Microsoft Patch Tuesday has delivered a record 974 security fixes, including two Windows privilege escalation zero-days already under attack. The 8 September 2026 release also contains nine Exchange Server fixes, while Adobe has separately patched an actively exploited flaw in Adobe Commerce and Magento.
Microsoft Patch Tuesday reaches 974 CVEs
Microsoft’s September security release addresses 974 CVEs across its products. This is a substantial increase from the 421 fixes issued in August and 622 in July, making it the company’s largest Patch Tuesday collection reported to date.
According to Tenable, the September total alone is not far below the 1,130 CVEs that Microsoft addressed during all of 2025. The scale of the release means organisations will need to assess affected assets carefully rather than treating every update as having the same urgency.
Two vulnerabilities stand out because Microsoft says they are already being exploited. Both allow attackers to elevate their privileges to SYSTEM, the highest level of control on a Windows device.
CVE-2026-85880 affects Windows ALPC
CVE-2026-85880 is a privilege escalation vulnerability in Windows Advanced Local Procedure Call, commonly shortened to ALPC. This Windows mechanism allows processes running on the same computer to communicate with each other.
An attacker who can already execute code inside a low-privilege AppContainer could exploit the flaw locally. A successful attack would escape the security sandbox and give the attacker SYSTEM privileges, without requiring any additional interaction from the user.
This is not described as an initial access vulnerability. An attacker would first need a way to run code on the target, potentially through another vulnerability or a malicious file. CVE-2026-85880 could then provide the elevated access needed to disable protections, access sensitive information or establish deeper control.
Microsoft has not disclosed who is exploiting the vulnerability, how widespread the attacks are or what the attackers are trying to achieve. However, confirmed exploitation makes this one of the most urgent fixes in the Microsoft Patch Tuesday release.
CVE-2026-81963 targets the Windows Update Stack
The second exploited Microsoft zero-day is CVE-2026-81963, another privilege escalation flaw. It affects the Windows Update Stack and can also allow an attacker to obtain SYSTEM-level access.
Few technical details about this vulnerability have been made public. Zero Day Initiative researcher Dustin Childs suggested that attackers are likely to combine it with a separate code execution flaw, potentially to deploy malware or ransomware after compromising a system.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-81963 and CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog on 8 September. US federal agencies have been given until 22 September 2026 to apply the relevant Microsoft fixes.
Microsoft Patch Tuesday includes Exchange risk
The record Microsoft Patch Tuesday release also addresses nine vulnerabilities in Exchange Server. Of these, CVE-2026-55007 has been identified by Childs as the most important Exchange patch in the September collection.
CVE-2026-55007 can allow a remote, unauthenticated attacker to execute code on a vulnerable Exchange server. The attack begins when the threat actor sends an email containing a specially crafted malicious Visio attachment.
No recipient needs to open the message or attachment. Instead, the vulnerable server processes the file automatically during content indexing, which creates the opportunity for the attacker’s code to execute.
Microsoft has assessed exploitation as difficult to trigger reliably. However, an attacker can repeat delivery attempts and only needs the exploit to work once. The absence of user interaction also makes the vulnerability more significant for organisations operating affected Exchange infrastructure.
The report does not identify which Exchange Server versions are affected. Administrators should therefore review Microsoft’s September advisory and their installed Exchange build before deciding whether a server falls outside the vulnerable range. There was no reported evidence of active exploitation of CVE-2026-55007 at publication time.
Adobe Commerce zero-day exploited since 4 September
The Microsoft Patch Tuesday release coincided with a substantial Adobe update. On 8 September, Adobe issued 10 security bulletins addressing 172 CVEs, including a maximum-severity remote code execution vulnerability in Adobe Commerce and its predecessor, Magento.
The vulnerability is tracked as CVE-2026-75650 and has been named StyleSmuggler. Adobe issued a hotfix on 7 September, after ecommerce security company Sansec observed attacks beginning on 4 September.
StyleSmuggler affects every Adobe Commerce and Magento release from version 2.4.4 up to and including version 2.4.9. It allows an unauthenticated attacker to inject malicious PHP code into Magento templates through their styles properties.
This technique enables the injected code to evade safety checks. In confirmed attacks, the malicious payload installed a backdoor that connected to a command and control server, then waited to receive further instructions.
Sansec said it had not seen evidence that the backdoor had been weaponised further at the time of reporting. Nevertheless, stores may already have been compromised, and applying the hotfix will not by itself remove malicious code or backdoors installed before remediation.
CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities Catalog on 8 September. The agency set an earlier remediation deadline of 11 September 2026 for US federal bodies, reflecting the vulnerability’s active exploitation and unauthenticated remote code execution impact.
Why these actively exploited flaws matter
The two Windows vulnerabilities turn limited access into complete local control, making them useful components in multi-stage attacks. CVE-2026-55007 presents a different concern because a malicious email attachment can be processed by Exchange without a recipient opening it.
StyleSmuggler poses the clearest immediate internet-facing risk. Vulnerable online shops can be attacked without authentication, and real intrusions began before Adobe released its hotfix.
What organisations should prioritise
-
Deploy the Microsoft Patch Tuesday fixes for CVE-2026-85880 and CVE-2026-81963 quickly, prioritising exposed and high-value Windows systems.
-
Review Exchange Server deployments against Microsoft’s September advisory and schedule the CVE-2026-55007 update promptly.
-
Apply Adobe’s CVE-2026-75650 hotfix urgently to Adobe Commerce or Magento versions 2.4.4 through 2.4.9.
-
Investigate vulnerable ecommerce servers for unexpected PHP template changes, backdoors and command and control connections dating from 4 September 2026.
-
Confirm that updates have installed successfully, rather than relying solely on automated deployment reports.
Originally reported by theregister.com.





