Microsoft's September 2026 security update addresses a massive 973 vulnerabilities, with 113 classified as critical. Most significantly, two vulnerabilities—CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC—are confirmed to have been exploited in the wild, both allowing for elevation of privilege. Among the critical fixes are 82 remote code execution (RCE) vulnerabilities across services like Kerberos, DNS Server, and Routing and Remote Access Service.
Beyond core Windows components, the update patches high-impact flaws in Azure AI Language and Microsoft Azure Active Directory B2C, both of which received perfect CVSS scores of 10.0. Security teams are advised to prioritize these updates and implement the newly released Snort rulesets (SIDs 67011-67084 and 301619-301655) to mitigate potential exploitation risks.
Top comments (0)