Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
September 8, 2026
Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, including 2 zero-days
September 8, 2026
Phishing Powers 80% of Attacks on US Companies: SOCs Can Detect It Early
September 8, 2026
Home/CyberSecurity News/Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, including 2 zero-days
CyberSecurity News

Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, including 2 zero-days

Key Takeaways Microsoft’s September 2026 Patch Tuesday addressed 973 security vulnerabilities across a wide range of products. Two zero-day vulnerabilities, both elevation-of-privilege flaws in...

Sarah simpson
Sarah simpson
September 8, 2026 5 Min Read
2 0

Key Takeaways

  • Microsoft’s September 2026 Patch Tuesday addressed 973 security vulnerabilities across a wide range of products.
  • Two zero-day vulnerabilities, both elevation-of-privilege flaws in Windows, were actively exploited prior to the patch release.
  • The vulnerabilities span critical Microsoft products including Windows, Office, SQL Server, Exchange, and Azure.
  • A significant number of critical and important fixes require immediate customer action, including those for Windows Secure Kernel Mode, VBS, and Microsoft Office applications.

Microsoft has issued its September 2026 Patch Tuesday security updates, a comprehensive release on September 8 that addresses 973 vulnerabilities. This extensive patching effort includes fixes for two zero-day vulnerabilities that were already being actively exploited in the wild.

Table Of Content

  • Key Takeaways
  • Two Windows Zero-Days Under Active Exploitation
  • Critical Fixes Across Windows and Office
  • Other Notable Vulnerabilities
  • What You Should Do

The patches target a broad spectrum of Microsoft products and services, including core components like Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure, and various developer tools. This necessitates a coordinated remediation strategy for organizations, encompassing endpoints, servers, and enterprise application environments.

According to Microsoft’s release notes, Windows accounted for the majority of the vulnerabilities with 723 fixes. Microsoft Office had 111, SQL Server 62, developer tools 22, SharePoint Server 16, and Exchange Server nine. Notably, Elevation of Privilege vulnerabilities constituted nearly half of the issues addressed in this release, followed by Remote Code Execution (RCE) flaws.

The breakdown of vulnerability impacts is as follows:

Vulnerability Impact Count
Elevation of Privilege 438
Remote Code Execution (RCE) 258
Information Disclosure 173
Denial of Service (DoS) 56
Security Feature Bypass 19
Spoofing 16
Tampering 13
Total 973

It is important to note that Microsoft also listed 25 republished non-Microsoft CVEs, which are distinct from the 973 Microsoft-specific vulnerabilities.

Two Windows Zero-Days Under Active Exploitation

Among the critical fixes are two zero-day vulnerabilities affecting Windows, both of which have been exploited in attacks. The first, CVE-2026-85880, is an elevation of privilege flaw impacting Windows Advanced Local Procedure Call (ALPC). Microsoft has classified this vulnerability as Important and has indicated that customer action is required. While the company confirmed active exploitation, details regarding the attackers, targeted organizations, or the full exploitation chain were not disclosed. For security teams, the active exploitation status elevates this to an urgent patching priority, regardless of its ‘Important’ severity rating.

The second zero-day, CVE-2026-81963, is another Important-rated elevation of privilege vulnerability found in the Windows Update Stack. Check Point’s advisory elaborated that this flaw involves improper link resolution before file access, a technique often referred to as link following. This allows an authenticated attacker to locally elevate privileges. This vulnerability is particularly relevant in post-compromise scenarios, where an attacker who has already gained initial access could leverage this weakness to achieve higher levels of control over a system.

Both vulnerabilities are marked as exploited but were not publicly disclosed in the Security Update Guide export. This distinction is not contradictory, as private exploitation can occur before a vulnerability becomes publicly known. This situation underscores a crucial lesson for administrators: relying solely on Critical-rated vulnerabilities for emergency deployment could lead to overlooking these two actively exploited zero-days.

Critical Fixes Across Windows and Office

Beyond the zero-days, several Critical vulnerabilities demand immediate attention, particularly within Windows security components. CVE-2026-83939 addresses an elevation of privilege in Windows Secure Kernel Mode, while CVE-2026-83498 affects Virtualization-Based Security (VBS) Enclave privileges. Another VBS-related issue, CVE-2026-83501, is an information disclosure vulnerability. All three Critical entries necessitate customer action, making them prime candidates for early compatibility testing and deployment alongside the actively exploited flaws.

Microsoft Office also received Critical remote code execution fixes. These include CVE-2026-81959 and CVE-2026-81953 in Excel, and CVE-2026-81952 in Word. Additionally, CVE-2026-85875, an Important Excel information disclosure vulnerability, was listed. Organizations must evaluate their installed Office products independently, as updating Windows does not guarantee that productivity applications are also fully patched.

Other Notable Vulnerabilities

Other significant remote code execution vulnerabilities include CVE-2026-85877 in Windows Print Spooler, CVE-2026-83997 in Windows Message Queuing, and CVE-2026-83998 in Remote Desktop Client. All three are rated Important and require customer action. While their titles indicate affected components and potential impact, they do not confirm whether exploitation is unauthenticated or if user interaction is required.

A substantial number of elevation-of-privilege entries impact the Windows Biometric Service. Additional fixes cover critical components such as the Windows Kernel, NTFS, Error Reporting, and the Resilient File System Deduplication Service. The sheer volume and diversity of these entries underscore the necessity for organizations to meticulously map advisories to their deployed systems, rather than making assumptions about negligible exposure based on a few familiar component names.

This month’s release also addresses availability and integrity issues. CVE-2026-84001 affects the Windows Key Distribution Center through a denial of service, while CVE-2026-83989 targets the Services for NFS ONCRPC XDR driver with the same impact. CVE-2026-83991 addresses tampering in the Windows Cloud Files Mini Filter Driver. Each of these vulnerabilities is rated Important.

Developer environments also require attention. CVE-2026-84003 addresses spoofing in Microsoft Authentication Library (MSAL) for Node.js, and CVE-2026-83948 covers remote code execution in Microsoft Azure CLI. Both require customer action. Conversely, the Critical Entra ID vulnerability CVE-2026-83941 is marked as requiring no customer action, illustrating the importance of checking remediation requirements individually for each vulnerability.

Microsoft emphasizes that Windows 10 and Windows 11 security updates are cumulative and directs administrators to the Microsoft Update Catalog. The company’s guidance also stresses the importance of installing the latest servicing stack update. Administrators should review all listed known issues, particularly for Exchange, SQL Server, and Windows Server, before implementing any production changes.

What You Should Do

  • Prioritize patching for the two actively exploited zero-day vulnerabilities (CVE-2026-85880 and CVE-2026-81963) immediately, regardless of their ‘Important’ severity rating.
  • Deploy Critical-rated fixes for Windows Secure Kernel Mode, VBS, and Microsoft Office applications after thorough compatibility testing.
  • Ensure all Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure, and developer tools are updated, as the patch release is comprehensive.
  • Implement a phased rollout strategy using representative test and pilot groups before expanding deployment, monitoring application health throughout the process.
  • Utilize tools like Microsoft Intune update rings to manage staged rollouts, set installation deadlines, and configure restart settings.
  • Verify successful installation of updates and required restarts, and promptly investigate any failed installations or offline devices.
  • Review Microsoft’s official release guidance and known issues, especially for server-side products like Exchange and SQL Server, before applying patches to production environments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Phishing Powers 80% of Attacks on US Companies: SOCs Can Detect It Early

Next Post

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Ivanti EPMM, Neurons, Sentry Flaws Allow RCE, Privilege Escalation
September 8, 2026
ChatGPT Sandbox Flaw Exposes Gmail Data to Account Takeover
September 8, 2026
Dell Secure Connect Gateway Critical Flaws Let Attackers Gain Unauthorized Access
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us