104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain ServicesActive Directory Federation Services (AD FS)Audio Video Control Transport ProtocolAzure ArcAzure CycleCloudAzure HDInsightsBranchCacheConnected Devices Platform Service (Cdpsvc)Data Sharing Service ClientGitHub Copilot and Visual Studio CodeGraphic FontsHID class driverIP HelperInternet Storage Name ServiceKernel Streaming WOW Thunk Service DriverMicrosoft AccountMicrosoft AuthenticatorMicrosoft Azure Attestation service and Device Health Attestation ServiceMicrosoft Azure CLIMicrosoft COM for WindowsMicrosoft Dynamics 365Microsoft Exchange ServerMicrosoft Graphics ComponentMicrosoft Install ServiceMicrosoft JScriptMicrosoft Local Security Authority Server (lsasrv)Microsoft OfficeMicrosoft Office AccessMicrosoft Office ExcelMicrosoft Office OutlookMicrosoft Office PowerPointMicrosoft Office PublisherMicrosoft Office SharePointMicrosoft Office WordMicrosoft Standard XPSMicrosoft Teams for AndroidMicrosoft Trace Data HelperMicrosoft UxTheme Library (uxtheme.dll)Microsoft WDAC OLE DB provider for SQLMicrosoft WebP Image ExtensionMicrosoft Windows Codecs LibraryMicrosoft Windows Media FoundationMicrosoft Windows PDFMicrosoft Windows SCSI Class System FileMicrosoft Windows Search ComponentMicrosoft Windows SpeechOpenSSH for WindowsPower AutomatePush Message Routing ServiceRPC RuntimeReliable Multicast Transport Driver (RMCAST)Remote Desktop ClientRemote Desktop Gateway ServiceRole: DNS ServerRole: Windows Fax ServiceSQL ServerSkype for BusinessSpring Cloud AzureStorage Port DriverTelnet ClientVirtual Hard Disk (VHD) Miniport DriverVisual StudioVisual Studio CodeVolume Manager DriverWindows AF_UNIX Socket ProviderWindows ALPCWindows Accounts ControlWindows Ancillary Function Driver for WinSockWindows Audio ServiceWindows Authentication MethodsWindows AutopilotWindows Bind Filter DriverWindows Biometric ServiceWindows BitLockerWindows Bluetooth Port DriverWindows Bluetooth ServiceWindows Boot ManagerWindows Broadcast DVR User ServiceWindows Broker Infrastructure ServiceWindows CD-ROM DriverWindows Camera Frame Server MonitorWindows Cloud Files Mini Filter DriverWindows Compressed FolderWindows Connected User Experiences and TelemetryWindows Container Manager ServiceWindows Core MessagingWindows Credential GuardWindows Credential ProvidersWindows DCOM ServerWindows DHCP ClientWindows DHCP ServerWindows DNSWindows DWM Core LibraryWindows Defender Firewall ServiceWindows Deployment ServicesWindows Device Association Broker serviceWindows Device Association ServiceWindows Devices Human InterfaceWindows Direct ShowWindows Display Enhancement ServiceWindows Distributed File System (DFS)Windows Embedded Mode ServiceWindows Encrypting File System (EFS)Windows Enterprise App ManagementWindows Error ReportingWindows Event Logging ServiceWindows Failover ClusterWindows Fast FAT DriverWindows File History ServiceWindows GDIWindows GDI+Windows Graphics KernelWindows Group PolicyWindows HTTP Print ProviderWindows HTTP.sysWindows HelloWindows Host Guardian ServiceWindows Hyper-VWindows IKE ExtensionWindows IP Address Management (IPAM) ServiceWindows Image AcquisitionWindows Imaging ComponentWindows InstallerWindows Internet Connection Sharing (ICS)Windows KerberosWindows KernelWindows Kernel Mode DriverWindows Key Distribution CenterWindows LDAP - Lightweight Directory Access ProtocolWindows License ManagerWindows Link Layer Topology Discovery ProtocolWindows MIDI Service ModuleWindows Management InstrumentationWindows Management ServicesWindows MediaWindows Media PlayerWindows Message QueuingWindows Message Queuing Queue ManagerWindows Microsoft DirectMusicWindows Mobile BroadbandWindows Modern Device Management (MDM)Windows Modern Execution ServerWindows NDISWindows NFS PortmapperWindows NTFSWindows NetlogonWindows Network Connection BrokerWindows Network File SystemWindows NotificationWindows OLE DBWindows Online Certificate Status Protocol (OCSP)Windows Overlay FilterWindows PaintWindows Partition Management DriverWindows Performance MonitorWindows Power Dependency CoordinatorWindows PowerShellWindows Print Spooler ComponentsWindows PrintWorkflowUserSvcWindows Program Compatibility Assistant ServiceWindows Push NotificationsWindows RDP ClientWindows RNDISWindows Raw Image ExtensionWindows RegistryWindows Remote Access Connection ManagerWindows Remote DesktopWindows Remote Desktop Licensing ServiceWindows Remote Desktop ProtocolWindows Remote Desktop ServicesWindows Resilient File System (ReFS)Windows Resilient File System (ReFS) Deduplication ServiceWindows Routing and Remote Access Service (RRAS)Windows SMB ClientWindows SMB ServerWindows SMB Server Network Transport Driver (srvnet.sys)Windows SchannelWindows Secure BootWindows Secure Kernel ModeWindows Secure Socket Tunneling Protocol (SSTP)Windows Security CenterWindows Security Health ServiceWindows ServerWindows Services for NFS ONCRPC XDR DriverWindows Setup Files CleanupWindows ShellWindows Smart CardWindows Spaceport.sysWindows StorageWindows Storage Management ProviderWindows Storage Port DriverWindows Storage Spaces ControllerWindows TCP/IPWindows Task SchedulerWindows Text ShapingWindows URL MonikerWindows USB Audio Class driver (usbaudio.sys)Windows USB DriverWindows USB Hub DriverWindows USB Mass Storage Class DriverWindows USB Video DriverWindows Universal Disk Format File System Driver (UDFS)Windows Universal Plug and Play (UPnP) Device HostWindows Update StackWindows VHD miniport driverWindows VOLSNAP.SYSWindows Virtual Trusted Platform ModuleWindows Volume Manager Extension DriverWindows Volume Shadow CopyWindows Web Platform StorageWindows WebClient ServiceWindows Win32 Kernel SubsystemWindows Win32KWindows Wireless NetworkingWindows Wireless Wide Area Network ServiceWindows Work Folder ServiceWindows Work FoldersWindows exFAT File SystemWindows iSCSIWindows iSCSI Target ServiceWinsockXBox Gaming ServicesXboxElevation of privilege (EoP) vulnerabilities accounted for 44.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 26.8%.ImportantCVE-2026-81963 | Windows Update Stack elevation of privilege vulnerabilityCVE-2026-81963 is an EoP vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.Windows Update Stack contains a link following vulnerability. An attacker could exploit this vulnerability to elevate to SYSTEM privileges.Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day.ImportantCVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerabilityCVE-2026-85880 is a EoP vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges.There have been 16 vulnerabilities patched in ALPC since 2022, but this is the first to be included in Patch Tuesday in more than three years (April 2023) and the second to be exploited as a zero-day since CVE-2023-21674 as part of the January 2023 Patch Tuesday.ImportantCVE-2026-69380 | Microsoft Exchange Server elevation of privilege vulnerabilityCVE-2026-69380 is an EoP in Microsoft Exchange Server. It received a CVSSv3 score of 8.1 and is rated as important. This is a missing authorization vulnerability. An authenticated attacker with access to a mailbox through a low-user privilege user account could exploit this vulnerability to gain access to other mailboxes. Successful exploitation would allow the attacker to send and receive emails as other Exchange users as well as access attachments. Despite the high CVSS score, this vulnerability is rated as “Exploitation Less Likely” according to the Microsoft Exploitability Index.ImportantCVE-2026-69525 | Remote Desktop Services remote code execution vulnerabilityCVE-2026-69525 is an RCE vulnerability affecting Remote Desktop Services. It received a CVSSv3 score of 9.8 and is rated as important. Successful exploitation of this flaw would allow an attacker to execute arbitrary code by exploiting a use-after-free flaw. Microsoft assesses this vulnerability as “Exploitation More Likely.”In addition to CVE-2026-69525, three RCEs in Remote Desktop Services were also patched this month. While each were rated as important, they differed in their CVSS scoring and exploitability rating as noted in the table below:CVECVSSv3Exploitability AssessmentCVE-2026-695147.5Exploitation UnlikelyCVE-2026-695397.5Exploitation UnlikelyCVE-2026-695997.5Exploitation Less LikelyCVE-2026-695367.1Exploitation Less LikelyCriticalCVE-2026-69730 | Windows DNS Server remote code execution vulnerabilityCVE-2026-69730 is an RCE vulnerability affecting Windows DNS Server. It received a CVSSv3 score of 9.8 and is rated Critical. According to the advisory, an unauthenticated, remote attacker could send a crafted packet to exploit a use-after-free flaw in Windows DNS in order to achieve remote code execution. Microsoft assesses this flaw as “Exploitation More Likely.”Eight additional RCEs in Windows DNS Server were patched this month, however they did not achieve the same exploitability assessment as CVE-2026-69730. These eight are outlined in the table below:CVECVSSv3SeverityExploitability AssessmentCVE-2026-695518.8ImportantExploitation Less LikelyCVE-2026-698138.1CriticalExploitation Less LikelyCVE-2026-698588.1CriticalExploitation UnlikelyCVE-2026-775058.1CriticalExploitation Less LikelyCVE-2026-697828.1ImportantExploitation UnlikelyCVE-2026-698278.1CriticalExploitation UnlikelyCVE-2026-699898.1ImportantExploitation UnlikelyCVE-2026-729287.5ImportantExploitation Less LikelyCriticalCVE-2026-69676 | Windows Kerberos remote code execution vulnerabilityCVE-2026-69676 is an RCE vulnerability affecting Windows Kerberos. It received a CVSSv3 score of 8.8 and is rated critical. An attacker with low-level access could exploit this authentication bypass flaw using capture-replay against Windows Kerberos in order to execute arbitrary code. Microsoft assesses this flaw as “Exploitation More Likely.”Tenable SolutionsA list of all the plugins released for Microsoft’s September 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.Get more informationMicrosoft's September 2026 Security UpdatesTenable plugins for Microsoft September 2026 Patch Tuesday Security UpdatesJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.