange Server 的 CVE-2026-55007 漏洞允许攻击者通过恶意 Visio 附件远程执行代码,Zero Day Init…