CVE Tools

Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

Qualys Security BlogBy Diksha Ojha25 min read

Reported exploitedMicrosoft Exchange ServerQualysWindows Update Stack

Our summary

Qualys reports that Microsoft has issued its largest Patch Tuesday update to date, remediating 974 security vulnerabilities across its product ecosystem. Among these fixes are two zero-days currently under active exploitation: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC), both enabling local privilege escalation. Additionally, Adobe released a patch for critical vulnerability CVE-2026-75650 in Adobe Commerce, which allows arbitrary code execution and has been added to CISA's Known Exploited Vulnerabilities Catalog.

Read at Qualys Security Blog

Below is the opening; the full story is at Qualys Security Blog.

From Qualys Security Blog

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. 

This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August.…

Continue at Qualys Security Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store