Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Microsoft released its September 2026 Patch Tuesday security updates on September 8, addressing 973 vulnerabilities, including two zero-days already exploited in attacks.

The release spans Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure, and developer tools, requiring organizations to coordinate remediation across endpoints, servers, and enterprise application environments.

Microsoft’s release notes attribute 723 addressed vulnerabilities to Windows, 111 to Office, 62 to SQL, 22 to developer tools, 16 to SharePoint Server and nine to Exchange Server.

Elevation of Privilege vulnerabilities dominated Microsoft’s September 2026 Patch Tuesday release, accounting for nearly half of all listed issues, followed by Remote Code Execution flaws.

Vulnerability Impact Count
Elevation of Privilege 438
Remote Code Execution (RCE) 258
Information Disclosure 173
Denial of Service (DoS) 56
Security Feature Bypass 19
Spoofing 16
Tampering 13
Total 973

The company separately lists 25 republished non-Microsoft CVEs, which should not be confused with the headline total of 974 Microsoft vulnerabilities.

Two Windows Zero-Days Under Active Exploitation

The first exploited flaw, CVE-2026-85880, affects Windows Advanced Local Procedure Call (ALPC) and permits elevation of privilege. Microsoft classifies it as Important and identifies customer action as required.

Although the summary confirms exploitation, it does not identify the attackers, targeted organizations, or exploitation chain. For defenders, the exploitation flag makes this an immediate patching concern despite its Important rating.

The second zero-day, CVE-2026-81963, is an Important-rated elevation-of-privilege vulnerability in Windows Update Stack. Check Point’s advisory describes improper link resolution before file access, commonly called link following, that allows an authorized attacker to elevate privileges locally. This is relevant to post-compromise activity: an attacker with existing access could use the weakness to obtain greater control over an affected system.

Both vulnerabilities are marked as exploited but not publicly disclosed in the Security Update Guide export. Those fields are not contradictory: private exploitation can occur before a vulnerability becomes publicly known.

For administrators, the central lesson is practical. Limiting emergency deployment to Critical-rated vulnerabilities would overlook both confirmed zero-days in this release.

Critical Fixes Across Windows and Office

Several Critical vulnerabilities affect Windows security components. CVE-2026-83939 addresses elevation of privilege in Windows Secure Kernel Mode, while CVE-2026-83498 affects Virtualization-Based Security (VBS) Enclave privileges.

Another VBS-related issue, CVE-2026-83501, involves information disclosure. All three Critical entries require customer action, making them candidates for early compatibility testing and deployment alongside the exploited vulnerabilities.

Microsoft Office also receives Critical remote-code-execution fixes, including CVE-2026-81959 and CVE-2026-81953 in Excel, and CVE-2026-81952 in Word. The export additionally lists CVE-2026-85875 as an Important Excel information-disclosure vulnerability. Organizations should assess installed Office products separately rather than treating completed Windows updates as evidence that productivity applications are patched.

Other notable remote-code-execution vulnerabilities include CVE-2026-85877 in Windows Print Spooler, CVE-2026-83997 in Windows Message Queuing, and CVE-2026-83998 in Remote Desktop Client.

All three are rated Important and require customer action. Their titles identify the affected components and potential impact, but do not establish that exploitation is unauthenticated or requires no user interaction.

A substantial cluster of elevation-of-privilege entries affects Windows Biometric Service. Additional fixes cover Windows Kernel, NTFS, Error Reporting and the Resilient File System Deduplication Service.

The breadth of these entries reinforces the need to map advisories to deployed systems, rather than selecting a handful of familiar component names and assuming the remaining exposure is negligible.

This month’s release also includes availability and integrity issues. CVE-2026-84001 affects Windows Key Distribution Center through denial of service, while CVE-2026-83989 targets the Services for NFS ONCRPC XDR driver with the same impact. CVE-2026-83991 addresses tampering in Windows Cloud Files Mini Filter Driver. Each vulnerability carries an Important rating.

Developer environments need attention as well. CVE-2026-84003 addresses spoofing in Microsoft Authentication Library (MSAL) for Node.js, while CVE-2026-83948 covers remote code execution in Microsoft Azure CLI.

Both require customer action. Conversely, the export marks Critical Entra ID vulnerability CVE-2026-83941 as requiring no customer action, illustrating why remediation requirements must be checked individually.

Microsoft states that Windows 10 and Windows 11 security updates are cumulative and directs administrators to the Microsoft Update Catalog. Its release guidance also emphasizes installing the latest servicing stack update. Administrators should review the listed known issues, particularly for Exchange, SQL Server, and Windows Server, before approving production changes.

Use representative test and pilot groups, then expand deployment while monitoring application health. Microsoft Intune update rings support staged rollouts, installation deadlines, and restart settings. Confirm successful installation and required restarts, and investigate failed or offline devices.

The post Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days appeared first on Cyber Security News.