Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
2026-09-09T07:23:59Z•de45e22ac092f3c0bbb34b38f21bf97449fb16e0386faad0957065a9de5cbdf7
CVE-2026-59346CVE-2026-75650CVE-2026-86218AI securityAdobe CommerceCISA KEVMagentoMicrosoft WindowsN-able N-centralPatch Tuesdayactively exploited vulnerabilitiesadversary-in-the-middlebrowser backdoorcloud securitycredential theftdata exfiltrationmalwarephishingransomware/extortionremote code executionrouter compromisesupply-chain securityunauthenticated RCEvishingzero-day
What happened
The document aggregates major cybersecurity news from September 2026, including actively exploited zero-days, unauthenticated remote-code-execution flaws, malware campaigns, credential theft, supply-chain compromises, cloud and SaaS attacks, router hijacking, and privacy incidents. The highest-risk items include Microsoft’s two exploited Windows zero-days, Adobe Commerce/Magento CVE-2026-75650, N-able N-central CVE-2026-86218 with a CVSS score of 10.0 and CISA KEV listing, and VMware Workstation/Fusion CVE-2026-59346 with a CVSS score of 9.3.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- de45e22ac092f3c0bbb34b38f21bf97449fb16e0386faad0957065a9de5cbdf7
- Enrichment time
- 2026-09-09T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.