{"id":61352,"date":"2026-09-09T00:25:22","date_gmt":"2026-09-09T00:25:22","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5295160"},"modified":"2026-09-09T00:25:22","modified_gmt":"2026-09-09T00:25:22","slug":"microsoft-breaks-patch-tuesday-record-with-974-cve-deluge","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/","title":{"rendered":"Microsoft breaks Patch Tuesday record with 974-CVE deluge"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"31.182203389831\">\n<p class=\"kicker \">security<\/p>\n<p class=\"subtitle \">Adobe also brought goodies to the patch party and they deserve immediate attention<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"144.35757680958\"> <!-- placeholder(#1) --> <\/p>\n<p>The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation.<\/p>\n<p>September&#8217;s <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Sep\" target=\"_blank\" rel=\"nofollow\">record-breaking collection of security updates<\/a>&nbsp;come after Microsoft served up <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/11\/421-bugs-in-microsofts-patch-tuesday-release-and-the-norks-have-already-attacked-one\/5286483\" target=\"_blank\">421 fixes in August<\/a>, and <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/14\/patchpocalypse-now-microsoft-tops-last-months-record-with-622-patch-tuesday-cves\/5271434\" target=\"_blank\">622 in July<\/a>. We&#8217;ve <a href=\"https:\/\/www.theregister.com\/patches\/2026\/05\/14\/welcome-to-the-vulnpocalypse-as-vendors-use-ai-to-find-bugs-and-patches-multiply-like-rabbits\/5240027\" target=\"_blank\">seen the new normal<\/a> and we are not impressed. Thanks, but no thanks, AI.&nbsp;<\/p>\n<p>In addition to Microsoft\u2019s massive patch drop,&nbsp;Adobe on Tuesday issued 10 bulletins <a href=\"https:\/\/helpx.adobe.com\/security.html\" target=\"_blank\" rel=\"nofollow\">addressing 172 CVEs<\/a>, including a max-severity vulnerability exploited as a zero day in Magento and its successor product Adobe Commerce. Adobe on Monday <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-146.html\" target=\"_blank\" rel=\"nofollow\">shipped a hotfix<\/a> for this one, tracked as CVE-2026-75650 and named StyleSmuggler, that gives unauthenticated attackers remote code execution.&nbsp;<\/p>\n<h3>StyleSmuggler<\/h3>\n<p>If your organization has any type of online shop, prioritize this one first as it\u2019s already being abused to compromise stores, according to e-commerce security shop Sansec.<\/p>\n<p>Sansec <a href=\"https:\/\/sansec.io\/research\/stylesmuggler-0day#adobe-patch%3A-cve-2026-75650\" rel=\"nofollow\">discovered StyleSmuggler<\/a>, and reports that attacks started on September 4. Every version of Magento and Adobe Commerce, from 2.4.4 up to and including 2.4.9, has the flaw.&nbsp;<\/p>\n<p>The bug allows attackers to inject malicious PHP code inside Magento templates using the \u201cstyles\u201d properties to evade safety detections. In confirmed attacks, the payload then installs a backdoor that connects to a command-and-control server and waits for instructions. \u201cSo far, we have no indication that the backdoor has been weaponized,\u201d the Sansec Forensics Team wrote.<\/p>\n<p>Don\u2019t wait to find out on this one. Put it at the top of your mitigation list.<\/p>\n<h3>Microsoft&#8217;s 974 CVEs<\/h3>\n<p>On to Microsoft\u2019s <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Sep\" target=\"_blank\" rel=\"nofollow\">record-breaking 974 CVEs<\/a>, which according to Tenable is not many fewer than the <a href=\"https:\/\/www.tenable.com\/blog\/microsoft-patch-tuesday-2025-year-in-review\" target=\"_blank\" rel=\"nofollow\">1,130 CVEs Redmond issued in 2025<\/a>.<\/p>\n<p>Two are already&nbsp;being&nbsp;exploited as zero-days.<\/p>\n<p>First up: <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-85880\" target=\"_blank\" rel=\"nofollow\">CVE-2026-85880<\/a>, a privilege escalation bug in Windows Advanced Local Procedure Call (ALPC). Successful exploitation can result in the attacker gaining SYSTEM privileges.<\/p>\n<p>\u201cAn attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system,\u201d Redmond warned. \u201cNo additional user interaction is required.\u201d<\/p>\n<p>No word yet on who is exploiting this bug, and to what end. The US Cybersecurity and Infrastructure Security Agency on Tuesday added CVE-2026-85880 plus a second Microsoft security hole (and the Adobe Commerce and Magento zero-day) to its <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/08\/cisa-adds-four-known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"nofollow\">Known Exploited Vulnerabilities Catalog<\/a>, and set a September 22 deadline for federal agencies to fix both new Microsoft bugs and a September 11 deadline to patch the Adobe flaw.<\/p>\n<p>The second Microsoft bug found and exploited as a zero-day is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-81963\" target=\"_blank\" rel=\"nofollow\">CVE-2026-81963<\/a>, another privilege escalation vulnerability. This one affects the Windows Update Stack. We also have very little detail about this flaw, other than it also allows attackers to gain SYSTEM-level access.<\/p>\n<p>\u201cMore likely is that this bug is being combined with a code execution bug to spread malware or ransomware,\u201d <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2026\/9\/8\/the-september-2026-security-update-review\" target=\"_blank\" rel=\"nofollow\">opined<\/a> Zero Day Initiative\u2019s Dustin Childs, who advised users to \u201cPatch this one quickly.\u201d<\/p>\n<p>While those are the only two (so far) under active exploitation, Childs rated&nbsp;<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-55007\" target=\"_blank\" rel=\"nofollow\">CVE-2026-55007<\/a>, one of nine Exchange Server flaws disclosed this month, as \u201cthe most important\u201d patch for the messaging server.&nbsp;<\/p>\n<p>It allows a remote, unauthenticated attacker to execute code on a vulnerable Exchange server by sending an email with a malicious Visio attachment. No user interaction is required, and the code executes when the server processes the attachment during content indexing.<\/p>\n<p>Redmond says it\u2019s \u201cdifficult to reliably trigger,\u201d but as Childs points out: \u201cThe attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.\u201d<\/p>\n<p>Childs also said he counts 20 patches for wormable bugs, so be sure to read his full Patch Tuesday review for those. \u201cWhile some might be more exploitable than others, having 20 of them in a single release is something else.\u201d<\/p>\n<h3>The missing CVE<\/h3>\n<p>While Redmond addressed nearly 1,000 security holes this month alone, it\u2019s also worth pointing out one that isn\u2019t this month\u2019s Patch Tuesday roundup: CVE-2026-85046. <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/09\/stable-channel-update-for-desktop_01882797386.html\" target=\"_blank\" rel=\"nofollow\">Google patched<\/a> this bug in Chrome on September 3, and at the time warned that it \u201cis aware that an exploit for CVE-2026-85046 exists in the wild.\u201d<\/p>\n<p>The high-severity, type confusion flaw exists in the V8 JavaScript engine used in both Google\u2019s Chrome and Microsoft\u2019s Edge browsers. And yet Microsoft still hasn\u2019t published a security advisory for CVE-2026-85046.<\/p>\n<p>\u201cIf you\u2019re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether,\u201d Adam Barnett, lead software engineer at Rapid7, told <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span>.<\/p>\n<p>\u201cA patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward,\u201d Barnett said. \u201cChrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it\u2019s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.\u201d \u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5295166&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/09\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/5295160\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Adobe also brought goodies to the patch party and they deserve immediate attention READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[307],"class_list":["post-61352","post","type-post","status-publish","format-standard","hentry","category-the-register","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft breaks Patch Tuesday record with 974-CVE deluge 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft breaks Patch Tuesday record with 974-CVE deluge 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T00:25:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Microsoft breaks Patch Tuesday record with 974-CVE deluge\",\"datePublished\":\"2026-09-09T00:25:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/\"},\"wordCount\":863,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"keywords\":[\"Security\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/\",\"name\":\"Microsoft breaks Patch Tuesday record with 974-CVE deluge 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/image.theregister.com\\\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"datePublished\":\"2026-09-09T00:25:22+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#primaryimage\",\"url\":\"https:\\\/\\\/image.theregister.com\\\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\",\"contentUrl\":\"https:\\\/\\\/image.theregister.com\\\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Microsoft breaks Patch Tuesday record with 974-CVE deluge\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft breaks Patch Tuesday record with 974-CVE deluge 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft breaks Patch Tuesday record with 974-CVE deluge 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-09-09T00:25:22+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Microsoft breaks Patch Tuesday record with 974-CVE deluge","datePublished":"2026-09-09T00:25:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/"},"wordCount":863,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","keywords":["Security"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/","url":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/","name":"Microsoft breaks Patch Tuesday record with 974-CVE deluge 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#primaryimage"},"thumbnailUrl":"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","datePublished":"2026-09-09T00:25:22+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#primaryimage","url":"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","contentUrl":"https:\/\/image.theregister.com\/5295166.jpg?imageId=5295166&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-breaks-patch-tuesday-record-with-974-cve-deluge\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/security\/"},{"@type":"ListItem","position":3,"name":"Microsoft breaks Patch Tuesday record with 974-CVE deluge"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61352"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61352\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}