Microsoft has released its September 2026 Patch Tuesday security updates, and this month’s release is one of the largest in the company’s history. Microsoft lists 974 vulnerabilities addressed across Windows, Office, Exchange Server, SQL Server, Azure, SharePoint, .NET and other products. More importantly, the September update fixes two vulnerabilities that Microsoft says were already being exploited in the wild. Both are Windows elevation-of-privilege flaws that can allow an attacker who already has a foothold on a system to escalate privileges to SYSTEM level.
The release also contains a large number of critical remote code execution vulnerabilities, including flaws affecting Windows DNS Server, DHCP Server, Remote Desktop Services, Exchange Server, Office, Hyper-V, Windows Graphics, and other components. Several of these vulnerabilities have a CVSS score of 9.8, making them particularly important for organizations to patch quickly.
What’s New in Microsoft September 2026 Patch Tuesday?
The biggest security changes in Microsoft’s September 2026 update are:
- 974 Microsoft CVEs addressed according to Microsoft’s release data.
- Two actively exploited zero-day vulnerabilities patched.
- The two zero-days affect the Windows Update Stack and Windows ALPC.
- A large number of Critical vulnerabilities, including many remote code execution flaws.
- Several CVSS 9.8 vulnerabilities affect Windows networking and enterprise services.
- Critical vulnerabilities have been fixed in Windows DNS Server, DHCP Server, Remote Desktop Services, Exchange Server, Office, Hyper-V and other Microsoft products.
- Windows 11 and Windows 10 also receive their regular September cumulative security updates.
For Windows 11 users, the September cumulative update is KB5124008, which brings Windows 11 24H2 and 25H2 to OS Builds 26100.9445 and 26200.9445, respectively. Microsoft also says the update includes additional coverage for automatic Secure Boot certificate deployment.
Two Zero-Day Vulnerabilities Fixed in September 2026
The two zero-days are the most important part of this month’s security update.
Microsoft says both vulnerabilities were exploited in the wild before the September patches became available. Security researchers currently have limited information about how widespread the attacks are, but both should be treated as high-priority vulnerabilities. (Zero-day initiative)
1. CVE-2026-81963 — Windows Update Stack Elevation of Privilege
CVE-2026-81963 is an Elevation of Privilege vulnerability in the Windows Update Stack.
Microsoft rates the vulnerability as Important, with a CVSS score of 7.8. Although it is not classified as Critical, it is significantly more important because Microsoft confirmed it was exploited in the wild.
The vulnerability involves improper link resolution before file access, also known as a link-following vulnerability.
An attacker who has already gained local access to a Windows computer could potentially exploit the flaw to elevate privileges and obtain SYSTEM-level permissions.
Security researchers believe this type of vulnerability could be particularly useful as part of a larger attack chain. An attacker may first gain an initial foothold through another vulnerability, phishing, malicious software, or stolen credentials and then use an elevation-of-privilege vulnerability to gain greater control of the system.
What users should do: Install the September 2026 Windows security update as soon as possible.
2. CVE-2026-85880 — Windows ALPC Elevation of Privilege
The second zero-day is CVE-2026-85880, a vulnerability in the Windows Advanced Local Procedure Call (ALPC) mechanism.
It is also rated Important and has a CVSS score of 7.8. Microsoft confirmed that the vulnerability was exploited in attacks before it was patched.
ALPC is a Windows mechanism for interprocess communication. According to security researchers, successful exploitation can allow an attacker with local code execution to elevate privileges and ultimately obtain SYSTEM-level privileges.
The important point for ordinary Windows users is that this isn’t necessarily a vulnerability that allows a remote attacker to immediately take over an unprotected PC over the internet. The attacker generally needs an initial foothold on the machine.
However, that doesn’t make the vulnerability less important. Privilege-escalation bugs are often useful once an attacker has gained limited access.
Microsoft has not provided detailed information about the attacks exploiting the vulnerability.
Critical Remote Code Execution Vulnerabilities
The two zero-days aren’t the only reason to install the September update.
This month’s release contains a large number of Critical vulnerabilities, many of which involve remote code execution. Security researchers identified numerous vulnerabilities that could potentially allow attackers to execute arbitrary code remotely without requiring extensive user interaction.
Some of the most notable vulnerabilities are as follows.
CVE-2026-69525 — Remote Desktop Services
CVE-2026-69525 affects Remote Desktop Services and has a CVSS score of 9.8.
The vulnerability is a remote code execution flaw involving a use-after-free condition. Tenable reports that Microsoft considers exploitation more likely.
Remote Desktop Services deserves particular attention because RDP is widely used in business environments and Windows Server deployments.
Organizations should prioritize this update on systems where Remote Desktop Services is enabled or exposed to networks.
CVE-2026-55007 — Exchange Server Remote Code Execution
CVE-2026-55007 is another particularly important vulnerability because it affects Microsoft Exchange Server.
According to Zeroday Initiative, a remote unauthenticated attacker could potentially achieve code execution by sending an email containing a specially crafted Visio attachment. The attack does not require the victim to open the attachment because the server processes the message.
That makes this vulnerability particularly concerning for organizations operating their own Exchange infrastructure.
If you manage an Exchange Server environment, this should be considered a high-priority update.
Windows DNS Server Has Multiple Critical RCE Vulnerabilities
Windows DNS Server is another major area of concern in the September update. Microsoft patched several DNS Server vulnerabilities, including CVE-2026-69730, which has a CVSS score of 9.8.
Other critical DNS-related vulnerabilities include:
- CVE-2026-69813
- CVE-2026-69858
- CVE-2026-72987
These vulnerabilities can potentially lead to remote code execution. DNS servers are particularly sensitive because they provide an essential network service. A successful attack against an organization’s DNS infrastructure could have consequences far beyond a single Windows computer.
Windows DHCP Server Also Has Critical Vulnerabilities
Microsoft also patched critical vulnerabilities affecting Windows DHCP Server.
Two notable examples are:
- CVE-2026-69845 — CVSS 9.8
- CVE-2026-72979 — CVSS 9.8
Both are remote code execution vulnerabilities. Organizations running Windows Server as a DHCP server should prioritize the September security updates.
Windows Graphics, Imaging and Media Components
The September release also fixes several critical vulnerabilities in Windows components that handle graphics, images and media.
Notable examples include:
- CVE-2026-77493 — Windows Graphics Component RCE, CVSS 9.8
- CVE-2026-70296 — Windows Imaging Component RCE, CVSS 9.8
- CVE-2026-69499 — Windows Imaging Component RCE
- CVE-2026-69860 — Windows Imaging Component RCE
- CVE-2026-73006 — DirectWrite RCE
These vulnerabilities are important because Windows regularly processes fonts, images, documents and other multimedia content.
Microsoft Office and Outlook Vulnerabilities
The September security release also contains numerous vulnerabilities affecting Microsoft Office, Outlook, Word and Excel. Several Office vulnerabilities are rated Critical and involve remote code execution.
Examples include:
- CVE-2026-78509 — Microsoft Office Outlook RCE, CVSS 9.8
- CVE-2026-78525 — Microsoft Office Outlook RCE
- CVE-2026-78510 — Microsoft Word RCE, CVSS 9.8
- CVE-2026-81948 — Microsoft Excel RCE
- CVE-2026-81949 — Microsoft Excel RCE
- CVE-2026-81950 — Microsoft Excel RCE
- CVE-2026-81951 — Microsoft Excel RCE
- CVE-2026-81953 — Microsoft Excel RCE
- CVE-2026-81959 — Microsoft Excel RCE
This is another reason users should not install only the Windows cumulative update and assume that everything is patched. Microsoft Office and other Microsoft applications may have separate security updates.
Why Are There So Many Microsoft Vulnerabilities This Month?
The unusually large number of patches is part of a broader trend in 2026. Microsoft has been dealing with an increasing number of vulnerabilities identified through security research and AI-assisted vulnerability discovery. September’s release is substantially larger than recent Patch Tuesday releases. Zerodayinitiative described the September release as a new record and noted that AI-assisted vulnerability discovery continues to increase the volume of security bugs being identified.
This also increases the importance of reducing the time between Microsoft’s release of a security patch and its installation on vulnerable systems.
Windows 11 September 2026 Update
For Windows 11 users, Microsoft released KB5124008 for versions 24H2 and 25H2.
The update changes the OS builds to:
- Windows 11 24H2 — Build 26100.9445
- Windows 11 25H2 — Build 26200.9445
Microsoft says the update includes security improvements and additional targeting data to increase the number of devices that can automatically receive updated Secure Boot certificates. Microsoft currently lists no known issues for the update.
Windows 10 also received the September security update KB5122878. It includes security improvements as well as fixes for Remote Desktop audio redirection and a BitLocker Group Policy issue.
Windows 10 September 2026 Update
For Windows 10 users, Microsoft released KB5122878 as part of the September 2026 security update.
The update changes the OS builds to:
- Windows 10 22H2 — Build 19045.7725
- Windows 10 21H2 — Build 19044.7725
KB5122878 includes the September security fixes, along with improvements to Secure Boot and fixes for a Remote Desktop audio redirection issue and a BitLocker Group Policy problem. The update is available to supported Windows 10 devices, including eligible systems enrolled in the Extended Security Updates (ESU) program.
Should You Install the September 2026 Updates?
Yes. You should install it as soon as it is available for your device. The biggest reason is not the number of vulnerabilities; Microsoft has confirmed that two Windows vulnerabilities are already being exploited in real-world attacks.
Microsoft is rolling out the September 2026 Patch Tuesday updates through Windows Update. Most eligible Windows 11 and Windows 10 devices will receive the updates automatically, but users can also manually check for updates.
To install the latest updates:
- Open Settings by pressing Windows + I.
- Select Windows Update.
- Click Check for updates.
- Download and install any available updates.
- Restart your PC to complete the installation.

If Windows Update isn’t available or you need to update multiple devices, you can also download the standalone installers from the Microsoft Update Catalog.
- Windows 11 KB5124008 (for versions 25H2/24H2) – 64‑bit
- Windows 11 KB5122880 (for versions 23H2/22H2) – 64‑bit
- Windows 10 KB5122878 (for versions 22H2/21H1 via ESU) – 64‑bit and 32‑bit (x86)
You can also:
- Download the Windows 11 ISO if you need to perform an in‑place upgrade or repair install.
- Use the Media Creation Tool or the Windows 11 installation assistant to upgrade supported devices to the latest version of Windows 11 (e.g., 25H2).
Before installing any major update, it’s a good idea to save your work and back up important files. While Windows updates typically install without issues, having a recent backup can help protect against unexpected problems.
If you encounter issues (updates stuck at a certain percentage, error codes during installation, etc.), refer to your Windows 11 Update troubleshooting guide to fix common problems.
Final Takeaway
Microsoft’s September 2026 Patch Tuesday is one of the most significant security releases of the year, addressing 974 vulnerabilities across Microsoft’s product ecosystem. The two most urgent flaws are CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC because both were actively exploited in the wild before Microsoft released the fixes.
The release also includes numerous Critical remote code execution vulnerabilities affecting Windows DNS Server, DHCP Server, Remote Desktop Services, Exchange Server, Office and other Microsoft products.
Windows users and organizations should not delay installing the September 2026 security updates, particularly on systems exposed to the internet or running enterprise services such as RDP, Exchange, DNS and DHCP.
Frequently Asked Questions
Patch Tuesday is Microsoft’s monthly security update release, typically published on the second Tuesday of each month. It delivers security patches, bug fixes, and reliability improvements for Windows and other Microsoft products.
CVE (Common Vulnerabilities and Exposures) IDs are standardized identifiers used to catalog publicly disclosed security vulnerabilities in the National Vulnerability Database (NVD) and other security databases.
Microsoft’s September 2026 security release addresses 974 vulnerabilities, making it one of the company’s largest Patch Tuesday releases. It also includes two actively exploited zero-day vulnerabilities.
Microsoft patched two actively exploited Windows elevation-of-privilege vulnerabilities: CVE-2026-81963 and CVE-2026-85880. Both were being exploited in the wild before the September security updates were released.
For Windows 11 24H2 and 25H2, Microsoft released KB5124008. It includes the September security fixes and other improvements, including changes related to automatic Secure Boot certificate updates.
Microsoft released KB5122878 for supported Windows 10 systems. The update includes September security fixes along with improvements to Secure Boot and fixes for Remote Desktop audio redirection and a BitLocker Group Policy issue.
Yes. The updates include important security patches, fixes for actively exploited zero-day vulnerabilities, and quality improvements for Windows 11 and Windows 10.








