Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

2026-09-08T20:52:16Z3c7b4b0bd34fa2eff7708a1034e8f7ae24d266f53bb193d269a9b6b08fd1f06e
CVE-2026-75650CVE-2026-81963CVE-2026-85880AI-assisted exploitationAdobe CommerceICSMagentoMicrosoft Patch TuesdayOT securitySiemens S7 PLCStyleSmuggleractive exploitationcritical infrastructureedge infrastructureexposure managementpost-quantum cryptographyremote code executionzero-day

What happened

Tenable reporting highlights three urgent vulnerability and threat developments: Microsoft’s September 2026 Patch Tuesday fixes 964 CVEs, including 104 critical issues and two zero-days exploited in the wild; the StyleSmuggler vulnerability (CVE-2026-75650) is a critical, unauthenticated remote-code-execution flaw in Adobe Commerce and Magento actively exploited before Adobe’s hotfix; and threat actors are targeting internet-exposed Siemens S7 PLCs, reportedly using AI-generated exploit scripts. Additional articles discuss edge-infrastructure exploitation convergence, post-quantum cryptography

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
3c7b4b0bd34fa2eff7708a1034e8f7ae24d266f53bb193d269a9b6b08fd1f06e
Enrichment time
2026-09-08T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.