Skip to content
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Tenable Research Special Operations September 8, 2026

Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.

Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.

This month’s update includes patches for:

.NET and Visual Studio

Active Directory Certificate Services (AD CS)

Active Directory Domain Services

Active Directory Federation Services (AD FS)

Audio Video Control Transport Protocol

Connected Devices Platform Service (Cdpsvc)

Data Sharing Service Client

GitHub Copilot and Visual Studio Code

Internet Storage Name Service

Kernel Streaming WOW Thunk Service Driver

Microsoft Authenticator

Microsoft Azure Attestation service and Device Health Attestation Service

Microsoft COM for Windows

Microsoft Dynamics 365

Microsoft Exchange Server

Microsoft Graphics Component

Microsoft Install Service

Microsoft Local Security Authority Server (lsasrv)

Microsoft Office Access

Microsoft Office Excel

Microsoft Office Outlook

Microsoft Office PowerPoint

Microsoft Office Publisher

Microsoft Office SharePoint

Microsoft Office Word

Microsoft Standard XPS

Microsoft Teams for Android

Microsoft Trace Data Helper

Microsoft UxTheme Library (uxtheme.dll)

Microsoft WDAC OLE DB provider for SQL

Microsoft WebP Image Extension

Microsoft Windows Codecs Library

Microsoft Windows Media Foundation

Microsoft Windows PDF

Microsoft Windows SCSI Class System File

Microsoft Windows Component

Microsoft Windows Speech

Push Message Routing Service

Reliable Multicast Transport Driver (RMCAST)

Remote Desktop Client

Remote Desktop Gateway Service

Role: Windows Fax Service

Virtual Hard Disk (VHD) Miniport Driver

Volume Manager Driver

Windows AF_UNIX Socket Provider

Windows Accounts Control

Windows Ancillary Function Driver for WinSock

Windows Audio Service

Windows Authentication Methods

Windows Bind Filter Driver

Windows Biometric Service

Windows Bluetooth Port Driver

Windows Bluetooth Service

Windows Broadcast DVR User Service

Windows Broker Infrastructure Service

Windows CD-ROM Driver

Windows Camera Frame Server Monitor

Windows Cloud Files Mini Filter Driver

Windows Compressed Folder

Windows Connected User Experiences and Telemetry

Windows Container Manager Service

Windows Core Messaging

Windows Credential Guard

Windows Credential Providers

Windows DWM Core Library

Windows Defender Firewall Service

Windows Deployment Services

Windows Device Association Broker service

Windows Device Association Service

Windows Devices Human Interface

Windows Display Enhancement Service

Windows Distributed File System (DFS)

Windows Embedded Mode Service

Windows Encrypting File System (EFS)

Windows Enterprise App Management

Windows Error Reporting

Windows Event Logging Service

Windows Failover Cluster

Windows Fast FAT Driver

Windows File History Service

Windows Graphics Kernel

Windows HTTP Print Provider

Windows Host Guardian Service

Windows IKE Extension

Windows IP Address Management (IPAM) Service

Windows Image Acquisition

Windows Imaging Component

Windows Internet Connection Sharing (ICS)

Windows Kernel Mode Driver

Windows Key Distribution Center

Windows LDAP - Lightweight Directory Access Protocol

Windows License Manager

Windows Link Layer Topology Discovery Protocol

Windows MIDI Service Module

Windows Management Instrumentation

Windows Management Services

Windows Message Queuing

Windows Message Queuing Queue Manager

Windows Microsoft DirectMusic

Windows Mobile Broadband

Windows Modern Device Management (MDM)

Windows Modern Execution Server

Windows NFS Portmapper

Windows Network Connection Broker

Windows Network File System

Windows Online Certificate Status Protocol (OCSP)

Windows Overlay Filter

Windows Partition Management Driver

Windows Performance Monitor

Windows Power Dependency Coordinator

Windows Print Spooler Components

Windows PrintWorkflowUserSvc

Windows Program Compatibility Assistant Service

Windows Push Notifications

Windows Raw Image Extension

Windows Remote Access Connection Manager

Windows Remote Desktop

Windows Remote Desktop Licensing Service

Windows Remote Desktop Protocol

Windows Remote Desktop Services

Windows Resilient File System (ReFS)

Windows Resilient File System (ReFS) Deduplication Service

Windows Routing and Remote Access Service (RRAS)

Windows SMB Server Network Transport Driver (srvnet.sys)

Windows Secure Kernel Mode

Windows Secure Socket Tunneling Protocol (SSTP)

Windows Security Center

Windows Security Health Service

Windows Services for NFS ONCRPC XDR Driver

Windows Setup Files Cleanup

Windows Spaceport.sys

Windows Storage Management Provider

Windows Storage Port Driver

Windows Storage Spaces Controller

Windows Task Scheduler

Windows USB Audio Class driver (usbaudio.sys)

Windows USB Hub Driver

Windows USB Mass Storage Class Driver

Windows USB Video Driver

Windows Universal Disk Format File System Driver (UDFS)

Windows Universal Plug and Play (UPnP) Device Host

Windows VHD miniport driver

Windows Virtual Trusted Platform Module

Windows Volume Manager Extension Driver

Windows Volume Shadow Copy

Windows Web Platform Storage

Windows WebClient Service

Windows Win32 Kernel Subsystem

Windows Wireless Networking

Windows Wireless Wide Area Network Service

Windows Work Folder Service

Windows exFAT File System

Windows iSCSI Target Service

Elevation of privilege (EoP) vulnerabilities accounted for 44.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 26.8%.

CVE-2026-81963 | Windows Update Stack elevation of privilege vulnerability

CVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.

Windows Update Stack contains a link following vulnerability. An attacker could exploit this vulnerability to elevate to SYSTEM privileges.

Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day.

CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability

CVE-2026-85880 is a EoP vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges.

There have been 16 vulnerabilities patched in ALPC since 2022, but this is the first to be included in Patch Tuesday in more than three years ( April 2023 ) and the second to be exploited as a zero-day since CVE-2023-21674 as part of the January 2023 Patch Tuesday .

CVE-2026-69380 | Microsoft Exchange Server elevation of privilege vulnerability

CVE-2026-69380 is an EoP in Microsoft Exchange Server. It received a CVSSv3 score of 8.1 and is rated as important. This is a missing authorization vulnerability. An authenticated attacker with access to a mailbox through a low-user privilege user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails as other Exchange users as well as access attachments. Despite the high CVSS score, this vulnerability is rated as “Exploitation Less Likely” according to the Microsoft Exploitability Index .

CVE-2026-69525 | Remote Desktop Services remote code execution vulnerability

CVE-2026-69525 is an RCE vulnerability affecting Remote Desktop Services. It received a CVSSv3 score of 9.8 and is rated as important. Successful exploitation of this flaw would allow an attacker to execute arbitrary code by exploiting a use-after-free flaw. Microsoft assesses this vulnerability as “Exploitation More Likely.”

In addition to CVE-2026-69525, three RCEs in Remote Desktop Services were also patched this month. While each were rated as important, they differed in their CVSS scoring and exploitability rating as noted in the table below:

CVE-2026-69730 | Windows DNS Server remote code execution vulnerability

CVE-2026-69730 is an RCE vulnerability affecting Windows DNS Server. It received a CVSSv3 score of 9.8 and is rated Critical. According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution. Microsoft assesses this flaw as “Exploitation More Likely.”

Eight additional RCEs in Windows DNS Server were patched this month, however they did not achieve the same exploitability assessment as CVE-2026-69730. These eight are outlined in the table below:

CVE-2026-69676 | Windows Kerberos remote code execution vulnerability

CVE-2026-69676 is an RCE vulnerability affecting Windows Kerberos. It received a CVSSv3 score of 8.8 and is rated critical. An attacker with low-level access could exploit this authentication bypass flaw using capture-replay against Windows Kerberos in order to execute arbitrary code. Microsoft assesses this flaw as “Exploitation More Likely.”

A list of all the plugins released for Microsoft’s September 2026 Patch Tuesday update can be found here . As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.

For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable .

Microsoft's September 2026 Security Updates

Tenable plugins for Microsoft September 2026 Patch Tuesday Security Updates

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.