Microsoft released fixes for 974 vulnerabilities in its September 2026 Patch Tuesday, the largest number ever shipped in a single monthly update. The figure included two zero-day flaws actively exploited in attacks. Security firms tallied similar counts: BleepingComputer reported 966, Zero Day Initiative 972, and Tenable 964.

The volume more than doubled August's 400 vulnerabilities and far exceeded July's previous record of 570. Microsoft's year-to-date total now stands at over 2,600 vulnerabilities—already surpassing the company's prior annual record of 1,245 in 2020 with three months remaining.

AI-assisted vulnerability discovery is driving the acceleration. Dustin Childs of ZDI, who in August suggested re-evaluating the definition of a "bug apocalypse," described the current environment as "deep into the new normal," noting that AI-assisted discovery shows no signs of slowing.

Microsoft rated 113 of its own CVEs as Critical, including 82 remote code execution flaws and 27 elevation-of-privilege vulnerabilities. The company also flagged 58 vulnerabilities as "More Likely" to be exploited. The patch republished 25 non-Microsoft CVEs, including Chromium fixes inherited by Edge.

CVE-2026-85880, a Windows Advanced Local Procedure Call elevation-of-privilege vulnerability, was among the two actively exploited zero-days. The heap-based buffer overflow—with a CVSS score of 7.8—allowed an authorized attacker to escalate to SYSTEM level. Threat intelligence firms Volexity and Proofpoint discovered it.

The second zero-day, CVE-2026-81963, also enabled privilege escalation on Windows systems and was located in the Windows Update Stack.

Adobe issued ten bulletins addressing 172 CVEs, including 107 in Experience Manager and 32 in Acrobat and Reader. One critical flaw, CVE-2026-75650—a CVSS 10.0 template-injection vulnerability in Adobe Commerce and Magento Open Source—was exploited in the wild since Sept. 4. Security researchers at Sansec attributed the attack, dubbed "StyleSmuggler," to the deployment of Rust backdoors and PHP web shells. Adobe released an emergency bulletin on Sept. 7, and the Cybersecurity and Infrastructure Security Agency imposed a three-day federal remediation deadline.

The frequency of actively exploited zero-days remained consistent: two in September, one in August, and two in July. Childs said enterprises must "embrace the suck" as high-volume critical patches become the standard.