Microsoft released September security updates addressing 973 vulnerabilities across Windows, Office, SQL Server, Exchange, SharePoint, Azure, and developer tools. The release fixes two actively exploited, Important-rated Windows elevation-of-privilege vulnerabilities: CVE-2026-85880 in Advanced Local Procedure Call (ALPC) and CVE-2026-81963 in the Windows Update Stack. It also includes Critical fixes affecting Windows Secure Kernel Mode, Virtualization-Based Security enclave components, and remote-code-execution flaws in Excel and Word; elevation-of-privilege issues account for 438 of the vulnerabilities and RCE issues for 258.
For Windows 11, Microsoft issued cumulative updates KB5124008 for versions 24H2 and 25H2, advancing them to builds 26100.9445 and 26200.9445, and KB5122880 for version 23H2. The updates introduce phased changes including Administrator Protection, which applies just-in-time administrative privileges and separates administrator profiles, along with Microsoft Execution Containers process isolation and Autopilot enhancements. Organizations should urgently deploy and verify patches for the exploited flaws, validate product applicability and known issues in representative groups, and use staged rollout procedures with reboot and installation monitoring.

See which actors are running it and whether you're in range.
100 events from the most recent confirmed update back to the earliest known activity.
Tenable published Nessus plugin 344796 to identify Microsoft SQL Server installations missing September 2026 security updates through self-reported version detection. The High-severity plugin covers SQL Server and Windows OLE DB remote-code-execution risks including CVE-2026-77482, CVE-2026-77486, and CVE-2026-78442, remediated through KB5122768 through KB5122775.
Tenable published Nessus Plugin 344798 to identify Microsoft SQL Server installations missing September 2026 security updates through self-reported version detection. The plugin covers multiple vulnerabilities, including network RCE flaws CVE-2026-77482, CVE-2026-77486, and CVE-2026-78442, remediated through KB5122768 through KB5122775.
Tenable published Cloud Security plugin 447888 to detect vulnerable Alpine Linux aspnetcore9-runtime and dotnet-host packages. The High-severity plugin covers .NET and Microsoft QUIC flaws including CVE-2026-62871, CVE-2026-70354, CVE-2026-62886, CVE-2026-62897, and CVE-2026-62898, and recommends updating affected packages to version 9.0.19-r0 or later; it reported no known public exploits.
Tenable published Nessus plugin 344559 to identify Microsoft Excel Click-to-Run installations missing September 2026 security updates using self-reported application versions rather than active exploit testing. The High-severity plugin covers Excel vulnerabilities including CVE-2026-78518 and advises Office 365, Office 2016 C2R, and Office 2019 users to enable automatic updates or update manually.
Tenable published Critical Nessus plugin 344562 to detect Microsoft Word Products Click-to-Run installations missing the September 2026 security updates through self-reported application versions. The plugin covers multiple Word remote-code-execution and information-disclosure flaws, plus the Outlook RCE flaw CVE-2026-78509, and does not directly test exploitability.
A patch was published for CVE-2026-71328, a high-severity CVSS 8.8 heap-based buffer-overflow vulnerability in Visual Studio affecting Microsoft.DiaSymReader.Native and related packages. Updating to version 18.9.0-beta1.26405.2 or later remediates the network-exploitable RCE flaw; Tenable reported no known exploits.
A patch was published for CVE-2026-69522, a High-severity CVSS 8.8 heap-based buffer-overflow vulnerability affecting Visual Studio and Microsoft.DiaSymReader.Native. Updating Microsoft.DiaSymReader.Native and related packages to version 18.9.0-beta1.26405.2 or later remediates the flaw; Tenable reported no known public exploits.
Microsoft published a patch for CVE-2026-69439 affecting Microsoft.DiaSymReader.Native and related .NET packages. Updating to version 18.9.0-beta1.26405.2 or later remediates the heap-based buffer-overflow elevation-of-privilege flaw tracked as GHSA-527h-q9f6-p7qx.
CSIRT Italia published alert AL01/260909/CSIRT-ITA, assigning a critical systemic-impact rating of 76.66 to Microsoft's September 2026 security updates. The agency highlighted the actively exploited CVE-2026-81963 and CVE-2026-85880 elevation-of-privilege flaws and recommended applying updates promptly through Windows Update.
Microsoft published a fix for CVE-2026-77897, a high-severity elevation-of-privilege vulnerability affecting Power Automate for desktop on Windows. A locally authenticated low-privileged attacker could exploit the high-complexity flaw without user interaction, with high confidentiality, integrity, and availability impact.
Arctic Wolf reported that September 2026 updates addressed CVE-2026-65669, a CVSS 9.6 injection vulnerability affecting SQL Server. The issue had previously been identified in the timeline only as associated with SQL Server Management Studio and Copilot functionality.
Microsoft disclosed CVE-2026-77488, an Important SQL Server integer-underflow vulnerability that allows a low-privileged authorized local attacker to read portions of heap memory without user interaction. Microsoft rated it CVSS 5.5, assessed exploitation as unlikely with no known exploitation or prior public disclosure, and made an official fix available.
Microsoft released SQL Server 2025 CU8 security update KB5122769 for Windows and Linux, advancing the product to build 17.0.4085.5 and remediating 56 vulnerabilities across elevation of privilege, RCE, information disclosure, security-feature bypass, and denial of service. Microsoft documented known regressions involving MSDASQL linked-server provider strings and sys.dm_exec_requests queries during database recovery, with trace flag 4696 offered as a mitigation for the latter.
Microsoft released SQL Server 2025 GDR update KB5122770 for all SQL Server 2025 editions on Windows and Linux, updating the product to build 17.0.1135.8. The update remediates elevation-of-privilege, remote-code-execution, information-disclosure, security-feature-bypass, and denial-of-service vulnerabilities, and has a known MSDASQL linked-server provider-string regression that can produce error 7416.
Microsoft released SQL Server 2022 GDR security update KB5122771, updating the product to build 16.0.1200.5 and remediating 56 vulnerabilities across RCE, elevation-of-privilege, information-disclosure, security-feature-bypass, and denial-of-service categories. Microsoft documented a known issue in which MSDASQL linked-server queries using a provider string can fail with error 7416 because of stricter Database Engine connection validation.
Microsoft released SQL Server 2022 CU26 security update KB5122768, updating the product to build 16.0.4275.2 and remediating 54 vulnerabilities across RCE, elevation-of-privilege, information-disclosure, security-feature-bypass, and denial-of-service categories. Microsoft documented known issues involving MSDASQL linked-server queries failing with error 7416 and sys.dm_exec_requests queries during database recovery causing an access violation; trace flag 4696 mitigates the latter issue.
Microsoft released SQL Server 2019 CU32 security update KB5122772, updating the product to build 15.0.4490.9 and remediating 52 SQL Server and Windows OLE DB vulnerabilities, including RCE, elevation-of-privilege, information-disclosure, and denial-of-service flaws. Microsoft documented a known issue in which certain MSDASQL linked-server queries using a provider string fail with error 7416 because of stricter Database Engine connection validation.
Microsoft released SQL Server 2019 GDR security update KB5122773, updating SQL Server 2019 to build 15.0.2190.7. The update remediates numerous SQL Server and Windows OLE DB vulnerabilities, including remote-code-execution, elevation-of-privilege, information-disclosure, and denial-of-service flaws; Microsoft also documented that some MSDASQL linked-server queries using provider strings can fail with error 7416 after installation.
Microsoft released SQL Server 2017 security update KB5122774, updating the product to build 14.0.3550.4 and remediating 45 SQL Server vulnerabilities plus two Windows OLE DB flaws, including RCE, elevation-of-privilege, denial-of-service, and information-disclosure issues. Microsoft documented a known issue where MSDASQL linked-server queries using a provider string can fail with error 7416 because of stricter connection validation.
Microsoft released SQL Server 2017 GDR update KB5122775, advancing SQL Server 2017 to build 14.0.2130.4 and remediating 44 SQL Server and Windows OLE DB vulnerabilities, including remote-code-execution, elevation-of-privilege, information-disclosure, and denial-of-service flaws. Microsoft also documented that some MSDASQL linked-server queries using a provider string can fail with error 7416 after installation because of stricter Database Engine connection validation.
Alpine Linux identified multiple vulnerabilities affecting aspnetcore9-runtime packages, including newly noted CVE-2026-58649 information disclosure and CVE-2026-69304 ASP.NET Core denial of service, alongside previously disclosed .NET and Visual Studio flaws. Updating aspnetcore9-runtime and related packages to version 9.0.20-r0 or later remediates the exposure; no known exploits were reported.
Microsoft released security update KB5002910 (MS26-5002910) for Microsoft Office Online Server and Microsoft Office Web Apps, remediating CVE-2026-81390, CVE-2026-81401, CVE-2026-81947, and CVE-2026-81956. CVE-2026-81947 is a CVSS 8.8 local vulnerability requiring user interaction that can have high confidentiality, integrity, and availability impact; Tenable published Nessus plugin 344556 to detect missing updates.
Tenable published Nessus plugin 344558 (smb_nt_ms26_sep_office_c2r.nasl) to identify Microsoft Office Click-to-Run installations potentially missing September 2026 security updates. The Windows-agent plugin references 18 CVEs, including CVE-2026-69285, and uses the SMB/MS_Bulletin_Checks/Possible Patch knowledge-base item for detection.
September 2026 Patch Tuesday addressed CVE-2026-66302 in Skype for Business Server, CVE-2026-69579 in Windows Message Queuing, and CVE-2026-69590 in Windows RRAS, each rated CVSS 9.8. The flaws can enable unauthenticated network attacks, including crafted requests or packets against affected services; the MSMQ issue is a use-after-free reachable through TCP port 1801.
Tenable published Nessus plugin 344560 for Windows agents to identify Microsoft Outlook Click-to-Run installations potentially missing September 2026 security updates. The plugin covers CVE-2026-69629, CVE-2026-78519, and CVE-2026-80073 and uses SMB/MS_Bulletin_Checks/Possible Patch KB data for detection.
Microsoft released KB5002916, KB5002904, KB5002898, KB5002913, and KB4011160 for Office products, remediating critical remote-code-execution, information-disclosure, and spoofing vulnerabilities across Office, Word, Excel, Access, Outlook, and the Microsoft Graphics Component. Tenable's Critical Nessus plugin 344286 detects affected installations through self-reported version information and reported no known exploits when published.
Tenable published Nessus plugin 344563 to detect missing Microsoft PowerPoint Click-to-Run security updates released on September 8, 2026. The plugin covers eight PowerPoint CVEs, including CVE-2026-69678, CVE-2026-69767, CVE-2026-69797, CVE-2026-72956, CVE-2026-72975, CVE-2026-72977, CVE-2026-78513, and CVE-2026-80081.
Microsoft released PowerPoint security update KB5002920 to remediate six vulnerabilities, including remote-code-execution flaws CVE-2026-69678, CVE-2026-69767, and CVE-2026-69797, plus three information-disclosure flaws. Tenable reported no known exploits and noted that Nessus plugin 344288 detects affected installations by self-reported version.
Microsoft released Word security update KB5002923 (MS26-5002923), addressing 31 CVEs including CVE-2026-78509, which Tenable used as its CVSS scoring source and rated 10.0. Tenable reported no known exploits for the vulnerabilities covered by the update.
Microsoft released KB5002644 for Microsoft Publisher Products to remediate CVE-2026-69742, an integer-overflow vulnerability, and CVE-2026-81385, a deserialization-of-untrusted-data flaw. Both vulnerabilities may allow unauthorized remote code execution; Tenable reported no known exploits.
Microsoft released Excel security update KB5002914 (MS26-5002914), addressing CVE-2026-78512 and numerous other Excel vulnerabilities. CVE-2026-78512 can permit remote code execution with user interaction and has high confidentiality, integrity, and availability impact; Tenable reported no known exploits.
Tenable published Nessus plugin 344557 (smb_nt_ms26_sep_access_c2r.nasl) for Windows agents and Risk Information sensors to identify Microsoft Access Click-to-Run installations potentially missing September 2026 security updates. The plugin checks SMB/MS_Bulletin_Checks/Possible Patch data and references CVE-2026-69477, CVE-2026-69529, CVE-2026-69614, and CVE-2026-69778.
Microsoft's September 8, 2026 security updates for Microsoft Access addressed CVE-2026-69477, CVE-2026-69529, CVE-2026-69614, and CVE-2026-69778 through KB5002912 and KB5002913. CVE-2026-69529 is a CVSS 8.8 network-accessible vulnerability requiring user interaction; Tenable reported no known exploits.
Microsoft published Outlook security update KB5002919 (MS26-5002919), addressing CVE-2026-69629, CVE-2026-78519, and CVE-2026-80073. CVE-2026-69629 is rated CVSS v2 10.0 and could enable network-based code execution with user interaction; Tenable reported no known exploits.
Tenable published a notice for an unspecified vulnerability affecting Microsoft .NET 8.0, 9.0, and 10.0 package families on CentOS 8 and Red Hat Enterprise Linux 8, 9, and 10, including .NET and ASP.NET Core runtimes, SDKs, hosts, targeting packs, templates, and debugging components. The notice reported no known exploits but did not provide technical details, severity, fixed package versions, or mitigation guidance.
Microsoft released Security Update KB5124012 for Windows 11 Version 26H1, addressing multiple vulnerabilities including the remotely exploitable RCE flaws CVE-2026-68839, CVE-2026-69276, and CVE-2026-69408. Tenable rated systems missing the update Critical and reported no known exploits.
Microsoft released security update KB5002908 under bulletin MS26-5002908 for SharePoint Server Subscription Edition, addressing 16 CVEs. The vulnerabilities include CVE-2026-69268, a CVSS 9.0 network-accessible flaw requiring low privileges and no user interaction, as well as access-control, race-condition, XSS, SQL-injection, and SSRF issues.
Microsoft released the September 2026 Windows Server 2025 security update KB5122871. The update fixes multiple vulnerabilities, including the Critical CVE-2026-68839 Windows USB Mass Storage Class Driver RCE flaw and RCE vulnerabilities CVE-2026-69276 in UxTheme and CVE-2026-69408 in Windows Media Foundation; Tenable reported no known exploits.
Microsoft released security update KB5122876 for Windows 10 version 1809 and Windows Server 2019. The update addresses multiple vulnerabilities, including remotely exploitable RCE flaws CVE-2026-68839 in the Windows USB Mass Storage Class Driver, CVE-2026-69276 in UxTheme, and CVE-2026-69408 in Windows Media Foundation.
Microsoft released Exchange Server 2019 CU14 SU14 (KB5121610), resolving eight CVEs including CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382, and CVE-2026-69641. The update replaces KB5121575, fixes hybrid shared-mailbox wrapper messages introduced after the June 2026 update, and has a known issue where published .ics calendars can return HTTP 500 errors.
Microsoft released Exchange Server Subscription Edition RTM SU10 (KB5121608), remediating eight vulnerabilities including CVE-2026-55007 and replacing KB5121573. The update fixes certain hybrid shared-mailbox and free/busy issues, while documenting known issues with published calendar HTTP 500 errors and delegated-mailbox availability in Graph-only hybrid deployments.
Microsoft released September 2026 security updates for Exchange Server 2016, 2019, and Subscription Edition through KB5121608, KB5121609, KB5121610, and KB5121611. The updates address multiple flaws, including CVE-2026-55007, a High-severity double-free vulnerability that could allow unauthorized network-based remote code execution.
Microsoft disclosed CVE-2026-77909, an Important Azure CycleCloud information-disclosure vulnerability caused by insufficiently protected credentials. A low-privileged authorized attacker could disclose credentials over a network without user interaction; Microsoft released a fix and credited XBREACH TEAM of XBreach.ai for coordinated disclosure.
Microsoft's September 2026 Windows 11 updates addressed CVE-2026-69784, a use-after-free elevation-of-privilege flaw in Windows Hello; CVE-2026-73017, a Windows Graphics Kernel remote-code-execution vulnerability; and CVE-2026-83979, a use-after-free elevation-of-privilege flaw in the Windows Biometric Service.
Microsoft's September 2026 updates resolved 20 vulnerabilities considered potentially wormable because they allow unauthenticated remote code execution without user interaction. The release included these flaws among fixes across Windows and other Microsoft products.
Microsoft received the CVE record for CVE-2026-65772, a deserialization-of-untrusted-data flaw in Microsoft Dynamics 365 On-Premises. An authorized low-privileged attacker could exploit the network-accessible vulnerability to execute code remotely without user interaction; Microsoft also added an MSRC Security Update Guide reference.
Microsoft received the CVE record for CVE-2026-69464, an execution-with-unnecessary-privileges flaw in Microsoft Office SharePoint. An authorized low-privileged attacker could elevate privileges over a network without user interaction; the CWE-250 vulnerability is rated CVSS 8.8.
Microsoft documented CVE-2026-47297, a deserialization-of-untrusted-data vulnerability in SQL Server that could allow an unauthorized attacker to execute code remotely over a network. The flaw is classified as CWE-502 and requires high attack complexity but no privileges or user interaction.
Microsoft received the CVE record for CVE-2026-69291, a heap-based buffer overflow in the Windows Volume Manager Extension Driver. The flaw could allow an unauthorized attacker to execute code remotely over a network with user interaction; it is classified as CWE-122 and has a CVSS vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Microsoft documented CVE-2026-69334, a heap-based buffer-overflow vulnerability in the Windows Volume Manager Extension Driver. An unauthenticated attacker could execute code remotely with user interaction; the flaw has low attack complexity and high confidentiality, integrity, and availability impact.
Microsoft received the CVE record for CVE-2026-69499, an integer-overflow vulnerability in the Windows Imaging Component that may allow an unauthorized attacker to execute code remotely over a network with user interaction. Microsoft published an MSRC Update Guide reference for the flaw, which is classified as CWE-190 and has high confidentiality, integrity, and availability impact.
Microsoft released security update KB5122882 for Windows Server 2022 and Azure Stack HCI 22H2. The update remediates multiple vulnerabilities, including the Critical remotely exploitable RCE flaws CVE-2026-68839, CVE-2026-69276, and CVE-2026-69408; Tenable rated hosts missing it Critical and reported no known public exploits at publication.
Microsoft released Security Update KB5123065 for Windows Server 2012 as part of its September 2026 security release. The update addresses remotely exploitable RCE vulnerabilities including CVE-2026-68839 in the Windows USB Mass Storage Class Driver, CVE-2026-69276 in uxtheme.dll, and CVE-2026-69408 in Windows Media Foundation; Tenable rated systems missing it Critical and reported no known exploits.
Microsoft released security update KB5123099 for Windows 10 version 1607 and Windows Server 2016. The update addresses multiple flaws, including CVE-2026-68839, a CVSS 9.8 Windows USB Mass Storage Class Driver remote-code-execution vulnerability, plus RCE risks in UxTheme and Windows Media Foundation.
Microsoft released the Windows 10 Extended Security Update KB5122878 for ESU-enrolled systems and Windows 10 Enterprise LTSC users. The update advanced Windows 10 to build 19045.7725 and Enterprise LTSC 2021 to build 19044.7725, incorporating September security fixes and resolving issues affecting Secure Boot targeting, BitLocker, Remote Desktop audio, Code Integrity, and OMA DM logging.
Microsoft's September 2026 KB5124008 update began gradually rolling out a Windows 11 setting that lets users position the taskbar on the left, top, right, or bottom of the display. The capability is delivered through Controlled Feature Rollout, so it is not immediately available on every updated device.
Tenable documented that Windows 11 23H2 update KB5122880 addresses CVE-2026-68839 in the Windows USB Mass Storage Class Driver, CVE-2026-69276 in uxtheme.dll, and CVE-2026-69408 in Windows Media Foundation. Each flaw could allow unauthorized remote code execution; Tenable classified systems missing the update as Critical and reported no known exploits at publication.
Microsoft released KB5124008 for Windows 11 24H2 and 25H2, advancing them to builds 26100.9445 and 26200.9445, and KB5122880 for version 23H2. The mandatory cumulative updates included security fixes and began phased delivery of features including Administrator Protection, taskbar and Start-menu changes, Process Isolation for Microsoft Execution Containers, and Autopilot device association.
Microsoft received the CVE record for CVE-2026-69465, a missing-authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code remotely over a network. The flaw is classified as CWE-862 and requires low privileges, low attack complexity, and no user interaction.
Microsoft's CVE record identified CVE-2026-69510 as a stack-based buffer overflow in Windows DHCP Server. An unauthorized attacker could remotely execute code over a network without privileges or user interaction, though exploitation requires high attack complexity.
Microsoft’s CVE record identified CVE-2026-69546 as a use-after-free vulnerability in Active Directory Domain Services. An unauthorized attacker could execute code remotely over a network without privileges or user interaction; exploitation has high attack complexity and high confidentiality, integrity, and availability impact.
Microsoft’s CVE record identified CVE-2026-69530 as a use-after-free flaw in the Windows Reliable Multicast Transport Driver (RMCAST). An unauthenticated attacker could execute code remotely over a network without user interaction; the vulnerability has high attack complexity but high confidentiality, integrity, and availability impact.
Microsoft received the CVE record for CVE-2026-66819, an SQL injection vulnerability in Microsoft SQL Server caused by improper neutralization of SQL-command elements. An authorized attacker could exploit it over a network to elevate privileges; the flaw is classified as CWE-89 and requires low privileges and low attack complexity.
Microsoft received the CVE record for CVE-2026-69442, a heap-based buffer overflow in Microsoft Office that could allow unauthenticated remote code execution with user interaction. The flaw is classified as CWE-122 and has a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Microsoft's September 2026 Patch Tuesday updates addressed CVE-2026-69829, a critical Windows Shell remote-code-execution vulnerability with a CVSS score of 9.8. The flaw requires low attack complexity and no privileges or user interaction for exploitation.
Microsoft released security updates addressing 973 vulnerabilities across Windows, Office, SQL Server, Exchange, SharePoint, Azure, and developer tools. The release included two exploited Windows elevation-of-privilege zero-days, CVE-2026-85880 and CVE-2026-81963, as well as Critical fixes affecting Windows Secure Kernel Mode, VBS components, Excel, and Word.
Microsoft's September 2026 updates addressed CVE-2026-62878 in Windows DNS Server, CVE-2026-62823 in Windows DHCP Server, CVE-2026-62893 in Windows Deployment Services, and CVE-2026-65789 in Windows DNS. The flaws include stack-based buffer overflow and use-after-free issues that can enable network-based remote code execution.
Microsoft documented CVE-2026-81963 as an actively exploited Windows Update Stack elevation-of-privilege vulnerability caused by improper link resolution before file access. A local authorized attacker can obtain SYSTEM privileges; Microsoft credited Romain Deperne and the Microsoft Threat Intelligence Centre for reporting the flaw.
Microsoft's September 2026 security updates included newly detailed critical cloud-service vulnerabilities: CVE-2026-70352 in Azure AI Language and CVE-2026-83711 in Azure Active Directory B2C, both CVSS 10.0; CVE-2026-80098 in Copilot Studio, CVSS 9.3; and CVE-2026-69857, an Azure Cosmos DB spoofing flaw rated CVSS 8.5. The reference reported no public exploitation for these vulnerabilities.
Microsoft's September 2026 Exchange Server updates addressed CVE-2026-69380, a CVSS 8.1 vulnerability that allows a low-privileged authenticated attacker to impersonate any user in an organization and take over mailboxes.
Microsoft released critical Servicing Stack Updates for Windows Server 2012, Windows Server 2012 R2, and Windows 10 version 1607/Windows Server 2016 as part of the September 2026 patch cycle.
Microsoft's September 2026 Patch Tuesday updates included CVE-2026-80097, a CVSS 8.6 Microsoft Authenticator improper-authentication privilege-escalation flaw, and the CVSS 9.8 remote-code-execution flaws CVE-2026-69595 in the Windows Services for NFS ONCRPC XDR Driver and CVE-2026-72979 in Windows DHCP Server. The latter two could permit unauthenticated network-based code execution.
The September 2026 updates were reported to include CVE-2026-78509 affecting Microsoft Outlook and CVE-2026-65669 associated with SQL Server Management Studio and its Copilot functionality. The reference warned that Outlook message-rendering or Reading Pane attack paths may reduce reliance on victims opening malicious attachments, and characterized the SSMS issue as involving authorization, prompt-handling, and AI-generated-action concerns.
Alongside the Windows 11 cumulative update, Microsoft published .NET 8.0.31 security update KB5126104, .NET 9.0.20 security update KB5126105, .NET Framework security update KB5126052, and Windows Malicious Software Removal Tool version 5.145 as KB890830.
Microsoft fixed several high-priority remote-code-execution vulnerabilities, including CVE-2026-69525 in Remote Desktop Services and CVE-2026-69730 in Windows DNS Server, both rated CVSS 9.8 and assessed as more likely to be exploited. The release also addressed CVE-2026-69676, a Critical Kerberos authentication-bypass RCE flaw rated CVSS 8.8 and assessed as more likely to be exploited.
Microsoft issued an optional Windows 11 preview release whose features were later incorporated into the September 2026 KB5124008 cumulative update.
Microsoft released optional preview update KB5120233 for Windows Server 2025. Its quality and non-security improvements, including network failover, Remote Desktop audio redirection, and Sysmon reliability changes, were later incorporated into KB5122871.
Microsoft reportedly patched approximately 620 vulnerabilities in the month preceding its September 2026 security release. This patch volume was cited as part of an accelerating increase in Microsoft's vulnerability remediation output.
Microsoft patched a then-record 570 vulnerabilities in a release two months before its September 2026 update. The September release subsequently exceeded that volume.
Microsoft previously disclosed the Administrator Protection feature through Windows 11 update KB5067036. The feature uses just-in-time privileges and profile separation to harden administrator accounts against elevation-of-privilege attacks.
Tenable published Nessus plugin 344797 (smb_nt_ms26_sep_ssms.nasl) to identify Windows systems with Microsoft SQL Server Management Studio installations affected by CVE-2026-65669. The plugin uses SMB or Registry enumeration and installed-software inventory data for detection.
Researcher Nightmare Eclipse published ShieldCrash, a purported proof-of-concept exploit that bypasses the patch for CVE-2026-69414 (ShieldBreak), a Microsoft Defender/Microsoft Malware Protection Engine privilege-escalation vulnerability.
Hungary’s National Cybersecurity Institute (NBSZ NKI) issued an alert on critical Microsoft vulnerabilities addressed in the September 2026 updates, citing widespread deployment and concerns over active exploitation. It urged organizations to promptly install available updates, highlighting CVE-2026-85880 and CVE-2026-81963.
CERT-FR published advisory CERTFR-2026-AVI-1147 covering multiple Microsoft Windows and Remote Desktop client vulnerabilities, including actively exploited CVE-2026-81963 and CVE-2026-85880. The advisory identified affected Windows client and server versions, supplied fixed-build thresholds, and urged administrators to deploy Microsoft's September security updates.
September 2026 updates included 22 critical Office-related vulnerabilities, 21 of them RCE flaws; reporting stated that 12 can be triggered through Outlook Reading Pane or Explorer Preview Pane without a user click. The affected issues include CVE-2026-77493 in Windows Graphics Component and CVE-2026-78510 in Word, both rated CVSS 9.8, as well as the Reading Pane-triggerable Outlook flaw CVE-2026-78509.
Microsoft disclosed CVE-2026-69806, an Important .NET elevation-of-privilege vulnerability involving exposure of sensitive information. A low-privileged local attacker in certain Linux environments could obtain the privileges of an affected process's user or service account; Microsoft rated it CVSS 7.0, assessed exploitation as less likely, and released a fix.
Microsoft disclosed CVE-2026-83941, a Critical CVSS 9.9 missing-authorization vulnerability in Entra ID that could allow a low-privileged authenticated attacker to elevate privileges remotely without user interaction. Microsoft stated that it fully mitigated the cloud-service flaw before publication, requires no customer action, and knew of no exploitation or prior public disclosure.
Microsoft disclosed CVE-2026-73018, a Critical heap-based buffer-overflow vulnerability in Graphic Fonts that could permit unauthenticated remote code execution if a user opens a specially crafted file. Microsoft rated it CVSS 8.8, provided an official fix, reported no public disclosure or known exploitation at publication, and credited namnp of Viettel Cyber Security and vietnq.
Microsoft disclosed CVE-2026-57099, an Important ASP.NET Core denial-of-service flaw caused by allocation of resources without limits or throttling. An unauthenticated remote attacker can cause high availability impact; Microsoft rated it CVSS 7.5, provided an official fix, and reported no public disclosure or known exploitation at original publication.
Microsoft disclosed CVE-2026-72978, an Important AD FS denial-of-service vulnerability caused by uncontrolled resource allocation (CWE-770). An unauthenticated network attacker could cause high availability impact; Microsoft provided an official fix and reported no known exploitation or prior public disclosure at original publication.
Microsoft disclosed CVE-2026-72986, a Critical Graphic Fonts remote-code-execution vulnerability involving heap-based buffer overflow and integer-overflow weaknesses. An unauthenticated attacker can exploit it if a user opens a specially crafted file; Microsoft assigned CVSS 8.8, provided a fix, and reported no known exploitation or prior public disclosure at original publication.
Microsoft disclosed CVE-2026-69900, an Important untrusted-pointer-dereference vulnerability in the Kernel Streaming WOW Thunk Service Driver. A locally authenticated low-privileged attacker could elevate to SYSTEM without user interaction; Microsoft rated it CVSS 7.8, assessed exploitation as unlikely, and provided an official fix.
Microsoft disclosed CVE-2026-69329, an Important BranchCache denial-of-service vulnerability involving an out-of-bounds read. An unauthenticated attacker could exploit it remotely without user interaction to cause high availability impact; Microsoft provided an official fix and reported no public disclosure or known exploitation at original publication.
Microsoft disclosed CVE-2026-69491, an Important heap-based buffer-overflow vulnerability in Windows Microsoft DirectMusic that can permit unauthenticated remote code execution over a network without user interaction. The flaw is rated CVSS 9.8; Microsoft assessed exploitation as unlikely, reported no public disclosure or known exploitation at original publication, and indicated that an official fix is available.
Microsoft disclosed CVE-2026-69624, an Important Active Directory Certificate Services vulnerability caused by incomplete disallowed-input validation (CWE-184). A low-privileged authenticated attacker could tamper with protected system data over a network without user interaction; Microsoft rated it CVSS 6.5, assessed exploitation as unlikely, and made an official fix available.
Microsoft disclosed CVE-2026-69576, a CWE-416 use-after-free vulnerability in Graphic Fonts that lets a locally authenticated low-privileged attacker obtain SYSTEM privileges without user interaction. Microsoft rated it CVSS 7.8, provided an official fix, and stated that it was neither publicly disclosed nor known to be exploited at original publication.
Microsoft disclosed CVE-2026-69516, a use-after-free elevation-of-privilege vulnerability in the Connected Devices Platform Service (Cdpsvc). A locally authenticated low-privileged attacker could elevate from Medium Integrity Level to Local Service by winning a race condition; Microsoft rated it CVSS 7.0, assessed exploitation as unlikely, and provided an official fix.
Microsoft disclosed CVE-2026-69439, an Important heap-based buffer-overflow vulnerability in .NET and Visual Studio triggered by processing a specially crafted Portable PDB file. Exploitation can execute code under the affected process's user or service account; Microsoft rated it CVSS 8.8, assessed exploitation as unlikely, and stated that an official fix is available.
CISA confirmed active exploitation of CVE-2026-81963 and CVE-2026-85880 and directed U.S. federal agencies to remediate both vulnerabilities by September 22. The flaws affect a Windows update-installation component and a Windows messaging system, respectively.
Microsoft documented CVE-2026-85880 as an actively exploited Windows ALPC heap-based buffer-overflow elevation-of-privilege flaw. An attacker executing code in a low-privilege AppContainer can escape the sandbox and gain SYSTEM privileges locally; Microsoft released a fix and credited Volexity and Proofpoint researchers Mark Kelly, David Galazin, and Jeremy Hedges.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
50 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcemicrosoft.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.