Microsoft Patch Tuesday September 2026: What to Install Now
Microsoft Patch Tuesday for September 2026 shipped fixes for 973 vulnerabilities, including 113 rated Critical, making it the largest Patch Tuesday on record, according to Automox. Cisco Talos counts the same 973 CVEs and 113 Critical bugs. Rapid7 puts Microsoft's own tally slightly higher, at 974, and counted 999 vulnerabilities total once it added 25 non-Microsoft CVEs reviewed in the same release. None of the three publications explain the small gap between their counts.
Two of those 973 fixes deserve attention before the rest: Microsoft says it is aware of exploitation in the wild for CVE-2026-81963 and CVE-2026-85880, according to Rapid7 and Cisco Talos. Windows users and administrators should check for this month's cumulative update on their specific edition. SQL Server Management Studio 22 and Outlook users have two more high-severity bugs worth knowing about, covered further down. Most home users can handle this through Settings > Windows Update; IT teams managing servers and domain controllers have a longer, more specific list to work through.
Microsoft Patch Tuesday September 2026 zero-days to patch first
Both are 7.8 elevation-of-privilege flaws that Microsoft lists as exploited in the wild (Rapid7; Cisco Talos). The available description confirms local, authenticated access as a requirement for CVE-2026-81963. Microsoft's published summary for CVE-2026-85880 describes the ALPC buffer overflow and the SYSTEM-level outcome but doesn't spell out the same attack prerequisites, so don't assume it needs identical conditions to exploit.
CVE-2026-81963 targets the Windows Update Stack. Microsoft describes it as a link-following and access-control flaw: an attacker with local, authenticated access can trick the update process into following a malicious link and gaining SYSTEM rights (Automox; Rapid7). Rapid7 notes all supported versions of Windows receive a fix for this specific bug (Rapid7).
CVE-2026-85880 hits Windows Advanced Local Procedure Call (ALPC). Cisco Talos and Rapid7 describe it as a heap-based buffer overflow tied to an uninitialized resource that also grants SYSTEM access (Cisco Talos; Rapid7).
Neither bug carries the highest CVSS score in this release, but they're the only two Microsoft lists as exploited in the wild this month. That's the clearest signal for where to start: get this month's cumulative update installed, then work down the rest of the list.
Server risks: DNS, Kerberos, and other infrastructure flaws
The highest CVSS score in the release belongs to CVE-2026-69730, a 9.8 use-after-free in Windows DNS Server. It requires no authentication and no user interaction, and Microsoft rates exploitation "Exploitation More Likely" (Automox; Cisco Talos).
That rating carries extra weight for a specific reason: domain controllers run DNS by default, and Microsoft recommends leaving it there, according to Automox. Those same servers typically also handle Active Directory authentication, so a DNS Server compromise on a domain controller doesn't stay contained to name lookups. Confirmed affected systems include Windows Server 2012 through 2025 and Windows 10 versions 1607 and 1809; Windows 11 isn't on Microsoft's affected list for this CVE (Automox).
A second "Exploitation More Likely" flaw, CVE-2026-69676 (CVSS 8.8), affects Windows Kerberos through an authentication bypass via replay attack (Automox; Cisco Talos). Kerberos is the authentication service Windows domains rely on to verify identity, so this one targets login infrastructure rather than a single desktop.
Three more "Exploitation More Likely" remote-code-execution bugs round out the infrastructure list: CVE-2026-69852 in Windows Routing and Remote Access Service, CVE-2026-72957 in Windows Deployment Services, and CVE-2026-70585 in the Services for NFS ONCRPC XDR Driver (Cisco Talos).
If you manage domain controllers, DNS servers, RRAS boxes, or deployment services, these are the roles Microsoft flags as more likely attack targets this month. "Exploitation More Likely" is Microsoft's own forward-looking label. It doesn't prove an active attack is underway, but it's the strongest signal Microsoft publishes for where attackers are expected to go next.
SQL Copilot and Outlook: high scores, lower urgency
CVE-2026-65669 (CVSS 9.6) sits inside SQL Copilot in SQL Server Management Studio 22 and is described as a heap-based buffer overflow (Automox). Despite the high score, Microsoft rates exploitation "less likely" because it requires user interaction, meaning someone has to trigger it rather than simply running the software (Automox).
CVE-2026-78509 (CVSS 9.8) can fire when Outlook renders a crafted email in the Reading Pane. Microsoft describes it as a heap-based buffer overflow and rates exploitation "less likely" too (Automox). It isn't among the two CVEs Microsoft lists as exploited this month.
Update SQL Server Management Studio 22 and Outlook along with everything else, but don't let a high CVSS score alone set your priority order. Microsoft's exploitability rating and the exploited-in-the-wild list are more reliable guides than the score by itself.
Installing September 2026 Microsoft security updates: what to check by edition
These September 2026 Microsoft security updates apply differently depending on your Windows edition, so matching the right package matters more than usual this month.
Windows 10 21H2 and 22H2 devices get the update through KB5122878 (builds 19045.7725 and 19044.7725), which bundles the latest servicing stack update with the cumulative update (Microsoft Support, yesterday). Microsoft says it isn't currently aware of general issues with this release.
Windows 10 version 1607 gets a separate package, KB5123099, which brings that build to 14393.9512 (Microsoft Support). Windows Server administrators should use whichever update is listed for their specific server version in Windows Update, WSUS, or the Microsoft Update Catalog rather than assume either KB above applies. Other editions, including Windows 11, should check Windows Update or the Update Catalog directly for the matching package.
To confirm the update installed correctly, check Settings > Windows Update > Update history for KB5122878 (or your edition's equivalent), or run winver and match the build number against what Microsoft lists for your version.
One caveat worth knowing: devices with an unrecommended BitLocker Group Policy configuration may be prompted for a BitLocker recovery key. Microsoft says the issue applies to updates released on or after April 14, 2026, and it's still noted in this release (Microsoft Support). If Windows asks for a recovery key after this update, check that policy setting before assuming the update broke something.
Admins working from custom deployment images have more to verify. Devices without the July 2023 cumulative update (KB5028244) or later need a standalone servicing stack update (KB5031539) installed first, and custom images must include a version- and architecture-matched boot.stl file or risk boot failures with error 0xc0430001 (Microsoft Support).
Support-lifecycle timing adds another layer. Windows 10 22H2 support ended last year, on October 14, 2025, and Windows 10 Enterprise LTSC 2021 runs out January 12, 2027 (Microsoft Support). Looking further out, Windows 11 24H2 Home and Pro, Exchange Server 2016/2019, and Office 2021 all lose support on October 14, 2026, with no Extended Security Updates option for Office 2021, according to Rapid7's lifecycle tracking.
What to do now
Home users should let Windows Update install this month's cumulative update for their edition and restart. That's the normal path for closing both exploited flaws.
Administrators should treat CVE-2026-81963 and CVE-2026-85880 as the first priority because Microsoft lists them as exploited in the wild, then work through DNS Server, Kerberos, RRAS, and deployment-service roles wherever those services run. Verify SSU prerequisites on any custom images before deploying at scale, and flag the October 14, 2026 end-of-support wave affecting Windows 11 24H2 Home/Pro, Exchange Server 2016/2019, and Office 2021 for planning now.
Comments
Be the first, drop a comment!