Twenty Wormable Bugs in One Patch Tuesday: What the September 2026 Microsoft Release Tells Us
Microsoft's September 2026 Patch Tuesday was the largest on record, and the headline number is not the most useful part of it. The release fixed 971 issues, including 112 rated Critical, according to Absolute Software's analysis. What deserves attention is the composition: two zero-days exploited in the wild, at least 20 flaws that ZDI researchers classified as wormable, and a set of pre-authentication remote code execution bugs in services that sit on network boundaries.
What wormable means in practice
A wormable vulnerability is one an attacker can exploit remotely, without authentication and without user interaction, in a way that can spread from host to host. Each of those three conditions is common on its own. Together they describe a flaw that behaves like a self-propagating worm rather than a targeted intrusion.
ZDI's assessment covered at least 20 such flaws in this release. The practical implication is that perimeter services need to be patched first, because a wormable bug in an internet-facing service does not wait for an attacker to choose a victim.
The two exploited zero-days
CVE-2026-81963 is a link-resolution elevation of privilege in the Windows Update Stack, rated 7.8, exploited in the wild. CVE-2026-85880 is an ALPC heap overflow elevation of privilege, also rated 7.8, also exploited. Both were used in an exploit chain that multiple China-aligned espionage actors delivered through the BlueMoon exploit kit, according to Tenable's research notes. The chain also involved CVE-2026-85046 and CVE-2026-87491.
One detail from the BlueMoon reporting is worth recording. The fix for CVE-2026-85046 entered the Chromium open-source repository on 7 August 2026, but the Chrome Stable channel did not receive it until 3 September. That 27-day gap between an open-source commit and a stable release gave attackers a window to reverse-engineer a working exploit from public code. Proofpoint also reported signs of AI-assisted exploit development in the samples, based on missing comments, obfuscation patterns and an unusually fast iteration rate.
Prioritization that reflects the data
Sorting by CVSS alone does not capture this release. The two exploited zero-days scored 7.8, below the 9.8 Critical entries that had no known exploitation. The exploited flaws deserve attention first because exploitation is confirmed, not because of their score.
A workable order is: patch the two exploited zero-days, then the wormable pre-authentication remote code execution bugs in boundary services, then everything else. Services named in the release include Windows DNS Server, RDP, RRAS, Netlogon, DHCP Server, Message Queuing and the HTTP print provider, along with Exchange Server and SharePoint.
Limitations
The count of 971 fixes and 112 Critical ratings comes from Absolute Software's summary; Microsoft's own count may differ depending on how updates are grouped. The wormable classification is ZDI's assessment of at least 20 flaws, not a complete enumeration. The BlueMoon attribution to China-aligned actors is an assessment by the reporting vendors, and the AI-assisted development observation is Proofpoint's inference from sample characteristics rather than a confirmed fact. The 27-day window is documented in the reporting but the causal link to the exploit kit is an inference.
References
- Absolute Software, September 2026 Patch Tuesday analysis
- ZDI assessment of wormable vulnerabilities in the September 2026 release
- Tenable research notes on CVE-2026-85046, CVE-2026-85880 and CVE-2026-87491
- Proofpoint reporting on the BlueMoon exploit kit
- NVD entries for CVE-2026-81963 and CVE-2026-85880
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.