Microsoft's September 2026 security update addresses 1186 vulnerabilities: 119 rated Critical, 913 Important. 2 are already exploited in the wild and 0 were publicly disclosed before today.
This is a big patch batch — 1,186 CVEs total — but the real story is three vulnerabilities already in CISA's KEV catalog, two of them zero-days actively exploited before today's release. Neither of the exploited Windows bugs was publicly disclosed ahead of the patch, so there's no advance warning you missed, but that also means attackers had a head start you didn't.
Prioritize the KEV-listed items below over the raw volume of Important-rated EoP and RCE bugs padding out the rest of this month's release.
Patch these first
- CVE-2026-81963 (Important, CVSS 7.8) — Windows Update Stack: Elevation of Privilege — exploited in the wild, CISA KEV
- CVE-2026-85880 (Important, CVSS 7.8) — Windows ALPC: Elevation of Privilege — exploited in the wild, CISA KEV
- CVE-2026-85046 (CVSS 0.0) — Microsoft Edge (Chromium-based): see advisory — CISA KEV
CVE-2026-81963 (Windows Update Stack, EoP, CVSS 7.8): improper link resolution — a classic link-following flaw — lets an authorized local attacker escalate privileges. It's exploited in the wild and KEV-listed, so treat any endpoint running the Windows Update Stack as exposed and patch it today.
CVE-2026-85880 (Windows ALPC, EoP, CVSS 7.8): a heap-based buffer overflow in ALPC that also allows local privilege escalation by an authorized attacker. Also exploited and KEV-listed — ALPC is a core Windows IPC mechanism, so this affects essentially every supported Windows version and should be patched alongside the Update Stack bug.
CVE-2026-85046 (Microsoft Edge, Chromium-based): this one comes from the Chromium side — Microsoft Edge ingests a Chrome fix for a vulnerability Google says has an exploit in the wild. Make sure Edge is set to auto-update or push the update manually; don't assume your Windows patching cadence covers browser components.
Also notable
- CVE-2026-69525 (Important, CVSS 9.8) — Windows Remote Desktop Services: Remote Code Execution
- CVE-2026-69730 (Critical, CVSS 9.8) — Windows DNS: Remote Code Execution
- CVE-2026-69854 (Critical, CVSS 9.0) — Spring Cloud Azure: Elevation of Privilege
- CVE-2026-69676 (Critical, CVSS 8.8) — Windows Kerberos: Remote Code Execution
- CVE-2026-69857 (Critical, CVSS 8.5) — Azure Cosmos DB: Spoofing
- CVE-2026-68880 (Important, CVSS 8.0) — Windows Win32K: Elevation of Privilege
- CVE-2026-69301 (Important, CVSS 8.0) — Windows Win32K: Elevation of Privilege
- CVE-2026-72940 (Important, CVSS 8.8) — Windows Schannel: Remote Code Execution
By the numbers
- Elevation of Privilege: 438
- Remote Code Execution: 258
- Unspecified: 213
- Information Disclosure: 173
- Denial of Service: 56
- Security Feature Bypass: 19
- Spoofing: 16
- Tampering: 13
Source: Microsoft Security Update Guide and the CISA KEV catalog.
Subscribe free → I write a curated cybersecurity news roundup, including this breakdown each Patch Tuesday. Get it in your inbox.
Top comments (0)