Full Report
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain ServicesActive Directory Federation Services (AD FS)Audio Video Control Transport ProtocolAzure ArcAzure CycleCloudAzure HDInsightsBranchCacheConnected Devices Platform Service (Cdpsvc)Data Sharing Service ClientGitHub Copilot and Visual Studio CodeGraphic FontsHID class driverIP HelperInternet Storage Name ServiceKernel Streaming WOW Thunk Service DriverMicrosoft AccountMicrosoft AuthenticatorMicrosoft Azure Attestation service and Device Health Attestation ServiceMicrosoft Azure CLIMicrosoft COM for WindowsMicrosoft Dynamics 365Microsoft Exchange ServerMicrosoft Graphics ComponentMicrosoft Install ServiceMicrosoft JScriptMicrosoft Local Security Authority Server (lsasrv)Microsoft OfficeMicrosoft Office AccessMicrosoft Office ExcelMicrosoft Office OutlookMicrosoft Office PowerPointMicrosoft Office PublisherMicrosoft Office SharePointMicrosoft Office WordMicrosoft Standard XPSMicrosoft Teams for AndroidMicrosoft Trace Data HelperMicrosoft UxTheme Library (uxtheme.dll)Microsoft WDAC OLE DB provider for SQLMicrosoft WebP Image ExtensionMicrosoft Windows Codecs LibraryMicrosoft Windows Media FoundationMicrosoft Windows PDFMicrosoft Windows SCSI Class System FileMicrosoft Windows Search ComponentMicrosoft Windows SpeechOpenSSH for WindowsPower AutomatePush Message Routing ServiceRPC RuntimeReliable Multicast Transport Driver (RMCAST)Remote Desktop ClientRemote Desktop Gateway ServiceRole: DNS ServerRole: Windows Fax ServiceSQL ServerSkype for BusinessSpring Cloud AzureStorage Port DriverTelnet ClientVirtual Hard Disk (VHD) Miniport DriverVisual StudioVisual Studio CodeVolume Manager DriverWindows AF_UNIX Socket ProviderWindows ALPCWindows Accounts ControlWindows Ancillary Function Driver for WinSockWindows Audio ServiceWindows Authentication MethodsWindows AutopilotWindows Bind Filter DriverWindows Biometric ServiceWindows BitLockerWindows Bluetooth Port DriverWindows Bluetooth ServiceWindows Boot ManagerWindows Broadcast DVR User ServiceWindows Broker Infrastructure ServiceWindows CD-ROM DriverWindows Camera Frame Server MonitorWindows Cloud Files Mini Filter DriverWindows Compressed FolderWindows Connected User Experiences and TelemetryWindows Container Manager ServiceWindows Core MessagingWindows Credential GuardWindows Credential ProvidersWindows DCOM ServerWindows DHCP ClientWindows DHCP ServerWindows DNSWindows DWM Core LibraryWindows Defender Firewall ServiceWindows Deployment ServicesWindows Device Association Broker serviceWindows Device Association ServiceWindows Devices Human InterfaceWindows Direct ShowWindows Display Enhancement ServiceWindows Distributed File System (DFS)Windows Embedded Mode ServiceWindows Encrypting File System (EFS)Windows Enterprise App ManagementWindows Error ReportingWindows Event Logging ServiceWindows Failover ClusterWindows Fast FAT DriverWindows File History ServiceWindows GDIWindows GDI+Windows Graphics KernelWindows Group PolicyWindows HTTP Print ProviderWindows HTTP.sysWindows HelloWindows Host Guardian ServiceWindows Hyper-VWindows IKE ExtensionWindows IP Address Management (IPAM) ServiceWindows Image AcquisitionWindows Imaging ComponentWindows InstallerWindows Internet Connection Sharing (ICS)Windows KerberosWindows KernelWindows Kernel Mode DriverWindows Key Distribution CenterWindows LDAP - Lightweight Directory Access ProtocolWindows License ManagerWindows Link Layer Topology Discovery ProtocolWindows MIDI Service ModuleWindows Management InstrumentationWindows Management ServicesWindows MediaWindows Media PlayerWindows Message QueuingWindows Message Queuing Queue ManagerWindows Microsoft DirectMusicWindows Mobile BroadbandWindows Modern Device Management (MDM)Windows Modern Execution ServerWindows NDISWindows NFS PortmapperWindows NTFSWindows NetlogonWindows Network Connection BrokerWindows Network File SystemWindows NotificationWindows OLE DBWindows Online Certificate Status Protocol (OCSP)Windows Overlay FilterWindows PaintWindows Partition Management DriverWindows Performance MonitorWindows Power Dependency CoordinatorWindows PowerShellWindows Print Spooler ComponentsWindows PrintWorkflowUserSvcWindows Program Compatibility Assistant ServiceWindows Push NotificationsWindows RDP ClientWindows RNDISWindows Raw Image ExtensionWindows RegistryWindows Remote Access Connection ManagerWindows Remote DesktopWindows Remote Desktop Licensing ServiceWindows Remote Desktop ProtocolWindows Remote Desktop ServicesWindows Resilient File System (ReFS)Windows Resilient File System (ReFS) Deduplication ServiceWindows Routing and Remote Access Service (RRAS)Windows SMB ClientWindows SMB ServerWindows SMB Server Network Transport Driver (srvnet.sys)Windows SchannelWindows Secure BootWindows Secure Kernel ModeWindows Secure Socket Tunneling Protocol (SSTP)Windows Security CenterWindows Security Health ServiceWindows ServerWindows Services for NFS ONCRPC XDR DriverWindows Setup Files CleanupWindows ShellWindows Smart CardWindows Spaceport.sysWindows StorageWindows Storage Management ProviderWindows Storage Port DriverWindows Storage Spaces ControllerWindows TCP/IPWindows Task SchedulerWindows Text ShapingWindows URL MonikerWindows USB Audio Class driver (usbaudio.sys)Windows USB DriverWindows USB Hub DriverWindows USB Mass Storage Class DriverWindows USB Video DriverWindows Universal Disk Format File System Driver (UDFS)Windows Universal Plug and Play (UPnP) Device HostWindows Update StackWindows VHD miniport driverWindows VOLSNAP.SYSWindows Virtual Trusted Platform ModuleWindows Volume Manager Extension DriverWindows Volume Shadow CopyWindows Web Platform StorageWindows WebClient ServiceWindows Win32 Kernel SubsystemWindows Win32KWindows Wireless NetworkingWindows Wireless Wide Area Network ServiceWindows Work Folder ServiceWindows Work FoldersWindows exFAT File SystemWindows iSCSIWindows iSCSI Target ServiceWinsockXBox Gaming ServicesXboxElevation of privilege (EoP) vulnerabilities accounted for 44.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 26.8%.ImportantCVE-2026-81963 | Windows Update Stack elevation of privilege vulnerabilityCVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.Windows Update Stack contains a link following vulnerability. An attacker could exploit this vulnerability to elevate to SYSTEM privileges.Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day.ImportantCVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerabilityCVE-2026-85880 is a EoP vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges.There have been 16 vulnerabilities patched in ALPC since 2022, but this is the first to be included in Patch Tuesday in more than three years (April 2023) and the second to be exploited as a zero-day since CVE-2023-21674 as part of the January 2023 Patch Tuesday.ImportantCVE-2026-69380 | Microsoft Exchange Server elevation of privilege vulnerabilityCVE-2026-69380 is an EoP in Microsoft Exchange Server. It received a CVSSv3 score of 8.1 and is rated as important. This is a missing authorization vulnerability. An authenticated attacker with access to a mailbox through a low-user privilege user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails as other Exchange users as well as access attachments. Despite the high CVSS score, this vulnerability is rated as “Exploitation Less Likely” according to the Microsoft Exploitability Index.ImportantCVE-2026-69525 | Remote Desktop Services remote code execution vulnerabilityCVE-2026-69525 is an RCE vulnerability affecting Remote Desktop Services. It received a CVSSv3 score of 9.8 and is rated as important. Successful exploitation of this flaw would allow an attacker to execute arbitrary code by exploiting a use-after-free flaw. Microsoft assesses this vulnerability as “Exploitation More Likely.”In addition to CVE-2026-69525, three RCEs in Remote Desktop Services were also patched this month. While each were rated as important, they differed in their CVSS scoring and exploitability rating as noted in the table below:CVECVSSv3Exploitability AssessmentCVE-2026-695147.5Exploitation UnlikelyCVE-2026-695397.5Exploitation UnlikelyCVE-2026-695997.5Exploitation Less LikelyCVE-2026-695367.1Exploitation Less LikelyCriticalCVE-2026-69730 | Windows DNS Server remote code execution vulnerabilityCVE-2026-69730 is an RCE vulnerability affecting Windows DNS Server. It received a CVSSv3 score of 9.8 and is rated Critical. According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution. Microsoft assesses this flaw as “Exploitation More Likely.”Eight additional RCEs in Windows DNS Server were patched this month, however they did not achieve the same exploitability assessment as CVE-2026-69730. These eight are outlined in the table below:CVECVSSv3SeverityExploitability AssessmentCVE-2026-695518.8ImportantExploitation Less LikelyCVE-2026-698138.1CriticalExploitation Less LikelyCVE-2026-698588.1CriticalExploitation UnlikelyCVE-2026-775058.1CriticalExploitation Less LikelyCVE-2026-697828.1ImportantExploitation UnlikelyCVE-2026-698278.1CriticalExploitation UnlikelyCVE-2026-699898.1ImportantExploitation UnlikelyCVE-2026-729287.5ImportantExploitation Less LikelyCriticalCVE-2026-69676 | Windows Kerberos remote code execution vulnerabilityCVE-2026-69676 is an RCE vulnerability affecting Windows Kerberos. It received a CVSSv3 score of 8.8 and is rated critical. An attacker with low-level access could exploit this authentication bypass flaw using capture-replay against Windows Kerberos in order to execute arbitrary code. Microsoft assesses this flaw as “Exploitation More Likely.”Tenable SolutionsA list of all the plugins released for Microsoft’s September 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.Get more informationMicrosoft's September 2026 Security UpdatesTenable plugins for Microsoft September 2026 Patch Tuesday Security UpdatesJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
As a vulnerability research specialist, I have summarized the critical findings from the September 2026 Microsoft Patch Tuesday release. This month was record-breaking, addressing **964 CVEs** (104 Critical, 860 Important), including two zero-days exploited in the wild.
---
# Vulnerability: Windows Update Stack Elevation of Privilege (Zero-Day)
## CVE Details
- **CVE ID:** CVE-2026-81963
- **CVSS Score:** 7.8 (Important)
- **CWE:** Link Following (CWE-59)
## Affected Systems
- **Products:** Windows Operating Systems (Desktop and Server)
- **Versions:** Multiple versions using the Windows Update Stack
- **Configurations:** Systems where the Update Stack is active (default).
## Vulnerability Description
A link-following vulnerability exists in the Windows Update Stack. An attacker can manipulate symbolic links to redirect file operations to locations they shouldn't have access to.
## Exploitation
- **Status:** **Exploited in the Wild** (Zero-Day)
- **Complexity:** Low
- **Attack Vector:** Local
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- **Result:** Attacker gains **SYSTEM** privileges.
## Remediation
### Patches
- Apply the September 2026 cumulative updates for the respective Windows version.
---
# Vulnerability: Windows ALPC Elevation of Privilege (Zero-Day)
## CVE Details
- **CVE ID:** CVE-2026-85880
- **CVSS Score:** 7.8 (Important)
- **CWE:** Improper Access Control
## Affected Systems
- **Products:** Windows Advanced Local Procedure Call (ALPC)
- **Versions:** All supported Windows Desktop and Server versions.
## Vulnerability Description
A flaw in how the ALPC (Advanced Local Procedure Call) handles specific requests allows an attacker to bypass security boundaries within the local inter-process communication mechanism.
## Exploitation
- **Status:** **Exploited in the Wild** (Zero-Day)
- **Complexity:** Low
- **Attack Vector:** Local
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- **Result:** Elevation to **SYSTEM** level privileges.
---
# Vulnerability: Windows DNS Server Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-69730
- **CVSS Score:** 9.8 (Critical)
- **CWE:** Use-After-Free (CWE-416)
## Affected Systems
- **Products:** Windows Server (DNS Role enabled)
- **Versions:** Windows Server 2012 through 2025 (estimated)
## Vulnerability Description
A use-after-free vulnerability exists in the Windows DNS Server service. An unauthenticated remote attacker can trigger the flaw by sending a specially crafted malicious packet to the DNS server.
## Exploitation
- **Status:** Not exploited (Assessment: **Exploitability More Likely**)
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- **Result:** Full system compromise/Remote Code Execution.
---
# Vulnerability: Remote Desktop Services Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-69525
- **CVSS Score:** 9.8 (Important/Critical severity)
- **CWE:** Use-After-Free (CWE-416)
## Affected Systems
- **Products:** Windows Remote Desktop Services (RDS)
- **Versions:** Multiple versions
- **Configurations:** Systems with RDP enabled and accessible.
## Vulnerability Description
A use-after-free flaw in RDS allows for arbitrary code execution. This is one of four RDS RCEs patched this month, but carries the highest exploitability rating.
## Exploitation
- **Status:** Not exploited (Assessment: **Exploitability More Likely**)
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
---
# Vulnerability: Windows Kerberos Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-69676
- **CVSS Score:** 8.8 (Critical)
- **CWE:** Authentication Bypass (Capture-Replay)
## Affected Systems
- **Products:** Windows Kerberos Authentication Component
- **Versions:** Standard Windows Server and Desktop environments.
## Vulnerability Description
An authentication bypass flaw utilizing a capture-replay attack vector. An attacker with low-level network access can replay authentication data to execute arbitrary code.
## Exploitation
- **Status:** Not exploited (Assessment: **Exploitability More Likely**)
- **Complexity:** Medium
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
---
## Remediation & Detection (All CVEs)
### Patches
- Systems should be updated immediately via Windows Update or WSUS using the **September 2026** cumulative updates.
### Detection
- **IOCs:** Monitor for unusual ALPC traffic, unexpected SYSTEM level process creation by the Update Stack, or malformed DNS queries targeting the server role.
- **Tools:** Use Tenable plugins for September 2026 Patch Tuesday to identify non-compliant assets.
## References
- Microsoft September 2026 Security Updates: hxxps[://]msrc[.]microsoft[.]com/update-guide/en-us/releaseNote/2026-sep
- Tenable Blog Summary: hxxps[://]www[.]tenable[.]com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880