Tech News

Patch Tuesday September 2026: 973 Fixes, 2 Exploited Zero-Days, and 20 Wormable Flaws

It's staggering: Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities. It is by far the largest Patch Tuesday in history and, in the process, smashes the record set just two months earlier. Here are the key takeaways.

On Tuesday, September 8, 2026, Microsoft released its monthly batch of security updates. It is a routine occurrence on the second Tuesday of every month. There are so many vulnerabilities this time that the total is nearly at the 1,000-mark. Yet, I wrote in July that Microsoft had delivered the biggest Patch Tuesday in its history with 570 flaws, before an August release with 421 flaws and one zero-day exploited by Lazarus. September more than doubles the previous month’s volume.

This is not especially surprising: we know that Microsoft uses an AI-assisted vulnerability discovery system across its entire product portfolio. For this new Patch Tuesday, Windows alone accounts for 723 fixes, followed by Office (111), SQL Server (62), SharePoint Server (16), and Exchange Server (9). Of this set of flaws, 113 are considered critical, and there are also two zero-days.

Among the vulnerabilities that deserve special attention, the following stand out:

  • CVE-2026-55007 (Exchange Server). A remote unauthenticated attacker can achieve code execution by simply sending an email with a malicious Visio attachment. The code executes when the server processes the message. It affects Exchange SE and Exchange 2019.
  • CVE-2026-78509 (Outlook). Remote code execution can be triggered by simply reading an email in the mail client. It affects Outlook distributed via Microsoft Office and Microsoft 365 Apps.
  • CVE-2026-69676 (Kerberos). Code execution on an Active Directory domain controller, accessible to any authenticated domain user with a specially crafted request.

Two exploited zero-days

Microsoft reports two zero-day vulnerabilities that were already exploited in the wild. In both cases, they are local privilege escalations on Windows.

CVE-2026-81963 - Windows Update

This vulnerability (CVE-2026-81963) is located in the Windows update stack: Windows Update. It is based on an improper link resolution before file access and allows an attacker who already has local access to obtain SYSTEM privileges on Windows. According to MSRC, only Windows 11 (23H2, 24H2, 25H2 and 26H1) and Windows Server 2025 are vulnerable.

CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) 

This second zero-day flaw (CVE-2026-85880) is a buffer overflow in the ALPC (Advanced Local Procedure Call) component.

"An attacker able to execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft says. A small but notable detail: this flaw only affects Windows 10 and Windows Server 2012 through 2022. In other words, Windows 11 is unaffected.

20 wormable security flaws

Beyond the zero-days, it is interesting to note that 20 vulnerabilities patched by Microsoft could be described as wormable. That is how Dustin Childs explains it in his summary published on the Zero Day Initiative blog. Indeed, there are 20 remotely exploitable flaws with no authentication and no user interaction, which makes it easier for malware to spread from one machine to another.

As a reminder, a flaw is considered wormable when it meets three conditions: it is remotely exploitable over the network, requires no prior authentication, and needs no user interaction at all. Malicious code can then compromise one machine and automatically jump to the next. That is what WannaCry and NotPetya did in 2017 with the SMB EternalBlue flaw, but we are not at that point here.

The vulnerabilities patched on September 8, 2026, mainly affect server components: DNS Server (including CVE-2026-69730, rated 9.8/10), DHCP Server, Netlogon, RRAS, SSTP, SMB, Message Queuing, Failover Cluster, NFS, and the RMCAST driver. DHCP Server is heavily impacted this month, with 36 vulnerabilities.

September 2026 Windows updates

Although I plan additional articles introducing the new updates, here is the list of cumulative updates released this month.

  • Windows 11 24H2 and 25H2: KB5124008 (builds 26100.9445 and 26200.9445)
  • Windows 11 26H1: KB5124012 (build 28000.2954)
  • Windows 11 23H2: KB5122880 (build 22631.7582)
  • Windows 10 21H2 and 22H2: KB5122878 (builds 19044.7725 and 19045.7725)
  • Windows Server 2025: KB5122871 (build 26100.33438)
  • Windows Server 2022: KB5122882 (build 20348.5622)
  • Windows Server 2019 and Windows 10 1809: KB5122876 (build 17763.9245)
  • Windows Server 2016 and Windows 10 1607: KB5123099 (build 14393.9512)
  • Windows Server 2012 R2: KB5123066
  • Windows Server 2012: KB5123065

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.