Microsoft's September 2026 security update addresses a massive 973 vulnerabilities, with 113 classified as critical. Most notably, two flaws—CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call (ALPC)—are already being exploited in the wild. Both are elevation of privilege vulnerabilities that pose a significant risk to unpatched systems by allowing attackers to gain higher-level permissions.
The update highlights a high volume of remote code execution (RCE) flaws, accounting for 82 of the critical entries. Significant risks were identified across Windows DNS Server, Kerberos, and various Azure services like Cosmos DB and Entra ID. Critical vulnerabilities in identity management, such as the 10.0 CVSS score for Azure Active Directory B2C and Azure AI Language, underscore the urgent need to secure cloud and identity infrastructure.
Security teams are encouraged to prioritize patches for core components like RRAS, SQL Server, and Microsoft Office, which remain frequent targets for exploitation. Cisco Talos has released updated Snort rulesets for both Snort 2 and Snort 3 to help organizations detect and block exploitation attempts against these newly disclosed vulnerabilities.
Top comments (0)