Back Petri Microsoft's September 2026 Patch Tuesday Fixes 114 Critical Flaws
Microsoft's latest update fixes hundreds of security issues, but several high-severity flaws affecting Exchange and other products are likely to draw the most attention from security teams.
Microsoft addressed 974 vulnerabilities in its September 2026 Patch Tuesday release.
The update includes fixes for 114 Critical vulnerabilities across Windows and Microsoft enterprise products.
High-severity flaws affecting Exchange Server, SharePoint, SQL Server, and Remote Desktop Services are among the most notable fixes.
Microsoft has released the September 2026 Patch Tuesday Updates for all supported versions of Windows 11 and Windows 10. This month, the company rolled out 974 patches to address several vulnerabilities in Windows, Office, Azure, Active Directory, Exchange Server, Remote Desktop Client and Server, SQL Server, Windows Hello, Microsoft Defender, and other components.
Microsoft has already fixed 2,760 vulnerabilities this year, which is more than double the number from 2025. On the quality and experience update front, Microsoft has released several improvements for Windows 11 versions 26H1 as well as 25H2 and 24H2.
974 vulnerabilities fixed in the September 2026 Patch Tuesday updates
According to the Zero Day Initiative , Microsoft has fixed 114 security flaws rated as “Critical,” with the rest being rated Important in terms of severity. Here’s a list of the most notable vulnerabilities Microsoft addressed in September:
CVE-2026-85880 : This is an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC). This security vulnerability could be exploited by attackers to gain SYSTEM privileges.
CVE-2026-81963 : This is a privilege escalation vulnerability in the Windows Update Stack with a CVSS score of 7.8. Microsoft has warned that this flaw could allow attackers to gain SYSTEM-level access.
CVE-2026-55007 : This is one of the nine Exchange Server vulnerabilities disclosed this month. An unauthenticated attacker could achieve remote code execution on an affected Exchange Server by sending an email with a malicious Visio attachment.
CVE-2026-69465 : This is an authorization vulnerability in Microsoft SharePoint that carries a CVSS score of 8.8. Cybercriminals could exploit this flaw to execute code over an enterprise network.
CVE-2026-65669 : This is a 9.6-rated injection vulnerability in SQL Server that allows an unauthorized attacker to elevate privileges over a network. It could be exploited by hackers when a user submits instructions through SQL Copilot.
CVE-2026-69525 : This remote execution bug in Remote Desktop Services carries a CVSS score of 9.8.
You can find the full list of CVEs addressed in the September 2026 Patch Tuesday Updates below:
Quality and experience updates
Microsoft released the KB5124008 update for PCs running Windows 11 versions 26H1 and 25H2/24H2. This release brings additionalhigh-confidencee device targeting data, which increases coverage of devices eligible to automatically receive new Secure Boot certificates. Microsoft will continue certificate deployment through Windows updates across supported PCs and non-managed business devices in the few months.
The KB5124008 update enhances the diagnostics logging experience for the OMA-DM client. It provides additional information to help troubleshoot device management server connection issues. Microsoft has also fixed a bug that could cause Microsoft Outlook and Teams to unexpectedly close on Arm64-based PCs.
Windows Update testing and best practices
Microsoft advises organizations to perform thorough testing to confirm that updates do not compromise the stability of their production systems. However, it is crucial to deploy Patch Tuesday updates to proactively address potential threats.
Additionally, IT administrators must prioritize backing up their systems before applying updates, utilizing the built-in backup features of Windows and Windows Server. These features allow for the restoration of specific files and folders or entire systems as required.
Last but not least, organizations should consistently monitor their systems for anomalies or unexpected behaviors. Regular monitoring is essential for staying vigilant against emerging risks and adopting appropriate security measures.
Rabia has a master's degree in Software Engineering and she has years of experience writing professionally Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on t...
How to Use Windows Memory Diagnostic Tool and How Much You Can Trust the Result Brien Posey Jul 14, 2026
Windows 11’s Low Latency Profile Fixes One of the Most Annoying Issues in File Explorer Russell Smith Jun 15, 2026
First Ring Daily: It’s a Windows Thing Laurent Giret Oct 24, 2025
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
