Microsoft released a record number of 974 security patches, including two vulnerabilities that have been exploited.
2026-09-09 08:25Cybersecurity🔥 44.2 heat score
1sources
1days unfolding
44.2heat score
5mentions
SummaryAI generated
In September 2026, Microsoft released 974 security patches, hitting a record high, including two zero-day vulnerabilities that had been exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed these two vulnerabilities in its known exploitable vulnerabilities list and set deadlines for federal agencies to fix them. One of the vulnerabilities (CVE-2026-85880) was located in the Windows ALPC component, allowing privilege escalation to the SYSTEM level without user interaction; another vulnerability (CVE-2026-81963) affected the Windows Update Stack, also providing system-level access. Additionally, the CVE-2026-55007 vulnerability in Exchange Server allowed attackers to remotely execute code through malicious Visio attachments. In the same month, Adobe released 172 CVE announcements, covering security updates related to Magento and Adobe Commerce systems that had been exploited as zero-day vulnerabilities.