Skip to main content
Splashtop20 years of trust
Log inFree Trial
+1.408.886.7177Log inFree Trial
A computer screen showing a calendar with the September 2026 Patch Tuesday highlighted.

September 2026 Patch Tuesday: 974 CVEs, 2 zero-days

9 min read
Updated
Get Started with Splashtop
Top-rated remote access, remote support, and endpoint management solutions.
Free Trial

Microsoft's September 2026 Patch Tuesday release addresses 974 Microsoft CVEs, making it the largest Patch Tuesday release to date. The release spans Windows clients and servers, Microsoft 365 apps, SQL Server, Exchange Server, Azure, developer tools, identity services, remote access components, and core Windows subsystems. Microsoft is also republishing 25 non-Microsoft CVEs.

Two vulnerabilities are already under active exploitation: CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC) and CVE-2026-81963 in the Windows Update Stack. Both are elevation-of-privilege vulnerabilities rated Important, which reinforces why exploit status should take priority over severity labels alone.

With nearly 1,000 Microsoft CVEs to evaluate, IT teams need a risk-based rollout that accounts for active exploitation, system exposure, business criticality, and the role each affected system plays in the environment.

Microsoft patch breakdown for September 2026

Of the 973 CVEs with detailed severity information, Microsoft rated 113 Critical and 860 Important. Microsoft indicates that 964 require customer action, while nine were resolved within Microsoft's cloud infrastructure.

Category

September 2026

Microsoft CVEs addressed

974

Critical

113

Important

860

CVEs requiring customer action

964

Actively exploited zero-days

2

Critical remote code execution vulnerabilities

82

Republished non-Microsoft CVEs

25

Elevation of privilege and remote code execution account for most of the release:

Vulnerability type

Count

Elevation of privilege

438

Remote code execution

258

Information disclosure

173

Denial of service

56

Security feature bypass

19

Spoofing

16

Tampering

13

The large number of elevation-of-privilege and remote code execution vulnerabilities makes it especially important to identify the systems most likely to provide a path to privileged access or broader compromise.

Where the vulnerabilities are concentrated

Windows accounts for most of this month's vulnerabilities, but the release also affects productivity applications and critical server infrastructure.

Product family

Vulnerabilities addressed

Distinct updates

Windows

723

32

Office

111

11

Office 2016

111

18

SQL Server

62

1

Developer Tools

22

36

SharePoint Server

16

3

Azure

12

4

Skype for Business

10

3

Exchange Server

9

4

Other

9

9

Two actively exploited zero-days require immediate attention

Microsoft has confirmed active exploitation of two Windows elevation-of-privilege vulnerabilities.

CVE

Affected component

Severity

Exploit status

Why it matters

CVE-2026-85880

Windows Advanced Local Procedure Call

Important

Exploitation Detected

Successful exploitation can allow an attacker to elevate privileges from a standard user context to SYSTEM.

CVE-2026-81963

Windows Update Stack

Important

Exploitation Detected

Successful exploitation can give an attacker elevated privileges and greater control of a compromised Windows system.

Elevation-of-privilege vulnerabilities typically require an attacker to have some level of access first, but they can help turn limited access into control of the affected system. Because Microsoft has already detected exploitation, both vulnerabilities should move ahead of vulnerabilities prioritized only by severity or theoretical risk.

Critical vulnerabilities to prioritize next

Microsoft rated 113 vulnerabilities Critical, including 82 remote code execution vulnerabilities. Rather than treating them as one uniform group, prioritize them according to the affected infrastructure, its exposure, and the potential impact of compromise.

Windows DNS Server

Six Critical remote code execution vulnerabilities affect Windows DNS Server:

  • CVE-2026-69730

  • CVE-2026-69827

  • CVE-2026-69858

  • CVE-2026-69813

  • CVE-2026-77505

  • CVE-2026-72987

DNS is foundational to Windows networks and Active Directory environments. Prioritize domain-integrated DNS servers and any affected systems that are reachable from untrusted networks.

Identity and domain infrastructure

The release includes Critical remote code execution vulnerabilities in several components at the center of Windows authentication:

CVE

Affected component

CVE-2026-69712

Windows Key Distribution Center

CVE-2026-69676

Windows Kerberos

CVE-2026-72982

Windows Netlogon

Kerberos, the Key Distribution Center, and Netlogon support authentication throughout Windows domains. Domain controllers and other systems supporting identity services should therefore be among the first servers evaluated and patched after the two exploited zero-days.

Remote access and network services

CVE-2026-69518 affects Windows Remote Desktop, while CVE-2026-69590, CVE-2026-72950, CVE-2026-72959, and CVE-2026-69852 affect Windows Routing and Remote Access Service (RRAS).

These components can create high-priority exposure when they are reachable from the internet, connected to VPN services, or accessible from less-trusted network segments. IT teams should identify where the affected services are enabled and move externally reachable or business-critical systems to the front of the queue.

SQL Server and Exchange Server

Four Critical remote code execution vulnerabilities affect Microsoft SQL Server:

  • CVE-2026-67631

  • CVE-2026-67378

  • CVE-2026-67636

  • CVE-2026-67643

Database and messaging systems often contain sensitive business data and may operate with privileged access to other resources. Review affected SQL Server and Exchange Server deployments promptly, prioritizing systems with external exposure, critical workloads, or access to high-value data.

Hyper-V, failover clustering, and deployment infrastructure

The September release also includes Critical remote code execution vulnerabilities in infrastructure that can affect multiple workloads or downstream systems.

CVEs

Affected component

Operational concern

CVE-2026-80083, CVE-2026-69603

Windows Hyper-V

A vulnerable host can put multiple guest workloads at risk.

CVE-2026-78444, CVE-2026-73010

Windows Failover Cluster

Clustered systems often support highly available production services.

CVE-2026-72954, CVE-2026-72957

Windows Deployment Services

Deployment infrastructure can influence many endpoints that rely on it for imaging or provisioning.

Patch timing should account for availability requirements, but the concentration of critical workloads on these systems makes delayed remediation risky. Use staged testing and coordinated maintenance windows where an immediate rollout could disrupt production services.

Microsoft 365 and Office applications

The release includes three Critical Word remote code execution vulnerabilities, six Critical Excel remote code execution vulnerabilities, and four Critical Outlook remote code execution vulnerabilities.

Office applications remain important because malicious files and email content can provide an initial path into user environments. These updates should generally follow exploited vulnerabilities and exposed infrastructure, but organizations with frequent external document exchange or higher-risk user groups may need to accelerate deployment.

How to prioritize September 2026 patches

No fixed timeline fits every environment. Use the following tiers as a starting point, then adjust them based on exposure, affected assets, business impact, available mitigations, and testing requirements.

Patch within 72 hours

Prioritize:

  • CVE-2026-85880 and CVE-2026-81963 because Microsoft has confirmed active exploitation

  • Windows DNS Server vulnerabilities on domain-integrated or externally reachable systems

  • Kerberos, Netlogon, Key Distribution Center, and Active Directory Domain Services updates on identity infrastructure

  • Windows Remote Desktop and RRAS vulnerabilities on exposed or remotely accessible systems

  • Critical SQL Server and Exchange Server vulnerabilities affecting sensitive or externally reachable workloads

  • Windows Deployment Services, Failover Cluster, and Hyper-V vulnerabilities on critical infrastructure

  • Any vulnerability later marked Exploitation More Likely or added to the CISA Known Exploited Vulnerabilities catalog

Move internet-facing systems, domain controllers, VPN gateways, remote access services, and systems handling privileged credentials or critical workloads to the front of this tier.

Patch within 1 to 2 weeks

Prioritize:

  • Microsoft Word, Excel, PowerPoint, Outlook, and SharePoint remote code execution vulnerabilities

  • Media, graphics, codecs, WebP, imaging, and other client-side vulnerabilities

  • Windows Hello, Credential Guard, and other authentication-related elevation-of-privilege vulnerabilities

  • Virtualization and storage systems that do not have edge exposure

  • Visual Studio, Visual Studio Code, PowerShell, and .NET updates on developer endpoints

Exposure and business role should still override the default timeline. For example, a high-risk user group that routinely receives external documents may need Office updates sooner.

Regular patch cycle

Include:

  • Lower-severity vulnerabilities in components with limited exposure

  • Local-access-only vulnerabilities on tightly controlled systems

  • Peripheral and device-driver issues on devices with restricted physical access

  • Non-internet-facing systems protected by effective compensating controls

Severity alone should not determine patch order. Confirmed exploitation, attack path, system exposure, required privileges, business criticality, and the potential effect on other systems provide a more useful basis for prioritization.

Notable third-party updates

Microsoft is republishing 25 non-Microsoft CVEs alongside this month's release. Organizations that manage Microsoft Edge on its Chromium-based release cadence should confirm relevant browser updates independently.

Browser, developer tool, open-source dependency, and third-party application updates should remain part of the same vulnerability-management workflow as operating system updates. Separate processes can create blind spots even when Windows patching is current.

Why September Patch Tuesday matters for IT teams

The September release is more than a large patching event. It exposes three operational challenges that IT teams need to address.

1. Volume makes manual prioritization unrealistic

Nearly 1,000 Microsoft CVEs cannot all receive the same urgency. IT teams need to determine which assets are affected, which vulnerabilities are being exploited, and which systems support identity, remote access, databases, collaboration, or critical workloads.

That assessment depends on accurate asset and software inventory. Without it, teams may spend time on lower-risk updates while exposed systems remain vulnerable.

2. Core enterprise infrastructure is heavily represented

September's updates reach identity services, DNS, remote access, databases, messaging, virtualization, and endpoint operating systems at the same time. This creates overlapping priorities across servers and user devices, with different testing and maintenance requirements for each.

A phased rollout can help teams move quickly on the most exposed systems while testing broader updates before organization-wide deployment.

3. Patch verification matters as much as deployment

Sending an update does not prove that every device is protected. Systems may be offline, installations may fail, or endpoints may miss a deployment window.

IT teams need to see which devices remain vulnerable, which patches succeeded, which failed, and which systems require another deployment attempt or additional remediation.

How Splashtop AEM can help prioritize and deploy patches

A Patch Tuesday release with 974 Microsoft CVEs creates two immediate challenges: identifying what matters in your environment and deploying the right updates quickly. Splashtop AEM helps IT teams manage both from a centralized console.

  • See where the risk is: Splashtop AEM provides centralized visibility into vulnerabilities, patch status, hardware and software inventory, and endpoint health. IT teams can use that context to identify affected devices and understand where urgent remediation is needed.

  • Prioritize the most important vulnerabilities: CVE insights and endpoint-level information help teams focus on exploited vulnerabilities, high-risk software, critical systems, and devices supporting sensitive functions such as identity or remote access.

  • Deploy updates faster: Splashtop AEM supports real-time patching, automated patch policies, scheduled deployment, and ring-based rollouts. Teams can test updates with a smaller device group, expand deployment in stages, and monitor success or failure without losing visibility across the environment.

  • Strengthen existing patching workflows: Teams still handling parts of patching manually can automate repetitive deployment and verification work. Splashtop AEM can enhance Microsoft Intune by adding real-time patching, CVE visibility, and remediation capabilities to their existing environment. Organizations using an RMM can use Splashtop AEM to strengthen patch visibility, automation, and endpoint workflows where additional capabilities are needed.

Respond faster to high-risk vulnerabilities with Splashtop AEM

September's record Patch Tuesday shows how quickly patch management becomes a prioritization and verification problem. IT teams need to identify exposed devices, deploy urgent updates, and confirm remediation without losing track of systems across distributed environments.

Splashtop AEM brings CVE visibility, real-time patching, automation, patch status monitoring, and endpoint insights into one platform.

Start a free trial of Splashtop AEM to identify vulnerable endpoints, prioritize high-risk updates, and deploy patches faster.

Get Started Now!
Try Splashtop AEM for free today
Free Trial


Share This
RSS FeedSubscribe

Related Content

Patch schedule on a computer screen.
Patch Management

How to Build a Smarter Patching Schedule

Learn More
A Windows and Mac computer side-by-side.
Patch Management

How to Simplify Cross-Platform Patching for Windows and macOS

A doctor typing on a computer.
Patch Management

Patch Management for HIPAA Compliance: What IT Teams Need

A central console monitors the patch statuses of several endpoints.
Patch Management

What Is Patch Status? How IT Teams Track Endpoint Updates

View All Blogs