The September 2026 security update release addresses a significant volume of Critical vulnerabilities, with a particular focus on zero-click exploitation vectors in Microsoft Office and unauthenticated remote code execution (RCE) in core infrastructure services. Key highlights include 12 Office vulnerabilities exploitable via the Preview or Reading Pane and a series of 9.8-scored RCE flaws in Netlogon, DNS, DHCP, and MSMQ. These vulnerabilities present a high risk to domain identity and network perimeters, as many allow attackers to gain SYSTEM-level access or execute code without user interaction.
Furthermore, Microsoft confirmed active exploitation of two zero-day vulnerabilities in the Windows Update Stack and Advanced Local Procedure Call (ALPC), both of which provide a reliable path for local privilege escalation. The release also notes critical guest-to-host escapes in Hyper-V and a post-patch public disclosure of 'ShieldCrash,' a purported zero-day in Microsoft Defender. Organizations are urged to prioritize patching domain controllers and edge-facing services like SSTP and DNS to mitigate the risk of immediate lateral movement or perimeter breaches.
Top comments (0)