Microsoft Releases Its Largest Patch Tuesday Update Yet
Microsoft released its September security updates on September 8, and this month’s release stands out for its size and urgency.
According to BleepingComputer’s Patch Tuesday count, Microsoft fixed 966 vulnerabilities, making this the largest monthly Microsoft security release reported to date. Of those, 105 were classified as Critical, including 81 remote-code-execution vulnerabilities.
Microsoft’s own security guidance also rates several major product families at the Critical level, including Windows 11, Windows Server, and Microsoft Office, with remote code execution listed as the most severe potential impact for multiple platforms.
The sheer number of vulnerabilities is noteworthy, but the most important part of this month’s update is simpler:
Two vulnerabilities were already being actively exploited before Microsoft released fixes.
Two Actively Exploited Zero-Days
Microsoft patched two actively exploited Windows privilege-escalation vulnerabilities this month.
CVE-2026-81963 — Windows Update Stack Elevation of Privilege
This vulnerability affects the Windows Update Stack.
Microsoft describes the flaw as improper link resolution before file access, which could allow an authorized attacker with local access to elevate privileges. Successful exploitation can result in SYSTEM-level privileges, giving an attacker extremely powerful control over the affected Windows device.
Microsoft has confirmed that the vulnerability has been exploited in attacks, although the company has not publicly disclosed detailed information about how attackers have been using it.
CVE-2026-85880 — Windows ALPC Elevation of Privilege
The second actively exploited vulnerability affects Windows Advanced Local Procedure Call, or ALPC.
ALPC is an internal Windows mechanism that allows processes to communicate with one another.
Microsoft identified the vulnerability as a heap-based buffer overflow that could allow an authorized local attacker to escalate privileges and obtain SYSTEM-level access. Microsoft has also confirmed exploitation of this flaw in the wild.
Again, Microsoft has not released detailed information describing the attacks.
Why SYSTEM-Level Access Matters
A privilege-escalation vulnerability may sound less dangerous than a vulnerability allowing an attacker to remotely compromise a machine from the internet.
But in real-world cyberattacks, privilege escalation is often an important part of the attack chain.
An attacker may initially enter a network through:
- A phishing email
- Stolen credentials
- A malicious attachment
- Compromised remote-access software
- A vulnerable application
- An infected workstation
The attacker may initially have only limited user permissions.
A privilege-escalation vulnerability can then provide a path from an ordinary compromised user account to SYSTEM privileges, which are among the highest permissions available on a Windows device.
Once attackers obtain that level of access, they may be able to disable security tools, dump credentials, install persistence mechanisms, access protected files, move laterally through the network, or deploy additional malware.
This is why actively exploited privilege-escalation vulnerabilities should not be dismissed simply because they require an attacker to already have some level of access.
More Than 100 Critical Vulnerabilities
The two zero-days are not the only reason organizations should prioritize this month’s updates.
BleepingComputer’s analysis of Microsoft’s September Patch Tuesday release identified:
- 438 elevation-of-privilege vulnerabilities
- 258 remote-code-execution vulnerabilities
- 173 information-disclosure vulnerabilities
- 56 denial-of-service vulnerabilities
- 19 security-feature-bypass vulnerabilities
- 16 spoofing vulnerabilities
Of the total vulnerabilities addressed in the Patch Tuesday release, 105 were classified as Critical.
Remote code execution is particularly important because these vulnerabilities can potentially allow an attacker to cause malicious code to run on a vulnerable computer.
Not every remote-code-execution vulnerability is equally exploitable, and some require specific conditions, authentication, or user interaction. However, the number of Critical vulnerabilities this month makes careful patch review especially important for IT administrators.
Windows Servers Need Attention Too
This month’s security release is not limited to employee workstations.
Microsoft lists several versions of Windows Server among the products receiving Critical security updates, including:
- Windows Server 2025
- Windows Server 2022
- Windows Server 2019
- Windows Server 2016
Microsoft identifies remote code execution as the maximum potential impact for these supported Windows Server releases.
Servers often host the most critical services within an organization, including Active Directory, file systems, databases, applications, remote access, and other business infrastructure.
That means server patching needs to be handled carefully, but it should not be ignored.
Organizations should use a structured process that includes testing, backups, maintenance windows, deployment, and verification.
Active Directory Is Included in the September Security Release
The September updates also address multiple vulnerabilities involving Active Directory Domain Services and Active Directory Certificate Services.
The vulnerabilities listed in Microsoft’s September security release include several remote-code-execution and privilege-escalation issues involving these technologies.
For businesses operating traditional Windows domains, these systems deserve particular attention.
Active Directory is often one of the most valuable targets in an enterprise network because compromising it can provide attackers with broad access to users, computers, servers, and administrative privileges.
Certificate Services can also become an important target because certificate-based authentication is increasingly used throughout modern Windows environments.
Exchange and SharePoint Also Received Security Updates
Microsoft’s September security release also covers Microsoft Exchange and SharePoint.
Microsoft lists both products as receiving security updates addressing vulnerabilities capable of remote code execution.
Exchange Server Subscription Edition received a September security update addressing several CVEs.
Administrators should also be aware that Microsoft has documented known issues with the update, including problems involving published .ics calendars and some free/busy scenarios in hybrid Exchange environments using Microsoft Graph.
This is a good example of why patching should be both urgent and controlled.
Security updates need to be installed, but organizations should still review known issues, test where appropriate, and verify important business services after deployment.
Microsoft Office Is Also Rated Critical
Microsoft’s September Office updates include security fixes across supported Office products.
Microsoft recommends that customers install all applicable Office updates and rates the maximum severity for Microsoft Office this month as Critical, with remote code execution as the most severe impact.
Organizations should therefore make sure they are not focusing only on Windows operating-system updates while leaving Office applications behind.
What Businesses Should Do Now
Organizations should treat the September 2026 Microsoft security updates as a priority.
IT administrators should consider the following actions:
- Install September Windows security updates as quickly as practical
- Prioritize systems exposed to higher security risk
- Confirm Windows Server systems are included in the patch cycle
- Review Active Directory and Certificate Services exposure
- Update Microsoft Office
- Apply applicable Exchange and SharePoint security updates
- Review Microsoft’s documented known issues before broad deployment
- Confirm endpoint security products remain healthy after patching
- Reboot systems where required
- Verify successful installation through endpoint-management or RMM tools
- Monitor security alerts for signs of exploitation
Because Microsoft has confirmed that two vulnerabilities are already being exploited, organizations should avoid treating this as a routine update that can simply wait until the next maintenance cycle.
Patch Management Is More Than Clicking “Update”
For small and midsize businesses, one of the biggest challenges is not necessarily downloading updates.
The challenge is making sure every device actually receives them.
Organizations may have:
- Remote laptops
- Computers that remain powered off
- Servers with limited maintenance windows
- Devices that have stopped checking in
- Applications that require testing before updates
- Older operating systems
- Unsupported hardware
- Employees who postpone restarts
A strong patch-management process should identify which machines are missing updates and verify that updates were successfully installed.
Simply assuming that Windows Update handled everything is not enough for a business environment.
Why This Patch Tuesday Deserves Extra Attention
Microsoft releases security updates every month.
September 2026 is different because of the combination of scale and confirmed exploitation.
Nearly 1,000 vulnerabilities were addressed in the Patch Tuesday release alone, more than 100 were classified as Critical, hundreds involve remote code execution or privilege escalation, and two Windows vulnerabilities were already being exploited before the fixes became available.
For attackers, unpatched systems represent opportunity.
Once a security update is released, researchers and cybercriminals can compare patched and unpatched versions of software to better understand what Microsoft changed.
That means the period immediately following Patch Tuesday can be particularly important for organizations that delay updates.
How MicroAdvantage Can Help
MicroAdvantage helps businesses manage and secure Windows endpoints, servers, Microsoft 365 environments, and network infrastructure.
Our managed IT and cybersecurity services can help organizations with:
- Windows patch management
- Server maintenance
- Microsoft 365 security
- Microsoft Defender
- Endpoint detection and response
- Microsoft Intune
- Vulnerability management
- Remote monitoring and management
- Microsoft Entra security
- Backup and recovery
- Cybersecurity monitoring
If your organization is unsure whether its computers and servers received Microsoft’s September security updates, now is the time to verify.
MicroAdvantage can help review your environment, identify missing patches, and strengthen your organization’s overall cybersecurity posture.
Sources & References
Microsoft Security Response Center — September 2026 Security Updates
Microsoft’s official guidance covering affected Windows, Windows Server, Office, Exchange, SharePoint, and other Microsoft products.
https://www.microsoft.com/en-us/msrc/blog/2026/09/202609-security-update
BleepingComputer — Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days
Detailed breakdown of September’s vulnerability count, severity categories, and actively exploited zero-days.
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
Microsoft Support — September 2026 Microsoft Office Updates
Official Microsoft listing of security updates released for supported Office products.
https://support.microsoft.com/en-us/servicing/office/5127194
Microsoft Support — September 2026 Exchange Server Security Update (KB5121608)
Official security update information and known issues for Exchange Server Subscription Edition.
https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5121608