Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that attackers are already using.
This big update comes after Microsoft’s recent change to AI for finding security weaknesses. It uses a special scanning system that works in different ways on the Windows code.
The release covers Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure, and developer tools. This means organizations need to work together to fix problems across endpoints, servers, and application environments.
Microsoft’s release notes say that there were 723 fixes for Windows, 111 for Office, 62 for SQL, 22 for developer tools, 16 for SharePoint Server, and nine for Exchange Server.
Elevation of Privilege problems were the main focus of Microsoft’s Patch Tuesday release in September 2026, making up almost half of all the issues listed. Remote Code Execution flaws came next.
| Vulnerability Impact | Count |
|---|---|
| Elevation of Privilege | 438 |
| Remote Code Execution (RCE) | 258 |
| Information Disclosure | 173 |
| Denial of Service (DoS) | 56 |
| Security Feature Bypass | 19 |
| Spoofing | 16 |
| Tampering | 13 |
| Total | 973 |
Two Windows Zero-Days Under Active Exploitation
The first flaw, CVE-2026-85880, affects Windows Advanced Local Procedure Call (ALPC) and allows users to gain higher privileges. Microsoft rates it as Important and says customers need to act.
The summary shows that there is exploitation, but it doesn’t name the attackers, the groups they target, or how they exploit. For defenders, the exploitation alert means they need to fix this right away, even though it is rated Important.
The second zero-day, CVE-2026-81963, is an important flaw that lets someone gain higher access in the Windows Update Stack. Check Point’s notice talks about a problem where links are not checked properly before opening files. This allows a person with access to boost their control locally. This matters for ongoing attacks: if an attacker is already inside, they can use this flaw to take more control of the system.
Both flaws are shown as used, but they are not publicly shared in the Security Update Guide. These two points do not conflict; private use can happen before a weakness is public.
InfoSecBulletin Cybersecurity for mankind
