Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

2026-09-09T07:23:59Zde45e22ac092f3c0bbb34b38f21bf97449fb16e0386faad0957065a9de5cbdf7
CVE-2026-59346CVE-2026-75650CVE-2026-86218AI securityAdobe CommerceCISA KEVMagentoMicrosoft WindowsN-able N-centralPatch Tuesdayactively exploited vulnerabilitiesadversary-in-the-middlebrowser backdoorcloud securitycredential theftdata exfiltrationmalwarephishingransomware/extortionremote code executionrouter compromisesupply-chain securityunauthenticated RCEvishingzero-day

What happened

The document aggregates major cybersecurity news from September 2026, including actively exploited zero-days, unauthenticated remote-code-execution flaws, malware campaigns, credential theft, supply-chain compromises, cloud and SaaS attacks, router hijacking, and privacy incidents. The highest-risk items include Microsoft’s two exploited Windows zero-days, Adobe Commerce/Magento CVE-2026-75650, N-able N-central CVE-2026-86218 with a CVSS score of 10.0 and CISA KEV listing, and VMware Workstation/Fusion CVE-2026-59346 with a CVSS score of 9.3.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
de45e22ac092f3c0bbb34b38f21bf97449fb16e0386faad0957065a9de5cbdf7
Enrichment time
2026-09-09T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days · Baitaphish