DEV Community

Cover image for Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Microsoft Patches 966 Vulnerabilities in September 2026 Update Including Two Actively Exploited Zero-Days

Summary

Microsoft's September 2026 Patch Tuesday fixed 966 flaws, its largest ever. The patch package includes 105 critical bugs and two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880). The critical flaws cluster in Windows network services (DNS, DHCP, RRAS, Netlogon), Office file parsing, imaging/graphics components, and Azure/Entra cloud services. Microsoft is attributing the surge in volume to AI-assisted vulnerability discovery.

Take Action:

Patch the Windows OS first for the two zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC, both already exploited in attacks to gain SYSTEM privileges. Next, patch internet-reachable and domain-joined Windows servers: DNS, DHCP, RRAS, Netlogon, Kerberos and the Key Distribution Center, Services for NFS, Deployment Services, Failover Cluster and SSTP all carry critical remote code execution flaws. Then move through Outlook, Word, Excel, and Office, followed by SQL Server, SharePoint Server, and Exchange. Windows Hello, Secure Kernel Mode, Credential Guard, and VBS should follow for anything holding credentials or running as a security boundary. Everything else can follow in the normal cycle, but plan for it to take longer than usual: almost no organization can test and deploy this volume in a single window.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)