Microsoft Patch Tuesday – September 2026

Today is Microsoft Patch Tuesday for September 2026. There are 973 vulnerabilities that have been addressed this time around. Two of them are actively exploited zero-days, and 113 are rated critical. None of the vulnerabilities were publicly disclosed before today. We recommend applying these updates as soon as possible.

Notable Patch Tuesday vulnerabilities for September

CVE-2026-81963

A link following flaw in the Windows Update Stack lets an attacker who is already logged on to a machine gain SYSTEM privileges. This is a zero-day that is actively exploited.

CVE-2026-85880

A heap overflow in Windows Advanced Local Procedure Call (ALPC) allows a local attacker to elevate to SYSTEM. The attacker needs to be able to run code in a low privilege AppContainer and can then escape the sandbox without any user interaction. This zero-day is also actively exploited.

CVE-2026-69730

A use after free in Windows DNS Server allows an unauthenticated attacker to execute code by sending a specially crafted packet to the service, without any user interaction. Microsoft rates exploitation as more likely, and several other DNS Server vulnerabilities are fixed this month, so servers running the DNS role should be prioritized.

CVE-2026-69525

A use after free in Remote Desktop Services allows an attacker on the network to execute code on the server without authenticating first. Microsoft considers exploitation more likely, so servers running Remote Desktop Services should be patched early.

For more detailed information on these and other vulnerabilities, please refer to the release notes: https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep

Need help addressing the above in your own organization? Speak to an Outpost24 expert.

About the Author

Marcus White Cybersecurity Specialist, Outpost24

Marcus is an Outpost24 cybersecurity specialist based in the UK, with 8+ years experience in the tech and cyber sectors. He writes about attack surface management, application security, threat intelligence, and compliance.