Microsoft breaks Patch Tuesday record with 974-CVE deluge

Microsoft and Adobe have released a massive volume of security patches, including fixes for critical vulnerabilities already being exploited in the wild. Organizations are urged to prioritize updates for Adobe Commerce and Windows systems to prevent remote code execution and privilege escalation.
Why it matters
The record-breaking number of vulnerabilities highlights a growing cybersecurity crisis that threatens enterprise data integrity and operational security.
Adobe also brought goodies to the patch party and they deserve immediate attention
The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation.
September's record-breaking collection of security updates come after Microsoft served up 421 fixes in August , and 622 in July . We've seen the new normal and we are not impressed. Thanks, but no thanks, AI.
In addition to Microsoft’s massive patch drop, Adobe on Tuesday issued 10 bulletins addressing 172 CVEs , including a max-severity vulnerability exploited as a zero day in Magento and its successor product Adobe Commerce. Adobe on Monday shipped a hotfix for this one, tracked as CVE-2026-75650 and named StyleSmuggler, that gives unauthenticated attackers remote code execution.
Also covering this story
3 other newsrooms covered this event. We read each version separately.
Microsoft breaks another patch Tuesday record
Microsoft Releases Record September Patch Tuesday Fixing 900+ Flaws Including Two Exploited Zero-Days
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in