Cybersecurity Research

Microsoft's September 2026 Patch Tuesday: Two Flaws Already Under Attack

Cisco Talos · 9 Sept 2026
Key Takeaway Apply Microsoft's September 2026 patches as soon as possible, prioritising systems that handle DNS, authentication, or remote access, since two flaws are already being actively exploited.

Microsoft has released its September 2026 Patch Tuesday update, addressing 973 vulnerabilities across its product range, 113 of which are rated critical. Of these, 82 are remote code execution flaws that could allow attackers to run malicious code on affected systems without authorisation.

Two vulnerabilities have already been exploited in the wild: CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, and CVE-2026-85880, an elevation of privilege issue in Windows Advanced Local Procedure Call (ALPC). Both carry a CVSS score of 7.8, meaning successful exploitation could let attackers gain higher-level access on a compromised device.

Microsoft also flagged several other vulnerabilities it believes are more likely to be exploited soon, including a critical Windows DNS Server flaw (CVE-2026-69730, CVSS 9.8) and an authentication issue in Spring Cloud Azure (CVE-2026-69854, CVSS 9.0). Other notable flaws affect Windows Kerberos, Routing and Remote Access Service, Deployment Services, VBS, NFS drivers, and Azure Cosmos DB.

Key Takeaway: Small businesses should prioritise applying this month's Microsoft security updates promptly, especially on systems handling DNS, authentication, or remote access, to close off vulnerabilities already being exploited by attackers.

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.