Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days
Sep 09, 2026
7 Mins Read
Moon
Summarize with:

September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days

Microsoft’s September 2026 Patch Tuesday release addresses 974 vulnerabilities, including two actively exploited zero-days. Both zero-days are Windows elevation of privilege flaws, and both were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Here’s a breakdown of vulnerability categories in this Patch Tuesday cycle:

September 2026 Patch Tuesday vulnerabilities, Microsoft

September 2026 Patch Tuesday vulnerabilities

This is Microsoft’s largest Patch Tuesday release on record, with 113 Critical-rated vulnerabilities. Defenders should prioritize the exploited Windows flaws first, then move quickly on network-reachable Remote Code Execution (RCE) flaws, Exchange Server, SharePoint Server, SQL Server, DNS Server, Remote Desktop Services, and business-critical cloud or identity services.

What Did Microsoft Patch in September 2026 Patch Tuesday?

Microsoft’s September 2026 security update covers a broad set of products and components, including Windows, Microsoft Office, SQL Server, SharePoint Server, Exchange Server, Azure services, Entra ID, Azure AD B2C, Remote Desktop Services, DNS Server, Skype for Business, .NET, Visual Studio, Microsoft Authenticator, and other Windows components.

Elevation of privilege flaws account for the largest share of the release, followed by remote code execution and information disclosure. Public release analysis lists hundreds of Windows vulnerabilities, more than 100 Office-related issues, over 60 SQL-related issues, 16 SharePoint Server vulnerabilities, and nine Exchange Server vulnerabilities.

The scale of the release makes prioritization essential. Security teams should not treat all 974 CVEs the same way. Exploited vulnerabilities, externally reachable services, privileged infrastructure, and systems tied to identity or software delivery should move first.

What Are September 2026 Patch Tuesday Zero-Days?

The September release includes two zero-day vulnerabilities, both marked as exploited in the wild. CISA added both to KEV on September 8, 2026, with a federal remediation due date of September 22, 2026.

CVE-2026-85880: Exploited Windows ALPC Elevation of Privilege

CVE-2026-85880 (CVSS 7.8) affects Windows Advanced Local Procedure Call (ALPC). Microsoft describes it as a heap-based buffer overflow that could allow a local attacker to gain SYSTEM privileges.

The main concern is its AppContainer escape capability. An attacker who already has code execution inside a low-privilege AppContainer could exploit the flaw locally to escape the sandbox and elevate privileges on the affected system. This makes the vulnerability especially relevant to endpoints and servers exposed to browser, Office, or other sandboxed workloads.

Details of CVE-2026-85880 (SOCRadar Vulnerability Intelligence), September 2026 Patch Tuesday

Details of CVE-2026-85880 (SOCRadar Vulnerability Intelligence)

CVE-2026-81963: Exploited Windows Update Stack Elevation of Privilege

CVE-2026-81963 (CVSS 7.8) affects the Windows Update Stack. The flaw involves improper link resolution before file access, allowing an authorized local attacker to elevate privileges to SYSTEM.

The Windows Update Stack is sensitive because update-related components run with elevated trust. The affected scope is narrower than the ALPC issue, but Windows 11 and Windows Server 2025 deployments should treat this as an urgent patching priority.

Details of CVE-2026-81963 (SOCRadar Vulnerability Intelligence), September 2026 Patch Tuesday

Details of CVE-2026-81963 (SOCRadar Vulnerability Intelligence)

Which Critical Microsoft CVEs Should Teams Prioritize?

With 113 Critical vulnerabilities in the September release, defenders should focus first on exploitability, exposure, and asset role.

High-priority CVEs include:

  • CVE-2026-70352 (CVSS 10.0): Azure AI Language elevation of privilege
  • CVE-2026-83711 (CVSS 10.0): Microsoft Azure Active Directory B2C elevation of privilege
  • CVE-2026-83941 (CVSS 9.9): Entra ID elevation of privilege
  • CVE-2026-69525 (CVSS 9.8): Remote Desktop Services remote code execution
  • CVE-2026-69730 (CVSS 9.8): Windows DNS Server remote code execution
  • CVE-2026-65669 (CVSS 9.6): Microsoft SQL Server elevation of privilege
  • CVE-2026-69465 (CVSS 8.8): Microsoft Office SharePoint remote code execution
  • CVE-2026-55007 (CVSS 8.1): Microsoft Exchange Server remote code execution

The Azure AI Language, Azure AD B2C, and Entra ID issues are service-side vulnerabilities for which Microsoft indicates no customer action is required. Customer-managed environments should still review tenant activity and monitor for supplemental Microsoft guidance.

Why Are DNS Server and RDS Vulnerabilities High Priority?

Windows DNS Server and Remote Desktop Services deserve special attention because they often sit close to identity, remote access, and core infrastructure.

CVE-2026-69730 is a Critical Windows DNS Server RCE vulnerability with a CVSS score of 9.8. DNS servers often support domain controllers, internal name resolution, and business-critical applications. Even when exposure is internal, compromise of DNS infrastructure can have broad operational impact.

CVE-2026-69525 affects Remote Desktop Services and is also rated CVSS 9.8. Microsoft assessed it as more likely to be exploited, and RDS remains a high-value target because of its role in administrative and remote access workflows.

ZDI also counted 20 vulnerabilities in this release that could be considered wormable because they allow remote code execution without authentication or user interaction.

What Other Microsoft Vulnerabilities Should Teams Watch?

Beyond the exploited zero-days and Critical RCEs, teams should review vulnerabilities affecting collaboration, cloud, identity, and developer environments.

High-priority areas include:

  • Exchange Server: Apply updates for Exchange environments and verify installation with supported tooling.
  • SharePoint Server: Prioritize externally reachable or business-critical SharePoint deployments.
  • SQL Server: Review SQL Server and SQL Server Management Studio exposure, especially where databases support production or build workflows.
  • Microsoft Office: Include Office and Office component fixes in endpoint patch cycles.
  • Azure and Entra services: Review Microsoft guidance to confirm whether fixes are service-side or require customer validation.
  • Remote access and infrastructure services: Prioritize RDS, DNS Server, DHCP, RRAS, SMB, Netlogon, Failover Cluster, and other network-facing Windows services where deployed.

How Should Teams Prioritize September 2026 Patch Tuesday?

Security teams should use a staged process based on exploitation status, exposure, and business criticality.

1. Patch the Exploited Zero-Days

Deploy fixes for CVE-2026-85880 and CVE-2026-81963 first. Treat both as post-compromise privilege escalation risks and review telemetry for suspicious local elevation activity.

2. Address Network-Reachable Critical RCEs

Prioritize RDS, DNS Server, DHCP Server, Netlogon, SMB, RRAS, Failover Cluster, and other services that may be reachable over the network.

3. Patch Exchange, SharePoint, and SQL Server

Move quickly on Exchange Server, SharePoint Server, and SQL Server updates, especially where systems are internet-facing, handle sensitive data, or support production workflows.

4. Validate Cloud and Identity Exposure

Review Azure, Entra ID, Azure AD B2C, Microsoft Authenticator, and related cloud-service guidance. Document service-side remediation where Microsoft handles the fix, and verify tenant activity where appropriate.

5. Complete the Remaining Updates

Finish deployment across Windows clients, servers, Office, .NET, Visual Studio, Skype for Business, developer tools, and remaining Microsoft products. Verify installation success rather than relying only on update approval.

How Can SOCRadar Help Prioritize Patch Tuesday Response?

Managing a Patch Tuesday release with hundreds of CVEs creates a visibility challenge. Security teams need to know which vulnerabilities are exploited, which assets are exposed, and which systems carry the highest business risk.

SOCRadar’s Cyber Threat Intelligence (CTI) module helps track exploited and high-risk Microsoft CVEs, CISA KEV status, exploitability changes, public disclosure, and advisory updates.

SOCRadar’s Attack Surface Management (ASM) module adds exposure context by identifying internet-facing assets, exposed services, vulnerable technologies, DNS records, and public infrastructure. Together, CTI and ASM help teams turn the September 2026 CVE list into a prioritized remediation plan.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

What Should Defenders Do Now?

Start by deploying the September 2026 Microsoft security updates for the two exploited zero-days, CVE-2026-85880 and CVE-2026-81963. Then prioritize Critical network-facing RCEs, DNS infrastructure, RDS, Exchange Server, SharePoint Server, SQL Server, and cloud or identity services that require customer-side validation.

Teams should also verify deployment completion, review telemetry for privilege escalation or unusual service behavior, and rescan exposed assets after patching. The full vendor list is available through Microsoft’s Security Update Guide release notes for September 2026.