Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extended break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for September 2026For the first part of the August release, Adobe released 10 bulletins addressing 172 unique CVEs in Adobe ColdFusion, Acrobat Reader, Commerce (two bulletins), Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate, and Adobe Photoshop Mobile. A total of 22 of these were submitted through the ZDI program.Here’s this month’s overview table: Adobe Patches for September 2026 Adobe Patches for September 2026 Bulletin ID Product CVE Count Highest Severity Highest CVSS Exploited Deployment Priority APSB26-146 Adobe Commerce 1 Critical 10.0 Yes 1 APSB26-142 Adobe Campaign Classic 1 Critical 10.0 No 1 APSB26-119 Adobe ColdFusion 9 Critical 9.9 No 1 APSB26-98 Adobe Experience Manager 107 Critical 9.9 No 2 APSB26-138 Adobe Commerce 8 Critical 9.3 No 2 APSB26-141 Adobe Acrobat and Reader 32 Critical 8.8 No 2 APSB26-130 Adobe Photoshop 8 Critical 8.6 No 3 APSB26-131 Adobe Illustrator 3 Critical 8.6 No 3 APSB26-132 Adobe Animate 1 Critical 8.2 No 3 APSB26-136 Adobe Photoshop Mobile 2 Important 7.4 No 3 TOTAL 10 bulletins 172 APSB26-146 (Adobe Commerce) is an out-of-band advisory posted September 7, 2026 addressing CVE-2026-75650, a CVSS 10.0 template-engine injection that Adobe reports is being exploited in the wild. All other bulletins were released on Patch Tuesday, September 8, 2026. No public proof-of-concept is noted for any bulletin. Clearly, the priority here is the Commerce bug currently under active attack. Campaign Classic and ColdFusion also clock in with a deployment priority of 1. The Acrobat Reader should also be a priority. It contains 32 CVEs, including many code execution bugs, and PDFs are a favorite of attackers. The Experience Manager has plenty of CVEs being patched and also rates a deployment priority of 2.Besides the one bug in Commerce, none of the other Adobe bugs receiving patches this month are listed as publicly known or under active attack at the time of release.Microsoft Patches for September 2026It’s a new record release from Microsoft, but, again, that seems to be the new normal. As always, counting this beast is tricky, but I see 972 new CVEs rolling out from Redmond this month. As with last month, only a single CVE is listed as being under active attack, so that’s something, I suppose. As for the products affected by this release, we have Windows and Windows components, Office and Office Components, Azure and Azure Components, .NET and Visual Studio, Active Directory, Copilot Studio, Dynamics, Edge (Chromium-based), DHCP Server and Client, DNS Server, Exchange Server, Teams for Android, OpenSSH, Remote Desktop Client and Server, Skype for Business, Biometric Service, SQL Server, Windows Hello, Xbox, and Defender. Along with the external and Chromium bugs being documented this month, this drives the total CVE count to a staggering 997. Of these new CVEs, 114 are rated Critical, with the rest being rated Important.To provide a little historical context on how many CVEs have been patched by Microsoft this year, let’s take a look at some year-over-year totals: On the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate. On the other hand, AI-assisted vulnerability discovery shows no signs of slowing down. However, we have not seen a correlating spike in active exploits – yet. As always, we’ll start with the bugs under active attack and move on from there. - CVE-2026-81963 - Windows Update Stack Elevation of Privilege VulnerabilityThis is the first bug being exploited in the wild, but we know little about how broadly that exploitation is. The bug itself is a privilege escalation in the Update Stack, which is worrisome, but I doubt the automatic update process itself is compromised. More likely is that this bug is being combined with a code execution bug to spread malware or ransomware. Patch this one quickly.- CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityThis is the other bug currently being exploited, and it is also a privilege escalation bug. These types of bugs must be triggered by the user, but they can hide within documents, PDFs, and other attachments. As with the Update Stack EoP, we don’t know how widespread these exploits may be, so assume they are coming for you and patch quickly.- &nbs
The September 2026 Security Update Review
Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extended break from your regularly scheduled activities as we take a look at t
Source: Zero Day Initiative