Back to Feed
VulnerabilitiesSep 8, 2026

Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

Microsoft releases largest-ever Patch Tuesday with 974 vulnerabilities, including 2 zero-days.

Summary

Microsoft's September 2026 Patch Tuesday addresses a record-breaking 974 vulnerabilities, with 113 critical and 860 important flaws. Two of these vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are zero-days that have been actively exploited in the wild and are now listed on CISA's Known Exploited Vulnerabilities Catalog. Adobe also released a patch for a critical vulnerability in Adobe Commerce, CVE-2026-75650, which is also being actively exploited.

Full text

Table of ContentsMicrosoft Patch Tuesday for September2026Adobe Patch for September 2026Zero-day Vulnerabilities Patched inSeptemberPatch Tuesday EditionCritical Severity Vulnerabilities Patched inSeptemberPatch Tuesday EditionOther Microsoft Vulnerability HighlightsMicrosoft Release SummaryQualys Monthly Webinar Series Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August. Microsoft Patch Tuesday for September 2026 This month’s release addresses 974 vulnerabilities, including 113 critical and 860 important-severity vulnerabilities. In this month’s updates, Microsoft has addressed two vulnerabilities that have been exploited in the wild. Microsoft has not addressed any vulnerabilities in Microsoft Edge (Chromium-based) in this month’s update. Microsoft Patch Tuesday, September edition, includes updates for vulnerabilities in Windows HTTP.sys, Windows Hyper-V, GitHub Copilot, and Visual Studio Code, Copilot Studio, Data Sharing Service Client, Entra ID, Microsoft Exchange Server, and more. This month’s release includes fixes for several high-severity issues that could potentially enable remote code execution, privilege escalation, or denial-of-service attacks. As always, timely patch deployment is crucial to reduce exposure and ensure systems remain resilient against exploitation attempts. The September 2026 Microsoft vulnerabilities are classified as follows: Vulnerability CategoryQuantitySeveritiesSpoofing Vulnerability16Critical: 1Important: 15Denial of Service Vulnerability56Important: 56Elevation of Privilege Vulnerability438Critical: 27Important: 411 Information Disclosure Vulnerability173Critical: 2Important: 171 Remote Code Execution Vulnerability253Critical: 82Important: 171 Security Feature Bypass Vulnerability19Critical: 1Important: 18 Adobe Patch for September 2026 Adobe has released only one security advisory addressing a single vulnerability affecting Adobe Commerce. CVE-2026-75650 is a critical-severity vulnerability that may lead to arbitrary code execution if exploited. CISA also acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog and urged users to patch it before September 22, 2026. Zero-day Vulnerabilities Patched in September Patch Tuesday Edition CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability A link following flaw in the Windows Update Stack may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CISA added the CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026. CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows ALPC may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CISA added the CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026. Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition CVE-2026-58599: HEVC Video Extensions Remote Code Execution Vulnerability The heap-based buffer overflow flaw in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code locally. CVE-2026-62906: Microsoft Discovery Studio Information Disclosure Vulnerability Improper neutralization of special elements in data query logic within Microsoft Discovery Studio may allow an unauthenticated attacker to disclose information over a network. CVE-2026-62916: Microsoft Entra ID Elevation of Privilege Vulnerability An authentication bypass using an alternate path or channel in Microsoft Entra ID may allow an unauthenticated attacker to elevate privileges over a network. CVE-2026-65669: Microsoft SQL Server Elevation of Privilege Vulnerability The code injection flaw in SQL Server may allow an unauthenticated attacker to elevate privileges over a network. CVE-2026-65772: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability The deserialization of untrusted data in Microsoft Dynamics 365 may allow an authenticated attacker to execute code over a network. CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network. CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network. CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network. CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine. CVE-2026-81948, CVE-2026-81951, & CVE-2026-81959: Microsoft Excel Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally. CVE-2026-69530, CVE-2026-78449, & CVE-2026-78450: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability The use-after-free flaw in the Reliable Multicast Transport Driver (RMCAST) may allow an unauthenticated attacker to execute code over a network. CVE-2026-69740, CVE-2026-69784, & CVE-2026-69864: Windows Hello Elevation of Privilege Vulnerability The use-after-free in Windows Hello may allow an authenticated attacker to elevate privileges locally. CVE-2026-72986 & CVE-2026-73018: Graphic Fonts Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Graphic Fonts may allow an unauthenticated attacker to execute code over a network. CVE-2026-73006 & CVE-2026-78439: Microsoft Office Graphics Component Remote Code Execution Vulnerability The stack-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network. CVE-2026-69285 & CVE-2026-78505: Microsoft Office Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office may allow an unauthenticated attacker to execute code over a network. CVE-2026-78509 & CVE-2026-78510: Microsoft Office Outlook Remote Code Execution Vulnerability The heap-based buffer overflow flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network. CVE-2026-67631 & CVE-2026-67643: Microsoft SQL Server Remote Code Execution Vulnerability The heap-based buffer overflow flaw in SQL Server may allow an authenticated attacker to execute code over a network. CVE-2026-69710 & CVE-2026-69799: Windows Hello Elevation of Privilege Vulnerability A race condition in Windows Hello may allow an authenticated attacker to elevate privileges locally. CVE-2026-69820 & CVE-2026-81354: Windows Hello Elevation of Privilege Vulnerability The heap-based buffer overflow flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally. CVE-2026-70203 & CVE-2026-7296

Indicators of Compromise

  • cve — CVE-2026-75650
  • cve — CVE-2026-81963
  • cve — CVE-2026-85880
  • cve — CVE-2026-58599

Entities

Microsoft (vendor)Adobe (vendor)Adobe Commerce (product)Windows Update Stack (product)Windows Advanced Local Procedure Call (product)HEVC Video Extensions (product)