Microsoft Patch Tuesday Hits Record 974 CVEs as Adobe Drops Zero-Day Fix

A staggering vulnerability deluge hits enterprise security teams as Microsoft issues 974 fixes and Adobe patches an active Magento zero-day.

Security operations center dashboard showing vulnerability analytics and patch management metrics during a high-alert cycle.
Security operations center dashboard showing vulnerability analytics and patch management metrics during a high-alert cycle.

Microsoft issues a record 974 CVE patches in a single month while Adobe scrambles to fix an actively exploited zero-day flaw in Magento and Adobe Commerce.

Key takeaways
  • Microsoft issued security updates for 974 distinct CVEs in a single month, setting a new record.
  • The massive Microsoft patch drop followed 421 fixes in August and 622 fixes in July.
  • Adobe released emergency fixes for 172 CVEs, including an actively exploited zero-day in Magento.
  • The Magento zero-day, tracked as CVE-2026-75650 and named StyleSmuggler, allows unauthenticated remote code execution.
  • E-commerce security firm Sansec discovered that StyleSmuggler attacks against Magento began on September 4.
In short

Microsoft issued a record 974 CVE patches in a single month during its September update cycle, significantly eclipsing previous vulnerability totals and putting immense pressure on enterprise IT and security teams worldwide.

Enterprise security teams face an unprecedented workload after Microsoft issued a staggering 974 Common Vulnerabilities and Exposures patches in a single update cycle, shattering previous monthly records. This historic software update volume follows a steady climb in reported flaws, compounding operational pressures on IT departments tasked with maintaining infrastructure defense. Alongside Microsoft's massive security drop, Adobe released urgent fixes for an actively exploited zero-day vulnerability affecting global e-commerce platforms. The simultaneous influx of high-volume updates highlights a broader industry crisis in software assurance and vulnerability management.

Why Did Microsoft Issue 974 CVEs This Month?

Microsoft released updates for 974 CVEs in its proprietary products during the September Patch Tuesday release cycle, eclipsing the 421 patches issued in August and 622 in July according to The Register. This unprecedented volume includes at least two critical vulnerabilities that Redmond confirmed are already actively exploited in the wild. Industry analysts attribute the dramatic surge in tracked bugs to a combination of more aggressive automated code analysis, complex dependency chains in modern operating systems, and shifting internal development pipelines. For enterprise administrators, the sheer volume transforms routine maintenance windows into grueling triage exercises, forcing teams to automate deployment without sacrificing system stability.

  • Microsoft deployed patches addressing 974 distinct CVEs in its September update cycle.
  • The massive drop follows 421 security fixes in August and 622 patches issued in July.
  • Two Microsoft vulnerabilities included in the September batch are already under active exploitation.
  • Adobe issued 10 bulletins covering 172 CVEs, including a critical zero-day in Magento and Adobe Commerce.

How Is Adobe Responding to the Magento Zero-Day?

Adobe rushed emergency hotfixes to address an actively exploited zero-day vulnerability tracked as CVE-2026-75650, which security researchers named StyleSmuggler. Discovered by e-commerce security firm Sansec, the flaw allows unauthenticated remote attackers to execute arbitrary code by injecting malicious PHP payloads into Magento templates via style properties. Active exploitation began on September 4, targeting online shops running vulnerable versions of Magento and Adobe Commerce from 2.4.4 up to 2.4.9. Attackers leverage the flaw to install persistent backdoors connecting directly to external command-and-control infrastructure, making immediate patching the single highest priority for digital merchants.

"If your organization has any type of online shop, prioritize this one first as it’s already being abused to compromise stores."

What to watch next

Security teams should monitor three critical operational indicators over the coming weeks as organizations process these record-breaking updates. First, track how quickly enterprise automation tools successfully deploy the 974 Microsoft patches without triggering widespread blue screens or application regressions. Second, watch for secondary indicators of compromise on e-commerce servers running Magento and Adobe Commerce, specifically looking for unauthorized backend connections linked to the StyleSmuggler exploit. Third, observe whether upstream software vendors adjust their QA timelines to prevent future vulnerability pileups that overwhelm corporate security bandwidth.

Frequently asked

How many CVEs did Microsoft patch in September?

Microsoft issued security updates addressing a record 974 CVEs across its products during the September Patch Tuesday cycle, following 421 fixes in August and 622 in July.

What is the StyleSmuggler vulnerability in Adobe Commerce?

Tracked as CVE-2026-75650, StyleSmuggler is a max-severity zero-day flaw in Magento and Adobe Commerce that allows unauthenticated attackers to achieve remote code execution via template injections.

Which versions of Magento and Adobe Commerce are affected by CVE-2026-75650?

Every version of Magento and Adobe Commerce from version 2.4.4 up to and including version 2.4.9 is affected by the StyleSmuggler vulnerability and requires immediate patching.

Who discovered the Magento zero-day exploit?

The Magento zero-day vulnerability known as StyleSmuggler was discovered by e-commerce security firm Sansec, which reported that attacks began on September 4.

This article answers
  • microsoft patch tuesday record
  • 974 cve microsoft update
  • adobe commerce zero day cve-2026-75650
  • stylesmuggler magento vulnerability
  • sansec magento hack september
  • how many cves did microsoft patch in september
  • what is the stylesmuggler vulnerability in adobe
  • which magento versions are affected by cve-2026-75650
  • microsoft patch tuesday september 2026
Topics
P
Patrick
Senior Technology Correspondent

Patrick covers AI infrastructure, model releases and enterprise automation. He has spent more than a decade reporting on how engineering decisions inside large platforms end up reshaping the software everyone else has to build on.

AI model launchesEnterprise automationCloud infrastructureDeveloper tooling