ADOBE released a September 2026 patch set spanning 10 bulletins and 172 unique CVEs across products including Commerce, Campaign Classic, ColdFusion, Experience Manager, Photoshop, Illustrator, Animate and Acrobat/Reader. The standout is APSB26-146 for Adobe Commerce, a Critical CVSS 10.0 template-engine injection (CVE-2026-75650) which Adobe notes is being exploited in the wild.
Other Adobe bulletins carry high severities but are not publicly known to be under active attack at release, with Experience Manager IPOs and Acrobat/Reader among priorities. Deployment priority across the Adobe updates generally places Commerce, Campaign Classic and ColdFusion high, while Acrobat/Reader and Experience Manager also warrant prompt update.
Microsoft’s September 2026 release is described as record-breaking, with 972 new CVEs. The list covers Windows and components, Office, Azure, .NET, Visual Studio, Active Directory, Edge (Chromium-based), Exchange, SQL Server and more, totalling 997 when combined with the Adobe total. Of these, 114 are rated Critical; the remainder are Important.
Notable exploited items highlighted include CVE-2026-85880 (ALPC Elevation of Privilege) and CVE-2026-81963 (Update Stack Elevation of Privilege), both acknowledged as being exploited in the wild, alongside a broader set of wormable candidates (approximately 20 CVEs) such as CVE-2026-69510, CVE-2026-69524, CVE-2026-72981 and many others affecting DHCP, DNS, RRAS, SMB, and related services.
The article emphasises prioritising patches for critical, wormable, and exploited flaws, with particular attention to Exchange Server (notably CVE-2026-55007) and SharePoint-related Remote Code Execution risks.
Evidence and response implied include rapid patching from Microsoft and Adobe, with explicit callouts to the active exploits for the two Microsoft vulnerabilities and the in-the-wild CVE for Adobe Commerce. Organisations are advised to test and deploy updates promptly, especially where internet-facing Exchange or large on-premises SharePoint deployments are involved.