Microsoft’s September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Microsoft Office, SQL Server, Exchange Server, SharePoint Server, Azure, and developer tools. Two vulnerabilities are confirmed to have been exploited as zero-days, making them immediate patching priorities despite both carrying an Important severity rating.

The scale of the release significantly exceeds August’s 400 vulnerabilities and July’s 570. Elevation of privilege accounts for the largest portion of the September release, followed by remote code execution and information disclosure vulnerabilities.


Breakdown of Vulnerabilities

  • 438 Elevation of Privilege vulnerabilities
  • 258 Remote Code Execution vulnerabilities
  • 173 Information Disclosure vulnerabilities
  • 56 Denial of Service vulnerabilities
  • 19 Security Feature Bypass vulnerabilities
  • 16 Spoofing vulnerabilities
  • 13 Tampering vulnerabilities

Microsoft’s release data attributes 723 vulnerabilities to Windows, 111 to Office, 62 to SQL, 22 to developer tools, 16 to SharePoint Server, and nine to Exchange Server.

Microsoft separately lists 25 republished CVEs assigned outside Microsoft. Those entries should be treated separately from the 973-vulnerability headline count.


Zero-Day Vulnerabilities

September’s Patch Tuesday addresses two zero-day vulnerabilities, both of which Microsoft has confirmed were exploited in attacks. Neither was listed as publicly disclosed before the updates became available.

CVE-2026-85880 | Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability

This actively exploited elevation of privilege vulnerability affects Windows ALPC and is rated Important by Microsoft. Technical details concerning the underlying weakness, exploitation chain, threat actors, and targeted organizations have not been publicly provided.

The confirmed exploitation makes CVE-2026-85880 a priority regardless of its Important rating. Organizations should account for Microsoft’s exploitation status rather than relying exclusively on severity classifications when establishing patch order.

CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability

This actively exploited vulnerability involves improper link resolution before file access, also known as link following. An authorized attacker can exploit the weakness locally to elevate privileges on an affected Windows system.

The vulnerability is particularly relevant to post-compromise activity. An attacker who has already obtained access to a system could potentially use CVE-2026-81963 to gain greater privileges and expand control over the endpoint. Microsoft rates the vulnerability Important and requires customer action.


Other Critical Vulnerabilities

Several critical vulnerabilities affect Windows security mechanisms responsible for protecting privileged operations and isolated workloads.

CVE-2026-83939 affects Windows Secure Kernel Mode and can result in elevation of privilege. CVE-2026-83498 also permits elevation of privilege within Virtualization-Based Security Enclaves, while CVE-2026-83501 exposes information through another VBS-related vulnerability. All three require customer action.

Microsoft Office received several critical remote code execution fixes. CVE-2026-81959 and CVE-2026-81953 affect Microsoft Excel, while CVE-2026-81952 affects Microsoft Word. Office deployments should be assessed separately from Windows patch status so that updated operating systems are not mistakenly treated as fully remediated endpoints.

Microsoft also addressed several Important-rated RCE vulnerabilities in commonly deployed Windows components. CVE-2026-85877 affects Windows Print Spooler, CVE-2026-83997 affects Windows Message Queuing, and CVE-2026-83998 affects Remote Desktop Client. Microsoft identifies customer action as required for each vulnerability.

A large group of elevation of privilege vulnerabilities also affects Windows Biometric Service, with further fixes covering the Windows Kernel, NTFS, Windows Error Reporting, and Resilient File System Deduplication Service.

Other notable vulnerabilities include CVE-2026-84001, a denial of service issue affecting Windows Key Distribution Center; CVE-2026-83989, a denial of service vulnerability in the Services for NFS ONCRPC XDR driver; and CVE-2026-83991, a tampering vulnerability affecting the Windows Cloud Files Mini Filter Driver.


Developer and Cloud Security Updates

September’s release extends beyond traditional Windows endpoints and servers.

CVE-2026-84003 addresses a spoofing vulnerability in Microsoft Authentication Library for Node.js, and CVE-2026-83948 addresses remote code execution in Microsoft Azure CLI. Microsoft requires customer action for both vulnerabilities.

Remediation requirements vary across Microsoft’s cloud services. For example, Microsoft lists critical Entra ID vulnerability CVE-2026-83941 as requiring no customer action. Administrators should verify the remediation status of individual cloud vulnerabilities rather than assuming every listed CVE requires a locally deployed update.


Recommendations for Users and Administrators

Organizations should prioritize CVE-2026-85880 and CVE-2026-81963 due to confirmed exploitation. Their Important ratings demonstrate why patch prioritization should account for exploitation status, affected assets, exposure, and potential impact rather than severity ratings alone.

Windows Secure Kernel Mode and VBS vulnerabilities should receive early testing due to their proximity to security boundaries intended to isolate sensitive operations. Microsoft Office also warrants priority attention given the critical Word and Excel RCE vulnerabilities included this month.

The unprecedented volume of September’s release makes asset-based prioritization particularly valuable. Security teams should identify which of the 973 vulnerabilities apply to deployed products and concentrate early remediation on actively exploited vulnerabilities, critical RCEs, identity infrastructure, externally accessible services, privileged systems, and widely deployed applications.

Microsoft recommends using representative test and pilot groups before broader deployment. Administrators should verify successful installation and required restarts, investigate endpoints that fail to update, and review known issues affecting Windows Server, Exchange, and SQL Server before production rollout.


How Can Netizen Help?

Founded in 2013, Netizen is an award-winning technology firm that develops and leverages cutting-edge solutions to create a more secure, integrated, and automated digital environment for government, defense, and commercial clients worldwide. Our innovative solutions transform complex cybersecurity and technology challenges into strategic advantages by delivering mission-critical capabilities that safeguard and optimize clients’ digital infrastructure. One example of this is our popular “CISO-as-a-Service” offering that enables organizations of any size to access executive level cybersecurity expertise at a fraction of the cost of hiring internally. 

Netizen also operates a state-of-the-art 24x7x365 Security Operations Center (SOC) that delivers comprehensive cybersecurity monitoring solutions for defense, government, and commercial clients. Our service portfolio includes cybersecurity assessments and advisory, hosted SIEM and EDR/XDR solutions, software assurance, penetration testing, cybersecurity engineering, and compliance audit support. We specialize in serving organizations that operate within some of the world’s most highly sensitive and tightly regulated environments where unwavering security, strict compliance, technical excellence, and operational maturity are non-negotiable requirements. Our proven track record in these domains positions us as the premier trusted partner for organizations where technology reliability and security cannot be compromised.

Netizen holds ISO 27001, ISO 9001, ISO 20000-1, and CMMI Level III SVC registrations demonstrating the maturity of our operations. We are a proud Service-Disabled Veteran-Owned Small Business (SDVOSB) certified by U.S. Small Business Administration (SBA) that has been named multiple times to the Inc. 5000 and Vet 100 lists of the most successful and fastest-growing private companies in the nation. Netizen has also been named a national “Best Workplace” by Inc. Magazine, a multiple awardee of the U.S. Department of Labor HIRE Vets Platinum Medallion for veteran hiring and retention, the Lehigh Valley Business of the Year and Veteran-Owned Business of the Year, and the recipient of dozens of other awards and accolades for innovation, community support, working environment, and growth.

Looking for expert guidance to secure, automate, and streamline your IT infrastructure and operations? Start the conversation today.


Posted in , ,

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.