Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Microsoft September 2026 Patch Tuesday fixes 966 flaws, including 2 actively exploited zero-days.
Summary
Microsoft's September 2026 Patch Tuesday addresses a record-breaking 966 vulnerabilities, with 105 classified as 'Critical'. Notably, two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which allow for local privilege escalation to SYSTEM, were actively exploited in the wild. This massive update follows Microsoft's adoption of an AI-powered vulnerability discovery system.
Full text
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days By Lawrence Abrams September 8, 2026 02:18 PM 0 Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. This Patch Tuesday addresses 105 "Critical" vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security feature bypass. The approximate number of bugs in each vulnerability category is listed below: 438 Elevation of Privilege Vulnerabilities 19 Security Feature Bypass Vulnerabilities 258 Remote Code Execution Vulnerabilities 173 Information Disclosure Vulnerabilities 56 Denial of Service Vulnerabilities 16 Spoofing Vulnerabilities When BleepingComputer reports on Patch Tuesday security updates, we only count vulnerabilities released by Microsoft on Patch Tuesday itself. Therefore, today's total does not include 204 flaws fixed earlier this month, including vulnerabilities in Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Microsoft Edge (Chromium-based), Microsoft Fabric, and Power Automate. This Patch Tuesday is Microsoft's largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August. The increase in Patch Tuesday security updates comes after Microsoft began using an AI-powered vulnerability discovery system to identify more security flaws across its software products. To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5124008 & KB5122880 cumulative updates and the Windows 10 KB5122878 extended security update. Microsoft patches 2 zero-days This month's Patch Tuesday fixes two actively exploited zero-day vulnerabilities. Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available. The actively exploited zero-day vulnerabilities addressed during this the September 2026 Patch Tuesday are: CVE-2026-81963 - Windows Update Stack Elevation of Privilege Vulnerability Microsoft has patched an actively exploited elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges. "Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.," warns Microsoft. The flaws were credited to Romain Deperne and the Microsoft Threat Intelligence Centre (MSTIC). No details have been shared on how the flaw was exploited in attacks. CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Microsoft has fixed a Windows Advanced Local Procedure Call (ALPC) flaw that was exploited in attacks to gain SYSTEM privileges. "Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally," explains Microsoft. Microsoft has not shared any details on how this flaw was exploited in attacks. The flaw were discovered by Volexity and Mark Kelly, David Galazin, Jeremy Hedges with Proofpoint Recent updates from other companies Other vendors who released updates or advisories in August 2026 include: Adobe released a security update for max-severity zero-day Adobe Commerce vulnerability dubbed StyleSmuggler that was exploited in attacks to backdoor websites. Cisco released security updates for numerous products, including Cisco IOS XR, Cisco Nexus 9000 Series Switches, and Cisco Phones. ConnectWise shared mitigations for a ScreenConnect Remote Access vulnerability that it plans to patch later this week. CrowdStrike warned customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting after an anonymous researcher released a zero-day flaw for the software. Google released Chrome security updates for an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. Hewlett Packard Enterprise (HPE) patched a critical RCE vulnerability in the ArubaOS-CX network operating system. MicroTik released security updates for two actively exploited flaws used to hijack devices over SSH. N-able released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. The flaw is believed to potentially exploited in attacks. Plex released security updates for multiple vulnerabilities this week, urging customers to install them as soon as possible without providing any further details. SAP released the September security updates for numerous products, including a maximum-severity "OVERPASS" flaw in the SAP Kernel code. SonicWall released security updates for two SMA1000 zero-day vulnerabilities that are being chained in RCE attacks. The September 2026 Patch Tuesday Security Updates Below is the complete list of resolved vulnerabilities in the September 2026 updates. Note, this report does include the flaws fixed earlier this month. To access the full description of each vulnerability and the systems it affects, you can view the full report here. Tag CVE ID CVE Title Severity .NET CVE-2026-69805 .NET Elevation of Privilege Vulnerability Important .NET CVE-2026-58649 .NET Information Disclosure Vulnerability Important .NET CVE-2026-69806 .NET Elevation of Privilege Vulnerability Important .NET and Visual Studio CVE-2026-69439 .NET and Visual Studio Elevation of Privilege Vulnerability Important Active Directory Certificate Services (AD CS) CVE-2026-69821 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability Important Active Directory Certificate Services (AD CS) CVE-2026-69624 Active Directory Certificate Services (AD CS) Tampering Vulnerability Important Active Directory Certificate Services (AD CS) CVE-2026-62810 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability Important Active Directory Certificate Services (AD CS) CVE-2026-69395 Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability Important Active Directory Domain Services CVE-2026-62762 Windows Active Directory Domain Services Denial of Service Vulnerability Important Active Directory Domain Services CVE-2026-62813 Windows Active Directory Domain Services Remote Code Execution Vulnerability Important Active Directory Domain Services CVE-2026-69809 Windows Active Directory Domain Services Denial of Service Vulnerability Important Active Directory Domain Services CVE-2026-69359 Active Directory Domain Services Elevation of Privilege Vulnerability Important Active Directory Domain Services CVE-2026-69524 Windows Active Directory Domain Services Remote Code Execution Vulnerability Important Active Directory Domain Services CVE-2026-69546 Windows Active Directory Domain Services Remote Code Execution Vulnerability Important Active Directory Federation Services (AD FS) CVE-2026-72978 Active Directory Federation Services (AD FS) Denial of Service Vulnerability Important ASP.NET Core CVE-2026-57099 ASP.NET Core Denial of Service Vulnerability Important ASP.NET Core CVE-2026-69304 ASP.NET Core Denial of Service Vulnerability Important Audio Video Control Transport Protocol CVE-2026-69401 Audio Video Control Transport Protocol Elevation of Privilege Vulnerability Important Azure AI Language CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability Critical Azure Arc CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability Important Azure Cosmos DB CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability Critical Azure CycleCloud CVE-2026-77909 Azure CycleCloud Information Disclosure Vulnerability Important Azure HDInsights CVE-2026-81349 Azure HDInsight Ambari Elevation of Privilege Vulnerability Important Bra
Indicators of Compromise
- cve — CVE-2026-81963
- cve — CVE-2026-85880