September 10, 2026
By esentry Team

Microsoft Patch Tuesday - September 2026

Risk Rating: High / Critical Priority
Date Released: 8th September 2026

Overview

Microsoft's September 2026 Patch Tuesday is its largest security update on record, addressing 974 vulnerabilities across Microsoft products. The most significant concern is the inclusion of two Windows zero-days that have already been exploited in the wild. Both are local Elevation of Privilege (EoP) vulnerabilities, meaning an attacker who has already gained access to a system can potentially increase their privileges to SYSTEM, Windows' highest privilege level.

The release covers Windows, Microsoft Office, SQL Server, Azure, SharePoint, Exchange Server and other Microsoft products. CrowdStrike identifies 437 Elevation of Privilege vulnerabilities and 258 Remote Code Execution (RCE) vulnerabilities among this month's fixes.

Key Highlights

  • 974 vulnerabilities addressed across Microsoft's September security release.
  • Two actively exploited Windows zero-days require immediate prioritisation.
  • 104 vulnerabilities are rated Critical with the remainder predominantly rated Important.
  • 437 Elevation of Privilege and 258 Remote Code Execution vulnerabilities are highlighted in research analysis.
  • Microsoft addressed 726 vulnerabilities affecting Windows, making Windows the primary area of exposure this month.
  • 22 Critical Microsoft Office vulnerabilities were identified, including 12 that can potentially be exploited through the Preview Pane or Reading Pane, increasing the importance of Office patching even where users do not actively open a malicious document.

Featured Vulnerabilities

CVE-2026-81963 — Windows Update Stack EoP

CVSS: 7.8 | Exploited in the Wild

A vulnerability in the Windows Update Stack allows an authorised local attacker to exploit improper file-link handling and elevate privileges to SYSTEM. Microsoft has confirmed that the vulnerability has been exploited, although it has not disclosed details of the attacks.

CVE-2026-85880 — Windows ALPC EoP

CVSS: 7.8 | Exploited in the Wild

This vulnerability affects Windows Advanced Local Procedure Call (ALPC), a mechanism used for communication between processes. Exploitation of the heap-based buffer overflow can allow a local attacker to escape a low-privilege AppContainer and obtain SYSTEM privileges. Microsoft has confirmed exploitation in the wild.

Neither vulnerability necessarily provides the initial entry into an organisation. However, once an attacker has obtained access through phishing, stolen credentials, malware or another vulnerability, successful exploitation could allow them to escalate privileges, access protected resources and potentially move further into the environment.

Recommendations

1. Identify and patch systems affected by CVE-2026-81963 and CVE-2026-85880, prioritising administrator endpoints, servers and systems with access to critical infrastructure.

2. Prioritise vulnerabilities based on active exploitation, Critical severity, Remote Code Execution and asset exposure, rather than treating all 974 vulnerabilities equally.

3. Review EDR/XDR, Windows and identity logs for unusual privilege escalation, SYSTEM-level processes, suspicious PowerShell activity, credential theft, new administrative accounts and abnormal lateral movement.

4. Review Office installations and ensure the September security updates are deployed, particularly on systems where Preview Pane or Reading Pane functionality is enabled.

5. Use vulnerability-management and endpoint-management platforms to confirm that patches have been installed and that vulnerable systems are no longer exposed.