Back Tenable Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.
Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.
This month’s update includes patches for:
.NET and Visual Studio
Active Directory Certificate Services (AD CS)
Active Directory Domain Services
Active Directory Federation Services (AD FS)
Audio Video Control Transport Protocol
Connected Devices Platform Service (Cdpsvc)
Data Sharing Service Client
GitHub Copilot and Visual Studio Code
Internet Storage Name Service
Kernel Streaming WOW Thunk Service Driver
Microsoft Authenticator
Microsoft Azure Attestation service and Device Health Attestation Service
Microsoft COM for Windows
Microsoft Dynamics 365
Microsoft Graphics Component
Microsoft Install Service
Microsoft Local Security Authority Server (lsasrv)
Microsoft Office Access
Microsoft Office Excel
Microsoft Office Outlook
Microsoft Office PowerPoint
Microsoft Office Publisher
Microsoft Office SharePoint
Microsoft Office Word
Microsoft Standard XPS
Microsoft Teams for Android
Microsoft Trace Data Helper
Microsoft UxTheme Library (uxtheme.dll)
Microsoft WDAC OLE DB provider for SQL
Microsoft WebP Image Extension
Microsoft Windows Codecs Library
Microsoft Windows Media Foundation
Microsoft Windows PDF
Microsoft Windows SCSI Class System File
Microsoft Windows Component
Microsoft Windows Speech
Push Message Routing Service
Reliable Multicast Transport Driver (RMCAST)
Remote Desktop Gateway Service
Role: Windows Fax Service
Virtual Hard Disk (VHD) Miniport Driver
Volume Manager Driver
Windows AF_UNIX Socket Provider
Windows Accounts Control
Windows Ancillary Function Driver for WinSock
Windows Audio Service
Windows Authentication Methods
Windows Bind Filter Driver
Windows Biometric Service
Windows Bluetooth Port Driver
Windows Bluetooth Service
Windows Broadcast DVR User Service
Windows Broker Infrastructure Service
Windows CD-ROM Driver
Windows Camera Frame Server Monitor
Windows Cloud Files Mini Filter Driver
Windows Compressed Folder
Windows Connected User Experiences and Telemetry
Windows Container Manager Service
Windows Core Messaging
Windows Credential Guard
Windows Credential Providers
Windows DWM Core Library
Windows Defender Firewall Service
Windows Deployment Services
Windows Device Association Broker service
Windows Device Association Service
Windows Devices Human Interface
Windows Display Enhancement Service
Windows Distributed File System (DFS)
Windows Embedded Mode Service
Windows Encrypting File System (EFS)
Windows Enterprise App Management
Windows Error Reporting
Windows Event Logging Service
Windows Failover Cluster
Windows Fast FAT Driver
Windows File History Service
Windows Graphics Kernel
Windows HTTP Print Provider
Windows Host Guardian Service
Windows IKE Extension
Windows IP Address Management (IPAM) Service
Windows Image Acquisition
Windows Internet Connection Sharing (ICS)
Windows Kernel Mode Driver
Windows Key Distribution Center
Windows LDAP - Lightweight Directory Access Protocol
Windows License Manager
Windows Link Layer Topology Discovery Protocol
Windows MIDI Service Module
Windows Management Instrumentation
Windows Management Services
Windows Message Queuing
Windows Message Queuing Queue Manager
Windows Microsoft DirectMusic
Windows Mobile Broadband
Windows Modern Device Management (MDM)
Windows Modern Execution Server
Windows NFS Portmapper
Windows Network Connection Broker
Windows Network File System
Windows Online Certificate Status Protocol (OCSP)
Windows Overlay Filter
Windows Partition Management Driver
Windows Performance Monitor
Windows Power Dependency Coordinator
Windows Print Spooler Components
Windows Program Compatibility Assistant Service
Windows Push Notifications
Windows Raw Image Extension
Windows Remote Access Connection Manager
Windows Remote Desktop
Windows Remote Desktop Licensing Service
Windows Remote Desktop Protocol
Windows Remote Desktop Services
Windows Resilient File System (ReFS)
Windows Resilient File System (ReFS) Deduplication Service
Windows Routing and Remote Access Service (RRAS)
Windows SMB Server Network Transport Driver (srvnet.sys)
Windows Secure Kernel Mode
Windows Secure Socket Tunneling Protocol (SSTP)
Windows Security Health Service
Windows Services for NFS ONCRPC XDR Driver
Windows Setup Files Cleanup
Windows Spaceport.sys
Windows Storage Management Provider
Windows Storage Port Driver
Windows Storage Spaces Controller
Windows Task Scheduler
Windows USB Audio Class driver (usbaudio.sys)
Windows USB Hub Driver
Windows USB Mass Storage Class Driver
Windows USB Video Driver
Windows Universal Disk Format File System Driver (UDFS)
Windows Universal Plug and Play (UPnP) Device Host
Windows Virtual Trusted Platform Module
Windows Volume Manager Extension Driver
Windows Volume Shadow Copy
Windows Web Platform Storage
Windows WebClient Service
Windows Win32 Kernel Subsystem
Windows Wireless Networking
Windows Wireless Wide Area Network Service
Windows Work Folder Service
Windows exFAT File System
Windows iSCSI Target Service
Elevation of privilege (EoP) vulnerabilities accounted for 44.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 26.8%.
CVE-2026-81963 | Windows Update Stack elevation of privilege vulnerability
CVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.
Windows Update Stack contains a link following vulnerability. An attacker could exploit this vulnerability to elevate to SYSTEM privileges.
Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day.
CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability
CVE-2026-85880 is a EoP vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges.
There have been 16 vulnerabilities patched in ALPC since 2022, but this is the first to be included in Patch Tuesday in more than three years ( April 2023 ) and the second to be exploited as a zero-day since CVE-2023-21674 as part of the January 2023 Patch Tuesday .
CVE-2026-69380 | Microsoft Exchange Server elevation of privilege vulnerability
CVE-2026-69380 is an EoP in Microsoft Exchange Server. It received a CVSSv3 score of 8.1 and is rated as important. This is a missing authorization vulnerability. An authenticated attacker with access to a mailbox through a low-user privilege user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails as other Exchange users as well as access attachments. Despite the high CVSS score, this vulnerability is rated as “Exploitation Less Likely” according to the Microsoft Exploitability Index .
CVE-2026-69525 | Remote Desktop Services remote code execution vulnerability
CVE-2026-69525 is an RCE vulnerability affecting Remote Desktop Services. It received a CVSSv3 score of 9.8 and is rated as important. Successful exploitation of this flaw would allow an attacker to execute arbitrary code by exploiting a use-after-free flaw. Microsoft assesses this vulnerability as “Exploitation More Likely.”
In addition to CVE-2026-69525, three RCEs in Remote Desktop Services were also patched this month. While each were rated as important, they differed in their CVSS scoring and exploitability rating as noted in the table below:
CVE-2026-69730 | Windows DNS Server remote code execution vulnerability
CVE-2026-69730 is an RCE vulnerability affecting Windows DNS Server. It received a CVSSv3 score of 9.8 and is rated Critical. According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution. Microsoft assesses this flaw as “Exploitation More Likely.”
Eight additional RCEs in Windows DNS Server were patched this month, however they did not achieve the same exploitability assessment as CVE-2026-69730. These eight are outlined in the table below:
CVE-2026-69676 | Windows Kerberos remote code execution vulnerability
CVE-2026-69676 is an RCE vulnerability affecting Windows Kerberos. It received a CVSSv3 score of 8.8 and is rated critical. An attacker with low-level access could exploit this authentication bypass flaw using capture-replay against Windows Kerberos in order to execute arbitrary code. Microsoft assesses this flaw as “Exploitation More Likely.”
A list of all the plugins released for Microsoft’s September 2026 Patch Tuesday update can be found here . As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.
For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable .
Microsoft's September 2026 Security Updates
Tenable plugins for Microsoft September 2026 Patch Tuesday Security Updates
Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
