Skip to content
September 2026 Microsoft Patch Tuesday

September 2026 Microsoft Patch Tuesday

Daily.Dev September 8, 2026

Microsoft's September 2026 Patch Tuesday addressed 964 CVEs, the largest release in its history, with 104 rated critical and 860 important. Two zero-day vulnerabilities exploited in the wild were patched: CVE-2026-81963 (Windows Update Stack elevation of privilege) and CVE-2026-85880 (Windows ALPC elevation of privilege), both with CVSSv3 7.8. Other notable flaws include CVE-2026-69380 (Exchange Server EoP), CVE-2026-69525 (Remote Desktop Services RCE, CVSS 9.8), CVE-2026-69730 (Windows DNS Server RCE, CVSS 9.8, critical), and CVE-2026-69676 (Windows Kerberos RCE, CVSS 8.8). Elevation of privilege bugs made up 44.7% of patches, remote code execution 26.8%. Tenable recommends prompt patching and regular vulnerability scanning.

Questions this post answers

Microsoft patched 964 CVEs in that release, the largest Patch Tuesday release in its history, with 104 rated critical and 860 rated important. Two zero-day vulnerabilities were exploited in the wild: CVE-2026-81963, a Windows Update Stack elevation of privilege flaw, and CVE-2026-85880, a Windows ALPC elevation of privilege flaw, both scoring 7.8 on CVSSv3. Security teams tracking record-breaking patch cycles can follow Windows CVE disclosures on daily.dev.

CVE-2026-85880 is an elevation of privilege vulnerability in Windows Advanced Local Procedure Call (ALPC), scoring 7.8 on CVSSv3, exploited in the wild as a zero-day allowing attackers to gain SYSTEM-level privileges. It is the first ALPC vulnerability included in Patch Tuesday in over three years, since April 2023, and only the second ALPC zero-day exploited since CVE-2023-21674 in January 2023. Developers securing Windows infrastructure can track recurring ALPC and kernel flaws on daily.dev.

CVE-2026-69730 is a critical remote code execution vulnerability in Windows DNS Server with a CVSSv3 score of 9.8, assessed by Microsoft as 'Exploitation More Likely.' An unauthenticated remote attacker could send a crafted packet exploiting a use-after-free flaw to achieve remote code execution. Eight additional Windows DNS Server RCEs were patched the same month with lower exploitability ratings. Admins prioritizing critical DNS server patches can monitor exploitability ratings via daily.dev.