September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message

Microsoft’s September 2026 Patch Tuesday is the year’s largest release, with 963 CVEs requiring customer action, 106 rated critical. Two are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call. Nothing in this release was publicly disclosed ahead of the patch. Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange. The Readiness team has published an infographic summarising deployment risk by product family.

Known issues

Three client issues are carried in from August close with this update, covering:

  • Microsoft Teams and the new Outlook failing to launch on ARM devices, such as the Surface Pro 11 and Surface Laptop 7, is resolved by KB5124008. The issue originated in August’s KB5121003 and was most likely on freshly imaged machines that had not yet taken Microsoft Store updates.
  • The same update resolved both desktop backgrounds reverting to solid black and mouse cursor customisation resetting on non-English installations. Both originated in the 27 August preview, KB5120998.

And Microsoft has left open a Microsoft Defender Antivirus notification defect, confirmed on 28 August, in which devices report that Defender is turned off while it is running correctly.

Major revisions and mitigations

The quietest revision window of recent months arrived alongside the largest release. Between the August and September Patch Tuesdays, from 12 August to 7 September, the MSRC Security Update Guide touched 324 CVEs. Of those, 307 were routine Microsoft Edge and Chromium republications requiring no customer action.

That leaves 17 entries affecting Microsoft’s own products, and only one of those is a genuine revision. CVE-2026-59133, an elevation of privilege in the High-Performance Computing Pack, moved to version 1.1, and its own revision note records the change as informational. For comparison, August’s window carried 76 revisions to Microsoft’s own products, 60 of them flagged as requiring customer action.

The Readiness team has reviewed all 963 published updates. Microsoft has published no mitigations and no workarounds anywhere in this release.

Windows lifecycle and enforcement updates

Microsoft has published no new service or enforcement deadlines for September. The lifecycle picture is different, with multiple end-of-support notices for this coming October:

  • The retail Office 2021 family retires in full, including Access, Excel, Outlook, PowerPoint, Project, Publisher, Visio and Word.
  • Office LTSC 2021 reaches end of support, and that includes Skype for Business LTSC 2021.
  • Windows 10 2016 LTSB and Windows 10 IoT Enterprise LTSB 2016 reach the end of extended support.
  • Windows Server 2012 and 2012 R2 reach the end of Extended Security Update Year 3. This is the final ESU year for both, not a step to a fourth.
  • Windows 11 Home and Pro version 24H2 reaches the end of updates.
  • Windows Server 2022 moves from mainstream to extended support, where it stays until 14 October 2031.

A second wave follows on 10 November 2026, and it is the one most likely to catch development teams rather than infrastructure teams. .NET 8 reaches the end of its long-term support branch, PowerShell 7.4 does the same, and Windows 11 Enterprise and Education 23H2 ends servicing alongside Windows 11 IoT Enterprise 23H2.

Microsoft’s test guidance for this release runs to 466 Windows entries, 55 of them flagged as high risk, against 109 and four in August. Given the large number of updates this month (who would have thought that we would be here at 963 CVEs), the Readiness team recommends the following testing priorities:

  • Printing. Print from 32-bit and 64-bit applications to physical and virtual printers, exercise XPS and PDF output, share a printer from a print server and print from a separate client, cancel a job mid-queue, and confirm the queue reflects every state change. This is 20 of the 55 high risk flags, and it is the single most likely source of a visible regression.
  • Fonts, graphics and imaging. Render varied fonts, sizes and styles across browsers, Office, PDF viewers and Notepad, confirm Print Preview matches the printed page, and open JPEG, TIFF, HEIF and raw images across Explorer, Photos and Office. Watch for clipping, distortion and missing glyphs.
  • USB Devices. Exercise device attachment and removal. Attach and remove USB audio, video and mass storage devices repeatedly, including through a hub, pair and unpair a wireless device, and confirm each enumerates and releases cleanly. Device Association carries seven high risk flags, and these drivers load whenever hardware is attached.
  • Remote Desktop. Open several concurrent sessions, enable printer, clipboard, audio, drive and smart card redirection together, disconnect and reconnect, and confirm redirected devices reattach.
  • Storage (ntfs.sys, spaceport.sys). This is a real hotspot for updates this month, but no high-risk changes. Test on hardware you can recover, because the storage changes reach the boot path, potentially resulting in a dead (test) machine.

Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.

Browsers

Microsoft has not released any updates for their browser products for the second month in a row. September’s Security Update Guide carries no Edge-specific CVEs at all, and the 307 Chromium republications in the revision window required no customer action. The nine Edge CVEs that did appear arrived mid-cycle on 28 August and were serviced through the browser’s own update channel rather than this release.

Estates on a managed Edge channel have nothing to do here beyond confirming the channel is current. It is the one quiet corner of an otherwise heavy month.

Microsoft Windows

Windows carries 726 CVEs, 77 of them critical, which is three-quarters of the entire release. Elevation of privilege dominates by volume at 406 entries, with remote code execution second at 156, information disclosure at 94 and denial of service at 47. The pattern is the reverse of the severity picture: the bulk is local elevation, while the critical-rated entries cluster in the network-facing roles.

  • Biometrics is a real focus this month as the Windows Biometric Service takes 64 fixes, the largest single-component count of the year. Most of the security issues are heap overflows that give a local attacker SYSTEM. Windows Hello adds nine, all critical. Patch it promptly on any estate using fingerprint or facial sign-in.
  • Windows DHCP Server leads at 36 entries and is topped by remote code execution at CVSS 9.8. Windows DNS Server takes 10 more, also reaching 9.8. Critical remote code execution also lands on Message Queuing, RRAS, Services for NFS, the HTTP Print Provider, Windows Shell, Netlogon, Internet Connection Sharing, SSTP and Failover Cluster, all at 9.8. Patch the resolvers, the DHCP servers and the domain controllers first.
  • Storage is the heaviest it has been this year. NTFS takes 29 fixes, Spaceport.sys behind Storage Spaces takes 17, and the Overlay Filter takes seven, with the Volume Manager, VHD miniport, iSCSI and Storage Port drivers behind them. These reach the boot path, so stage them on recoverable hardware.
  • The rest of the most-patched tally runs Win32k at 19, Microsoft Standard XPS at 18, Windows Error Reporting at 12, and the Windows Kernel, Windows Search, the Print Spooler and the Device Association Service at 11 each.

Add this Windows update to your Patch Now schedule, with DHCP and DNS servers first and the biometric stack close behind.

Microsoft Office

Microsoft released 137 Office CVEs this month, 24 of them critical, with remote code execution the through-line at 69 entries and information disclosure close behind at 52. September breaks the recent pattern in a way that matters for deployment: this wave is not MSI-only.

  • Click-to-Run estates are squarely in scope. Roughly 105 of the Office CVEs reach Click-to-Run, so Microsoft 365 Apps, Office 2019, LTSC 2021 and LTSC 2024 all update, on Windows and on Mac. Word takes 35 fixes, Excel 32, PowerPoint 10 and Outlook seven. The heaviest client entries are CVE-2026-78510 in Word and CVE-2026-78509 in Outlook, both critical remote code execution at CVSS 9.8, in document-rendering paths that fire on preview or open.
  • SharePoint Server Subscription Edition takes 16 entries and is the only SharePoint baseline with a package this month. Server updates cannot be uninstalled and always require a reboot, so validate in a maintenance window.
  • Skype for Business Server takes 10 entries, led by CVE-2026-66302, a critical remote code execution at CVSS 9.8. Patch it and note that the LTSC 2021 edition leaves support on 13 October 2026.

Nothing in Office is exploited this month. With 24 critical-rated entries and the Click-to-Run channel carrying most of the exposure, the September Office updates belong on the Patch Now schedule regardless.

Microsoft Exchange and SQL Server

Exchange is quiet and SQL Server is not, which inverts the usual relationship between the two.

  • Exchange Server takes nine CVEs across 2016 CU23, 2019 CU14 and CU15, and Subscription Edition. None is critical and none is exploited, though the highest reaches CVSS 9.3. The mix runs to two remote code execution entries, two elevations of privilege, two spoofing, and one each of tampering, denial of service and information disclosure. Apply the update from an elevated command prompt, because an un-elevated run leaves Exchange services partially patched and broken, then confirm mail flow, Autodiscover and any hybrid connection before returning the server to service.
  • SQL Server takes 62 CVEs, four of them critical, across the 2017, 2019, 2022 and 2025 branches. There is no 2016 package this month. Remote code execution leads at 24 entries, with information disclosure at 22. The critical entries are CVE-2026-67631 and CVE-2026-67643 at CVSS 8.8, and CVE-2026-67378 and CVE-2026-67636 at 8.5.
  • Eight SQL packages ship, a CU+GDR and an RTM+GDR for each branch: 2025 (KB5122769, KB5122770), 2022 (KB5122768, KB5122771), 2019 (KB5122772, KB5122773) and 2017 (KB5122774, KB5122775). Microsoft’s guidance is explicit that the baseline or RTM version must be installed first and the GDR patch applied on top; test the install and the removal on every servicing branch you run, then restart the service and confirm Always On availability groups stay healthy.

Exchange goes on the Schedule list, and SQL Server goes on the Patch Now list. That is an unusual split, and it is driven by the four critical remote code execution entries on the database estate.

Microsoft Developer Tools

Microsoft released 24 CVEs across its developer tooling this month, 23 rated important and one critical. Security feature bypasses are the main focus with eight CVE entries, with remote code execution and information disclosure at four each.

  • The single critical entry is CVE-2026-34182 at CVSS 9.1, a flaw in CMS AuthEnvelopedData processing that allows forged messages to be accepted. It reaches Visual Studio 2017 through 2022.
  • The highest-scoring entry in this family is not the critical one. CVE-2026-81376, a Visual Studio Code security feature bypass, reaches CVSS 9.6 while carrying an important rating. It is a useful reminder that severity labels and CVSS scores answer different questions.
  • Visual Studio Code and its Copilot extensions take 10 entries, mostly security feature bypasses. Update the editor and confirm workspace trust prompts, extension installation and remote sessions behave as configured.
  • .NET ships SDK updates on all three supported lines, x64 and x86: 8.0.131 and 8.0.425, 9.0.121 and 9.0.318, and 10.0.112 and 10.0.401. Install them, then build and run a representative project to check for regressions. Keep the 10 November date for .NET 8 in view while you are in there.
  • The .NET Framework ships monthly rollups per operating system: Windows Server 2012 (KB5126147), Server 2012 R2 (KB5126148), Windows 10 1809 (KB5126144), 21H2 (KB5126145), 22H2 (KB5126146) and Server 2022 (KB5126149). One gap worth noting: the 4.7.2 package for Windows 10 1607 is listed as pending and will follow, so estates still on 1607 will not complete their Framework patching this cycle.

Add these to your standard release schedule, behind this month’s Windows, Office and SQL Server priorities. Keep the 10 November date for .NET 8 and PowerShell 7.4 in view while you are in the developer estate, because a patch this month does not extend either branch.

Adobe (and third-party updates)

September is the largest release of the year, and this (crazy, super high) volume is the least interesting thing about it. The 963 CVEs matter less than the 55 entries Microsoft flags as high risk, and those sit in printing and fonts. Adobe shipped two Acrobat builds one digit apart and only the second is a security update (nothing to worry about here). Of the CVEs Microsoft republished, 25 are not Microsoft’s. A version number tells you very little about the work in front of you. So, given my (super-secret knowledge) of how Microsoft operates over the summer, here is my prediction for next month (October). It won’t be as big as this month – but just you wait – November is going to be big. Let’s up those numbers (or not).

Read more: September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message

Story added 14. September 2026, content source with full text you can find at link above.