Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Reported exploitedWindowsOfficeOur summary
Microsoft has published its September 2026 security update, remediating 973 vulnerabilities across its software portfolio, including 113 rated as "critical." Among these, 82 are remote code execution flaws affecting products such as Windows, Office, SQL Server, Azure Cosmos DB, and Spring Cloud Azure.
Notably, Microsoft confirmed active exploitation in the wild for two elevation of privilege issues: CVE-2026-81963">CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880">CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC). Administrators should prioritize patching these components immediately, alongside other high-severity bugs flagged by the vendor as having a higher likelihood of exploitation.
Below is the opening; the full story is at Cisco Talos.
From Cisco Talos
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963">CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963">CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.