Microsoft Released September 2026 Software Updates

Microsoft has released software updates as part of its September 2026 Patch Tuesday. The updates fix 966 security vulnerabilities in total, including 2 actively exploited zero-day vulnerabilities.

The breakdown of the vulnerabilities are as follows:

  • 438 elevation of privilege

  • 258 remote code execution

  • 173 information disclosure

  • 16 spoofing

  • 56 denial of service

  • 19 security feature bypass

The actively exploited zero-days are as follows:

  • CVE-2026-81963 - vulnerability in Windows Update Stack that can lead to elevation of privilege

  • CVE-2026-85880 - vulnerability in Windows Advanced Local Procedure Call that can lead to elevation of privilege

Why You Should Care?

These vulnerabilities are flaws that have been identified in Microsoft software, and now that they are publicly known, attackers will try to exploit as many targets as possible before users apply the fix. This makes it extra dangerous, and needs to be addressed as soon as possible.

In this case, two zero-day vulnerabilities are being actively exploited, which means it is only a matter of time before the attackers compromise your business. Now that patches are available, it is critical to apply the patches as soon as possible to avoid getting compromised.

What Should You Do?

  • Test the patches ASAP at your organization, and make sure it does not break any business applications

  • Prioritize the three zero-day vulnerabilities

  • Roll out the rest of the Patch Tuesday updates

References

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/

Next
Next

IDScan breached and more - Sept 13, 2026