Microsoft Patch Tuesday | September 2026

966 Vulnerabilities and Two Active Zero-Days

 

Microsoft has released its September 2026 Patch Tuesday security updates, addressing a record 966 vulnerabilities, including two actively exploited zero-day flaws.

 

This month’s release includes 105 Critical vulnerabilities, made up of:

    • 81 Remote Code Execution vulnerabilities
    • 20 Elevation of Privilege vulnerabilities
    • 2 Information Disclosure vulnerabilities
    • 1 Security Feature Bypass vulnerability

Across the wider release, Microsoft addressed approximately:

    • 438 Elevation of Privilege vulnerabilities
    • 258 Remote Code Execution vulnerabilities
    • 173 Information Disclosure vulnerabilities
    • 56 Denial of Service vulnerabilities
    • 19 Security Feature Bypass vulnerabilities
    • 16 Spoofing vulnerabilities

The total does not include a further 204 vulnerabilities Microsoft addressed earlier in September across products including Azure AI Language, Azure Cosmos DB, Entra ID, Microsoft Edge, Microsoft Fabric, Power Automate and other Microsoft services.

September’s Patch Tuesday is Microsoft’s largest security update to date, following two already significant releases in July and August.

Microsoft has previously warned that the volume of vulnerabilities disclosed through Patch Tuesday could increase as it expands the use of AI-assisted vulnerability discovery across its software portfolio.

 

Microsoft Patches Two Actively Exploited Zero-Days

Two zero-day vulnerabilities fixed this month were already being exploited in attacks before patches became available.

Both are elevation of privilege vulnerabilities affecting Windows and can allow an attacker to gain SYSTEM-level privileges.

CVE-2026-81963 – Windows Update Stack Elevation of Privilege Vulnerability

Microsoft has patched CVE-2026-81963, an actively exploited elevation of privilege vulnerability in the Windows Update Stack.

The issue is caused by improper link resolution before file access, sometimes referred to as link following.

According to Microsoft, an authorised attacker could exploit the vulnerability locally to elevate their privileges.

Successful exploitation could allow an attacker to gain SYSTEM-level access on the affected device.

Microsoft has confirmed that the vulnerability has been exploited in attacks but has not published technical details about the exploitation observed.

The vulnerability was credited to Romain Deperne and the Microsoft Threat Intelligence Centre.

Organisations running affected Windows systems should prioritise deployment of the relevant security updates due to the confirmed exploitation status.

CVE-2026-85880 – Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability

The second actively exploited zero-day is CVE-2026-85880, affecting Windows Advanced Local Procedure Call.

The vulnerability is caused by a heap-based buffer overflow in Windows ALPC.

An authorised attacker able to exploit the flaw locally could elevate privileges and gain SYSTEM-level access.

Microsoft has again confirmed active exploitation but has not disclosed how attackers are using the vulnerability in real-world attacks.

The flaw was reported by Volexity and researchers Mark Kelly, David Galazin and Jeremy Hedges from Proofpoint.

Because the vulnerability is already being exploited, affected organisations should treat remediation as a priority.

 

Why Elevation of Privilege Vulnerabilities Matter

Elevation of privilege vulnerabilities are particularly useful to attackers when they form part of a wider attack chain.

An attacker may initially gain access to a device through phishing, stolen credentials, malware or exploitation of another vulnerability.

If they only have access through a standard user account, their ability to make meaningful changes to the system can be limited.

An elevation of privilege vulnerability can allow them to move from that initial foothold to administrative or SYSTEM-level access.

From there, an attacker may be able to:

    • Disable or interfere with security controls
    • Access sensitive files or credentials
    • Modify system configurations
    • Install persistent malware
    • Move further through the environment

This makes vulnerabilities such as CVE-2026-81963 and CVE-2026-85880 particularly important where attackers already have some level of local access.

 

258 Remote Code Execution Vulnerabilities Addressed

Microsoft also addressed approximately 258 Remote Code Execution vulnerabilities in September.

Remote code execution vulnerabilities can allow an attacker to execute code on a vulnerable system, potentially without needing direct physical or authenticated access.

Of the 105 Critical vulnerabilities addressed this month, 81 fall into the remote code execution category.

The actual risk associated with each vulnerability depends on several factors, including:

    • Whether the affected software is present in the environment
    • Whether the vulnerable service is exposed
    • Whether authentication is required
    • Whether user interaction is needed
    • Whether exploit code is publicly available
    • Whether active exploitation has been observed

This is why severity alone should not be used as the only measure of remediation priority.

A Critical vulnerability affecting an unused or isolated component may represent less immediate risk than a lower-rated vulnerability affecting an internet-facing system with active exploitation.

 

438 Elevation of Privilege Vulnerabilities

Elevation of privilege represents the largest category in September’s release, with approximately 438 vulnerabilities addressed.

These issues generally require an attacker to already have some level of access to the affected system.

However, once that foothold exists, privilege escalation can significantly increase the attacker’s control.

This is particularly relevant in modern attack chains, where threat actors often combine multiple weaknesses rather than relying on a single vulnerability.

For example, an attacker could exploit one vulnerability for initial access before using an elevation of privilege flaw to gain SYSTEM-level permissions and establish persistence.

Information Disclosure, Denial of Service and Security Bypass Flaws

Microsoft also patched:

    • 173 Information Disclosure vulnerabilities
    • 56 Denial of Service vulnerabilities
    • 19 Security Feature Bypass vulnerabilities
    • 16 Spoofing vulnerabilities

Information disclosure vulnerabilities can expose data that would normally be restricted, while security feature bypass vulnerabilities can allow attackers to circumvent protections built into an application or operating system.

Denial of service vulnerabilities can be exploited to affect the availability of systems or services, while spoofing vulnerabilities may allow attackers to impersonate trusted users, systems or resources.

Although these categories may not always attract the same attention as remote code execution vulnerabilities, they can still play an important role in wider attack chains.

What Should Security Teams Prioritise?

With nearly 1,000 vulnerabilities addressed in a single release, applying every update at the same priority level is unlikely to be practical.

Security teams should begin by identifying whether the affected products and components are present within their environment.

Priority should then be given to:

    • Vulnerabilities confirmed as actively exploited
    • Internet-facing or externally accessible systems
    • Critical remote code execution vulnerabilities
    • Vulnerabilities that provide SYSTEM or administrative privileges
    • Assets containing sensitive or business-critical data
    • Vulnerabilities with publicly available exploit code

For September, CVE-2026-81963 and CVE-2026-85880 should be reviewed immediately due to confirmed exploitation.

Teams should also verify that security updates have been successfully deployed across affected assets rather than relying solely on patch deployment status.

 

Visibility Is Critical When Patch Volumes Increase

September’s release highlights the growing challenge facing security teams.

When hundreds of vulnerabilities are disclosed at once, simply knowing that a patch exists is not enough.

Organisations need to know which assets are affected, how exposed those assets are and whether remediation has been completed successfully.

Within CybaOps, vulnerability information can be brought together with asset visibility and remediation workflows, helping teams identify affected systems and prioritise action based on their own environment rather than treating every vulnerability equally.

As Patch Tuesday releases continue to increase in size, that context becomes increasingly important.

The objective is not to work through a list of 966 CVEs one by one.

It is to identify the vulnerabilities that create the greatest risk in your environment and make sure they are actually fixed.

 To access the full description of each vulnerability and the systems it affects, you can view the full report here.

Latest Insights and Articles

RMM platforms are operational infrastructure. They are built for efficiency, reach and control. They are not...

CybaVerse has achieved ISO 27001 recertification with BSI, independently validating our information security...

See how MDR works with existing EDR, including SentinelOne, without rip-and-replace. Keep control, cut...

See How CybaOps Can Take You
From Chaos To Clarity