Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
2026-09-08T20:52:16Z•3c7b4b0bd34fa2eff7708a1034e8f7ae24d266f53bb193d269a9b6b08fd1f06e
CVE-2026-75650CVE-2026-81963CVE-2026-85880AI-assisted exploitationAdobe CommerceICSMagentoMicrosoft Patch TuesdayOT securitySiemens S7 PLCStyleSmuggleractive exploitationcritical infrastructureedge infrastructureexposure managementpost-quantum cryptographyremote code executionzero-day
What happened
Tenable reporting highlights three urgent vulnerability and threat developments: Microsoft’s September 2026 Patch Tuesday fixes 964 CVEs, including 104 critical issues and two zero-days exploited in the wild; the StyleSmuggler vulnerability (CVE-2026-75650) is a critical, unauthenticated remote-code-execution flaw in Adobe Commerce and Magento actively exploited before Adobe’s hotfix; and threat actors are targeting internet-exposed Siemens S7 PLCs, reportedly using AI-generated exploit scripts. Additional articles discuss edge-infrastructure exploitation convergence, post-quantum cryptography
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 3c7b4b0bd34fa2eff7708a1034e8f7ae24d266f53bb193d269a9b6b08fd1f06e
- Enrichment time
- 2026-09-08T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.