SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Microsoft's September 2026 Patch Tuesday: 973 Vulnerabilities, Two Exploited Zero-Days and a Record Security Release

Microsoft's September 2026 Patch Tuesday: 973 Vulnerabilities, Two Exploited Zero-Days and a Record Security Release

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, infrastructure services, virtualization components and other Microsoft products.

Sep 9, 2026By Meghana Raatni

Microsoft's September 2026 Patch Tuesday is the company's largest security release to date, addressing 973 vulnerabilities across Windows, Office, infrastructure services, virtualization components and other Microsoft products.

The release patches two vulnerabilities already being exploited in the wild: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC).

The update also contains a large concentration of remote-code-execution vulnerabilities affecting critical enterprise infrastructure, including Netlogon, DNS, DHCP, Message Queuing, NFS, SSTP, Hyper-V and Microsoft Office.

September 2026 Vulnerabilities at a Glance

973 Vulnerabilities
113 Critical
860 Important
2 Exploited Zero-Days

The numbers make elevation of privilege the most common vulnerability class, but many of the vulnerabilities demanding the fastest attention are remote-code-execution flaws exposed through network-facing or widely deployed services. At least 17 of the RCE flaws are unauthenticated and network-reachable. 113 of the flaws have been classified as critical, and 860 as important.

Zero-Days Exploited in the Wild

CVE-2026-81963: Windows Update Stack Elevation of Privilege

Severity: Important

CVSS: 7.8

Type: Elevation of Privilege

Exploitation: Detected in the wild

User interaction: None required

CVE-2026-81963 affects the Windows Update Stack and results from improper link resolution before file access, commonly described as a link-following vulnerability. An attacker who already has local, low-privileged access can exploit the flaw to obtain SYSTEM privileges.

In practical terms, this is a post-compromise privilege-escalation vulnerability rather than an initial-access vulnerability. An attacker first needs a foothold on the Windows system. Once local code execution has been obtained, however, the vulnerability provides a path from low privileges to the highest local Windows privilege level.

The Windows Update Stack presents a particularly broad attack surface because its components are present across supported Windows clients and servers and execute with elevated privileges during update operations.

Why it matters

Although its 7.8 CVSS score places it below many of September's Critical RCE vulnerabilities, confirmed exploitation significantly increases its priority. An attacker who has already gained execution through phishing, stolen credentials or another vulnerability could potentially use CVE-2026-81963 to turn that limited foothold into SYSTEM-level access.

CVE-2026-85880: Windows ALPC Elevation of Privilege

Severity: Important

CVSS: 7.8

Type: Elevation of Privilege

Exploitation: Detected in the wild

User interaction: None required

The second actively exploited zero-day, CVE-2026-85880, affects Windows Advanced Local Procedure Call (ALPC). The vulnerability is caused by a heap-based buffer overflow and can allow an authorized local attacker to elevate privileges to SYSTEM.

An attacker who already has local code execution — including execution inside a low-privilege AppContainer sandbox — can trigger the vulnerability to escape that restricted context and reach SYSTEM privileges. No additional user interaction is required.

ALPC is a core Windows inter-process communication mechanism underpinning technologies including RPC, COM and numerous Windows system services. Consequently, the vulnerability exists in a low-level and widely used Windows component.

As with CVE-2026-81963, Microsoft has not disclosed how attackers are exploiting CVE-2026-85880 in observed attacks.

Why it matters

The flaw is particularly useful in an exploit chain. Initial-access vulnerabilities or sandbox escapes often leave attackers operating with restricted privileges; CVE-2026-85880 can provide the subsequent privilege-escalation step needed to obtain complete local control.

Critical Vulnerabilities That Demand Attention

September's release contains too many Critical vulnerabilities to examine individually, but several groups stand out because they combine remote code execution with limited or no authentication requirements and exposure on high-value enterprise systems.

CVE-2026-72982: Windows Netlogon Remote Code Execution

CVE-2026-72982 is a Critical CVSS 9.8 remote-code-execution vulnerability in Windows Netlogon. An unauthenticated attacker can send a specially crafted packet to the Netlogon service and execute arbitrary code on the target without user interaction.

Netlogon handles domain logon requests, secure-channel establishment between domain members and domain controllers and machine-account password operations. It therefore runs on domain controllers and must be accessible to systems participating in the domain.

The combination of unauthenticated network access, remote code execution and domain-controller exposure makes CVE-2026-72982 one of the highest-priority vulnerabilities in the release.

CVE-2026-69730: Windows DNS Server Remote Code Execution

CVE-2026-69730 is another Critical CVSS 9.8 RCE vulnerability. An unauthenticated attacker can send a specially crafted packet to a vulnerable Windows DNS Server and execute code without user interaction.

The vulnerability deserves particular attention in Active Directory environments because Windows DNS commonly operates alongside other domain infrastructure, including on domain controllers.

A remote compromise of such a server can therefore place an attacker directly onto highly trusted infrastructure.

CVE-2026-69845 and CVE-2026-72979: Windows DHCP Server RCE

Two vulnerabilities affecting Windows DHCP Server — CVE-2026-69845 and CVE-2026-72979 — are each rated Critical with CVSS scores of 9.8.

An unauthenticated attacker with network access to the DHCP server can send crafted packets and trigger either a heap-based buffer overflow or a use-after-free condition, depending on the vulnerability, leading to arbitrary code execution. Neither vulnerability requires user interaction.

Because DHCP servers are core network infrastructure and communicate directly with endpoints requesting network configuration, compromise could provide an attacker with a valuable internal foothold.

CVE-2026-73009: Windows SSTP Remote Code Execution

CVE-2026-73009 affects the Windows Secure Socket Tunneling Protocol service and carries a Critical CVSS score of 9.8. An unauthenticated attacker can send a specially crafted packet to the SSTP listener and execute code remotely.

SSTP is supported by Windows Server's Routing and Remote Access Service for VPN connectivity. Organizations using SSTP remote-access VPNs may expose the vulnerable service over TCP port 443, potentially placing vulnerable systems directly at the network perimeter.

That combination of internet-facing exposure and unauthenticated RCE makes SSTP servers an important patching priority.

Critical Microsoft Office Vulnerabilities

Microsoft Office represents another major attack surface in September.

22 Critical Office-related vulnerabilities were identified: 21 remote-code-execution flaws and one information-disclosure vulnerability affecting Outlook, Word, Excel, PowerPoint, the Office Graphics Component and Windows Graphics Component.

More significantly, 12 of the 22 vulnerabilities can be triggered through Outlook's Reading Pane or Windows Explorer's Preview Pane. For those vulnerabilities, viewing a malicious file or message in the relevant preview interface can be sufficient to trigger exploitation without opening the attachment or responding to a macro prompt.

Three Preview/Reading Pane vulnerabilities carry CVSS 9.8 scores:

These vulnerabilities deserve particular attention on user workstations because exploitation can occur with substantially less interaction than traditional malicious-document attacks.

Products Affected

The September 2026 release spans a broad Microsoft ecosystem. Major affected technologies highlighted in the September reporting include:

  • .NET
  • .NET and Visual Studio
  • Active Directory Certificate Services (AD CS)
  • Active Directory Domain Services
  • Active Directory Federation Services (AD FS)
  • ASP.NET Core
  • Audio Video Control Transport Protocol
  • Azure AI Language
  • Azure Arc
  • Azure Cosmos DB
  • Azure CycleCloud
  • Azure HDInsights
  • BranchCache
  • Connected Devices Platform Service (Cdpsvc)
  • Copilot Studio
  • Data Sharing Service Client
  • Entra ID
  • GitHub Copilot and Visual Studio Code
  • Graphic Fonts
  • HID class driver
  • Internet Storage Name Service
  • IP Helper
  • Kernel Streaming WOW Thunk Service Driver
  • Microsoft Account
  • Microsoft Authentication Library (MSAL) for Node.js
  • Microsoft Authenticator
  • Microsoft Azure Active Directory B2C
  • Microsoft Azure CLI
  • Microsoft COM for Windows
  • Microsoft Discovery Studio
  • Microsoft Dynamics 365
  • Microsoft Entra ID
  • Microsoft Exchange Server
  • Microsoft Fabric
  • Microsoft Graphics Component
  • Microsoft Install Service
  • Microsoft JScript
  • Microsoft Local Security Authority Server (lsasrv)
  • Microsoft Office
  • Microsoft Office Access
  • Microsoft Office Excel
  • Microsoft Office Outlook
  • Microsoft Office PowerPoint
  • Microsoft Office Publisher
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft Standard XPS
  • Microsoft Teams for Android
  • Microsoft Trace Data Helper
  • Microsoft UxTheme Library (uxtheme.dll)
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft WebP Image Extension
  • Microsoft Windows Codecs Library
  • Microsoft Windows Media Foundation
  • Microsoft Windows PDF
  • Microsoft Windows SCSI Class System File
  • Microsoft Windows Search Component
  • Microsoft Windows Speech
  • OpenSSH for Windows
  • Power Automate
  • Push Message Routing Service
  • Reliable Multicast Transport Driver (RMCAST)
  • Remote Desktop Client
  • Remote Desktop Gateway Service
  • Role: DNS Server
  • Role: Windows Fax Service
  • RPC Runtime
  • Skype for Business
  • Spring Cloud Azure
  • SQL Server
  • Storage Port Driver
  • Telnet Client
  • Virtual Hard Disk (VHD) Miniport Driver
  • Visual Studio
  • Visual Studio Code
  • Volume Manager Driver
  • Windows Accounts Control
  • Windows AF_UNIX Socket Provider
  • Windows ALPC
  • Windows Ancillary Function Driver for WinSock
  • Windows Audio Service
  • Windows Authentication Methods
  • Windows Autopilot
  • Windows Bind Filter Driver
  • Windows Biometric Service
  • Windows BitLocker
  • Windows Bluetooth Port Driver
  • Windows Bluetooth Service
  • Windows Boot Manager
  • Windows Broadcast DVR User Service
  • Windows Broker Infrastructure Service
  • Windows Camera Frame Server Monitor
  • Windows CD-ROM Driver
  • Windows Cloud Files Mini Filter Driver
  • Windows Compressed Folder
  • Windows Connected User Experiences and Telemetry
  • Windows Container Manager Service
  • Windows Core Messaging
  • Windows Credential Guard
  • Windows Credential Providers
  • Windows DCOM Server
  • Windows Defender Firewall Service
  • Windows Deployment Services
  • Windows Device Association Broker service
  • Windows Device Association Service
  • Windows Device Health Attestation (DHA)
  • Windows Devices Human Interface
  • Windows DHCP Client
  • Windows DHCP Server
  • Windows Direct Show
  • Windows Display Enhancement Service
  • Windows Distributed File System (DFS)
  • Windows DNS
  • Windows DWM Core Library
  • Windows Embedded Mode Service
  • Windows Encrypting File System (EFS)
  • Windows Enterprise App Management
  • Windows Error Reporting
  • Windows Event Logging Service
  • Windows exFAT File System
  • Windows Failover Cluster
  • Windows Fast FAT Driver
  • Windows File History Service
  • Windows GDI
  • Windows GDI+
  • Windows Graphics Kernel
  • Windows Group Policy
  • Windows Hello
  • Windows Host Guardian Service
  • Windows HTTP Print Provider
  • Windows HTTP.sys
  • Windows Hyper-V
  • Windows IKE Extension
  • Windows Image Acquisition
  • Windows Imaging Component
  • Windows Installer
  • Windows Internet Connection Sharing (ICS)
  • Windows IP Address Management (IPAM) Service
  • Windows iSCSI
  • Windows iSCSI Target Service
  • Windows Kerberos
  • Windows Kernel
  • Windows Kernel Mode Driver
  • Windows Key Distribution Center
  • Windows LDAP - Lightweight Directory Access Protocol
  • Windows License Manager
  • Windows Link Layer Topology Discovery Protocol
  • Windows Management Instrumentation
  • Windows Management Services
  • Windows Media
  • Windows Media Player
  • Windows Message Queuing
  • Windows Message Queuing Queue Manager
  • Windows Microsoft DirectMusic
  • Windows MIDI Service Module
  • Windows Mobile Broadband
  • Windows Modern Device Management (MDM)
  • Windows Modern Execution Server
  • Windows NDIS
  • Windows Netlogon
  • Windows Network Connection Broker
  • Windows Network File System
  • Windows NFS Portmapper
  • Windows Notification
  • Windows NTFS
  • Windows OLE DB
  • Windows Online Certificate Status Protocol (OCSP)
  • Windows Overlay Filter
  • Windows Paint
  • Windows Partition Management Driver
  • Windows Performance Monitor
  • Windows Power Dependency Coordinator
  • Windows PowerShell
  • Windows Print Spooler Components
  • Windows PrintWorkflowUserSvc
  • Windows Program Compatibility Assistant Service
  • Windows Push Notifications
  • Windows Raw Image Extension
  • Windows RDP Client
  • Windows Registry
  • Windows Remote Access Connection Manager
  • Windows Remote Desktop
  • Windows Remote Desktop Licensing Service
  • Windows Remote Desktop Protocol
  • Windows Remote Desktop Services
  • Windows Resilient File System (ReFS)
  • Windows Resilient File System (ReFS) Deduplication Service
  • Windows RNDIS
  • Windows Routing and Remote Access Service (RRAS)
  • Windows Schannel
  • Windows Secure Boot
  • Windows Secure Kernel Mode
  • Windows Secure Socket Tunneling Protocol (SSTP)
  • Windows Security Center
  • Windows Security Health Service
  • Windows Server
  • Windows Services for NFS ONCRPC XDR Driver
  • Windows Setup Files Cleanup
  • Windows Shell
  • Windows Smart Card
  • Windows SMB Client
  • Windows SMB Server
  • Windows SMB Server Network Transport Driver (srvnet.sys)
  • Windows Spaceport.sys
  • Windows Storage
  • Windows Storage Management Provider
  • Windows Storage Port Driver
  • Windows Storage Spaces Controller
  • Windows Task Scheduler
  • Windows TCP/IP
  • Windows Text Shaping
  • Windows Universal Disk Format File System Driver (UDFS)
  • Windows Universal Plug and Play (UPnP) Device Host
  • Windows Update Stack
  • Windows URL Moniker
  • Windows USB Audio Class driver (usbaudio.sys)
  • Windows USB Driver
  • Windows USB Hub Driver
  • Windows USB Mass Storage Class Driver
  • Windows USB Video Driver
  • Windows VHD miniport driver
  • Windows Virtual Trusted Platform Module
  • Windows Virtualization-Based Security (VBS) Enclave
  • Windows VOLSNAP.SYS
  • Windows Volume Manager Extension Driver
  • Windows Volume Shadow Copy
  • Windows Web Platform Storage
  • Windows WebClient Service
  • Windows Win32 Kernel Subsystem
  • Windows Win32K
  • Windows Wireless Networking
  • Windows Wireless Wide Area Network Service
  • Windows Work Folder Service
  • Windows Work Folders
  • Winsock
  • Xbox
  • XBox Gaming Services

Patches and Mitigations

The primary remediation for vulnerabilities included in September Patch Tuesday is to deploy Microsoft's corresponding security updates.

Given the scale of the release, organizations may need to prioritize deployment rather than treat every vulnerability identically.

1. Patch the two exploited zero-days first

CVE-2026-81963 and CVE-2026-85880 are confirmed as being exploited in the wild.

Systems vulnerable to either flaw should therefore be prioritized even though Microsoft rates both vulnerabilities Important rather than Critical.

2. Prioritize unauthenticated network RCE

Systems running Netlogon, DNS Server, DHCP Server, MSMQ, Services for NFS and SSTP should receive particular attention because September includes Critical vulnerabilities capable of remote code execution without authentication or user interaction.

Internet-facing SSTP services and internally exposed infrastructure such as DNS, DHCP and domain controllers should be identified early in the patching process.

3. Patch domain controllers and identity infrastructure rapidly

The release contains Critical RCE vulnerabilities affecting both Netlogon and Kerberos, two important components of Windows domain authentication.

Where change-control procedures prevent immediate deployment, network access to affected infrastructure should be limited to systems and segments that genuinely require it.

4. Treat Office updates as high priority

The presence of 12 Critical vulnerabilities triggerable through Preview Pane or Reading Pane creates a particularly low-interaction attack path.

Office updates should therefore be prioritized across user endpoints. In environments where immediate patch deployment is impossible, administrators can consider restricting Preview/Reading Pane functionality as a temporary compensating control after assessing operational impact.

5. Review Hyper-V hosts separately from ordinary endpoints

CVE-2026-69603 and CVE-2026-80083 can cross the guest-to-host security boundary in Hyper-V.

Organizations operating virtualization infrastructure should therefore include Hyper-V hosts in the high-priority patch group rather than relying only on guest operating-system updates.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open MikroTik RouterOS Under Attack: Critical SSH Vulnerabilities Enable Router Takeover
MikroTik RouterOS Under Attack: Critical SSH Vulnerabilities Enable Router Takeover

CVE Research

MikroTik RouterOS Under Attack: Critical SSH Vulnerabilities Enable Router Takeover

Sep 8, 2026

Open StyleSmuggler: The Evolution of a Magento Zero-Day (Updated: Patch Available)
StyleSmuggler: The Evolution of a Magento Zero-Day (Updated: Patch Available)

CVE Research

StyleSmuggler: The Evolution of a Magento Zero-Day (Updated: Patch Available)

StyleSmuggler, a Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026