A cybersecurity operator faces a glowing Windows shield splitting blue defense from red hooded hackers.
Microsoft’s September 2026 security release deserves urgent attention less because of any single headline CVE total than because it fixes two Windows elevation-of-privilege vulnerabilities already exploited in the wild. For Windows administrators, that changes the first question from “how large was this Patch Tuesday?” to “which systems can an attacker turn into SYSTEM-level footholds after gaining a foothold?” At the same time, a critical Windows DNS Server remote-code-execution vulnerability and several other reported network-exposed issues make exposure-based prioritization essential.

The apparent scale of the release is substantial, but the exact number is not settled across contemporary reporting. That is not merely a pedantic discrepancy: security teams using monthly totals for risk dashboards, staffing decisions, or patch SLAs should avoid treating one vendor’s count as an official, universally comparable fact. The durable operational facts are clearer: the exploited flaws affect Windows local privilege boundaries, while the DNS Server issue is a potentially far more exposed server-side risk where the affected role is deployed.

Two exploited Windows flaws should lead endpoint triage​

The two vulnerabilities identified as actively exploited are:

  • CVE-2026-81963, an elevation-of-privilege issue in the Windows Update Stack.
  • CVE-2026-85880, an elevation-of-privilege issue in Windows Advanced Local Procedure Call (ALPC).

Both are rated Important with a CVSS score of 7.8 in reporting based on Microsoft’s advisories. Both are described as capable of yielding SYSTEM-level privileges when successfully exploited. Microsoft indicated that the vulnerabilities had been exploited, and Canada’s Cyber Centre reported that CISA added both to its Known Exploited Vulnerabilities catalog on September 8, 2026.

That combination warrants a focused interpretation. Neither flaw is described in the available material as an unauthenticated, network-reachable remote-code-execution bug. These are local elevation-of-privilege vulnerabilities: an attacker generally needs some ability to execute code or otherwise establish a position on a target machine before attempting to elevate privileges. They are therefore not equivalent to a wormable network service defect.

They are still serious. SYSTEM is among the most powerful security contexts on Windows. A malicious process that begins with a limited user context may use a privilege-escalation flaw to interfere with security tooling, access protected areas of the operating system, establish stronger persistence, or expand what it can do on that endpoint. In a realistic intrusion chain, local privilege escalation can convert a modest compromise into a much more damaging one.

The technical descriptions also help distinguish the two issues. CVE-2026-81963 involves link following in the Windows Update Stack. CVE-2026-85880 is reported as a heap-buffer-overflow issue in ALPC, a Windows interprocess communication mechanism. Available reports do not disclose exploitation mechanics or the scope of attacks, so organizations should not infer a particular threat actor, delivery method, or campaign from the “exploited” designation alone.

For enterprises, the immediate response should be to identify devices that have not received the September security updates, with particular attention to endpoints where compromise would have disproportionate consequences: administrator workstations, jump hosts, shared devices, developer systems, and machines handling sensitive data. Organizations should also investigate credible signs of a pre-existing endpoint intrusion. Patching closes the known vulnerability, but it does not by itself evict an attacker who may already have used a flaw to gain elevated access.

The DNS Server flaw changes the server-side risk picture​

CVE-2026-69730 is a separate priority case. It is a critical remote-code-execution vulnerability in Windows DNS Server with a CVSS score of 9.8. Microsoft assessed exploitation as more likely, according to contemporaneous security reporting. Tenable’s description of the advisory says an unauthenticated remote attacker could send a crafted packet that exploits a use-after-free condition.

This represents a materially different exposure model from the two exploited elevation-of-privilege vulnerabilities. A vulnerable DNS Server that is reachable by an untrusted party may offer an attacker an initial entry path rather than simply a means to deepen an existing compromise. The appropriate urgency depends on whether the DNS Server role is installed and how the service is exposed—not every Windows machine runs it, and not every DNS server accepts traffic from untrusted networks.

Administrators should first establish applicability. Inventory systems carrying the Windows DNS Server role, determine which interfaces and networks can reach them, and prioritize externally exposed or broadly reachable infrastructure. Segmentation, restrictive firewall rules, and limiting DNS service exposure remain valuable defensive controls, but they should not be treated as substitutes for applying the security update where the vulnerability applies.

A useful practical distinction is this:

  • The two exploited CVEs demand fast endpoint patching because they are already known to have been used and can raise attacker privileges to SYSTEM.
  • The DNS Server CVE demands urgent review because it is critical, assessed as more likely to be exploited, and may be reachable over the network on affected servers.

The order in which a particular organization deploys updates may differ. A company with no Windows DNS Server deployment has no direct exposure to that issue, while a company operating reachable Windows DNS infrastructure may put it at the top of its emergency maintenance queue. Conversely, a heavily targeted organization with many unpatched user endpoints may treat the known-exploited local flaws as its most immediate concern. This is why severity alone is an incomplete patch-prioritization metric.

A large release, but no single uncontested CVE count​

Cisco Talos characterized the September release as including 973 vulnerabilities, 113 of them critical, and stated that 82 of its critical count were remote-code-execution vulnerabilities. Those are useful figures for understanding Talos’s analysis and related detection coverage, but they should not be repeated as an unqualified Microsoft-wide total.

Other contemporary assessments arrived at different results: 964 CVEs with 104 critical findings; roughly 972 with 112 critical; and 997 with 114 critical when external and Chromium vulnerabilities were included. These differences do not establish that one analyst is necessarily wrong. They demonstrate that security-update counts depend on methodology, timing, and scope.

Some counts can exclude flaws fixed earlier in the month rather than on Patch Tuesday itself. Others can include external or Chromium-related vulnerabilities alongside Microsoft vulnerabilities. In a release approaching a thousand tracked issues, even a narrow difference in inclusion rules can move the public headline significantly.

For IT leaders, the practical lesson is to record a source, date, and counting definition whenever a monthly total is used in governance reporting. “September updates addressed 973 vulnerabilities” overstates precision unless the organization means specifically the Talos-defined set. A more defensible statement is that the September release was exceptionally large, with contemporary counts varying according to inclusion criteria.

The same restraint applies to the claimed total of critical RCE bugs. Talos reported 82 within its critical set, while another report used a different scope and reported 81 critical RCEs. Without a fully reconciled CVE-level dataset and documented inclusion rules, the apparent one-bug difference is not decision-useful. The relevant decision is to identify RCEs that apply to the organization’s deployed products and are exposed to attackers.

Other server and application risks need applicability checks​

Independent analysis highlighted a cluster of potentially wormable, unauthenticated RCE issues and called attention to CVE-2026-55007 in Exchange Server. It also identified areas such as SharePoint, SQL Server, and Remote Desktop Services as deserving prioritization where deployed.

These observations should guide review, not replace asset-based assessment. “Potentially wormable” is a meaningful warning about propagation risk under the right conditions, but it does not mean every organization is exposed, nor does it prove active exploitation. The dossier does not provide a verified exhaustive CVE-by-CVE inventory, product mapping, or configuration analysis for all September fixes. Administrators should therefore avoid applying a generic “patch everything critical first” rule without considering which affected services they actually run, how those services are reachable, and what compensating controls are in place.

For example, an Exchange Server issue may be a first-order priority for an organization operating on-premises Exchange, but irrelevant to an organization without that product. A Remote Desktop Services weakness matters most where the service is enabled and reachable. SQL Server and SharePoint risks should be ranked according to installed versions, hosting arrangements, network paths, and the sensitivity of the applications they support.

This does not argue for delaying patches while conducting a perfect inventory. It argues for parallel work: rapidly deploy broadly applicable Windows updates, while an infrastructure team identifies exposed high-value server roles and routes those systems through the fastest safe maintenance process.

Snort coverage adds a detection layer, not a patch substitute​

Cisco Talos announced Snort rules intended to detect attempts to exploit some vulnerabilities covered by the September disclosures. The listed coverage includes these ranges:

  • Snort 2 SIDs 67011–67032 and 67036–67084.
  • Snort 3 SIDs 301619–301629, 301632–301655, and 67046.

This can be useful to security operations teams that run the relevant Snort deployments. Network detection can provide another opportunity to identify malicious traffic, support investigation, and validate whether suspicious activity reaches monitored segments.

However, the announced rules are not evidence that every September vulnerability has a matching signature. Talos says the coverage applies to only some disclosed issues, may change, and may be expanded. The available material also does not map individual SIDs to individual CVEs. Teams should not assume a listed rule range detects either of the known-exploited local privilege-escalation vulnerabilities, or that an absence of alerts proves a system is safe.

This limitation is especially important for local elevation-of-privilege flaws. Depending on the technique and where telemetry is collected, network intrusion detection may have little or no visibility into exploitation occurring entirely on a host. Endpoint telemetry, process monitoring, privilege-use alerts, and careful investigation of suspicious local activity are likely to matter more for detecting post-compromise behavior. For network-facing server bugs, network signatures may be more directly relevant, but they remain a supplementary control rather than remediation.

A practical Windows patch plan​

A proportionate response to this release can be organized around exposure and known exploitation:

  • Confirm September update deployment status across supported Windows endpoints and servers. Escalate systems missing the relevant security updates.
  • Prioritize the two known-exploited Windows elevation-of-privilege fixes on high-value endpoints and systems where attackers could use a limited foothold to gain SYSTEM.
  • Identify Windows DNS Server installations immediately and rank them by network reachability. Treat exposed or broadly reachable servers as urgent candidates for remediation.
  • Review deployed server applications and roles flagged in independent analysis, including Exchange Server, SharePoint, SQL Server, and Remote Desktop Services. Apply updates based on actual product applicability and exposure.
  • Use available Snort coverage appropriately, updating and validating applicable rule sets while recognizing that signatures are partial and can change.
  • Look for signs of compromise, especially on devices that remained unpatched after disclosure. A known-exploited elevation-of-privilege bug is a reason to revisit endpoint detections and incident-response triage, not just update compliance.
  • Document the counting methodology used in management reports. Describe the release as a very large update cycle and avoid presenting a disputed CVE number as a definitive official total.

September 2026 is a case where precise public CVE arithmetic is less important than disciplined action. The confirmed high-priority facts are enough to support urgent work: two Windows local privilege-escalation vulnerabilities were actively exploited, a critical Windows DNS Server RCE carried a high severity and a more-likely exploitation assessment, and the broader release contains numerous issues that should be ranked against each organization’s actual software footprint. Fast patch deployment, exposure-aware server triage, and detection-informed monitoring are the appropriate response.


Update: New details narrow the highest-risk server and sandbox scenarios (September 9, 2026)​

TechRepublic reports that CVE-2026-85880 may enable an attacker to escape a low-privilege AppContainer and obtain SYSTEM privileges, according to Action1’s Mike Walters. That makes the ALPC flaw particularly relevant where applications or browser-related processes rely on sandboxing as a containment layer.

The outlet also reports that CVE-2026-81963 can be exploited by a low-privileged local attacker without user interaction, according to Action1’s Jack Bicer. This reinforces the need to patch systems where attackers could already have a basic local foothold, rather than treating the flaw as a standalone remote-entry vulnerability.

For servers, TechRepublic says CVE-2026-55007 in Exchange Server requires the server to process a malicious Visio attachment and sustained low-memory conditions. That constraint may make exploitation harder than for broadly reachable infrastructure bugs, but organizations running on-premises Exchange should still assess exposure and maintenance status.

The report also identifies DHCP, Netlogon, NFS and Remote Desktop Services among infrastructure components needing exposure-based prioritization alongside Windows DNS Server.


Update: Report flags Outlook, Remote Desktop and Kerberos as added September priorities (September 11, 2026)​

The Next Web reports that the September release includes several additional high-severity issues that may change patch sequencing for organizations with exposed Microsoft services. It identifies CVE-2026-78509, a CVSS 9.8 Outlook vulnerability reportedly triggerable through the Preview Pane, and CVE-2026-69525, a separate 9.8-rated Remote Desktop Services flaw.

The outlet also reports that CVE-2026-69676 affects Kerberos on domain controllers and could allow a domain user to execute code through a crafted request. Microsoft reportedly assesses exploitation of that issue as more likely, making rapid review particularly important for Active Directory infrastructure.

Contrary to the earlier description suggesting a low-memory prerequisite, The Next Web says Exchange Server CVE-2026-55007 can be triggered when a server processes an email carrying a malicious Visio attachment, without a user opening it. The report says Microsoft considers exploitation unreliable, but organizations operating on-premises Exchange should treat mail-flow exposure and patch status as urgent review items.

Finally, the report cites Zero Day Initiative analysis classifying 20 September vulnerabilities as potentially wormable across services including DHCP, DNS, Netlogon, Message Queuing and SMB. That characterization reinforces the need to prioritize reachable infrastructure roles, especially domain controllers and servers accepting traffic beyond tightly trusted network segments.


Update: September patches reportedly disrupt Remote Desktop and Plan9 folder sharing (September 11, 2026)​

Neowin reports that Microsoft has confirmed a serious post-update issue affecting Remote Desktop Services after the September security updates. Affected servers may see intermittent RDP connection failures, sign-in problems, or stalls at “Please wait for the Remote Desktop Configuration.” Related tools, including MMC, RDS Licensing Diagnoser, File Explorer, and Windows Update, may also become unresponsive.

The reported impact spans Windows Server 2012 through Windows Server 2025, plus supported Windows 10 and Windows 11 releases. Microsoft reportedly has no administrator-applied workaround beyond contacting Microsoft Support for Business and says a future Windows update will address the problem.

Separately, the same report says HCS-managed Linux virtual machines can lose access to Windows-host folders shared through Plan9. This can affect WSL and software dependent on those mounted shares, including Claude Cowork, on supported Windows 11 versions.

For IT teams, this adds deployment-risk management to the existing security urgency: test the September updates carefully on RDS hosts and Windows 11 systems using WSL or HCS-managed VMs, maintain console access and rollback plans, and monitor Microsoft’s update channels for an out-of-band or cumulative fix.


Update: September update now linked to USB Audio Class 1.0 failures on Windows 11 (September 12, 2026)​

Neowin reports that Microsoft has added a further known issue affecting Windows 11 clients after the September security updates: USB Audio Class 1.0 devices can fail with a Device Manager Code 10 error, resulting in no audio output.

According to Microsoft’s reported assessment, the issue affects Windows 11 versions 24H2, 25H2, and 26H1, but not Windows Server. Symptoms can include unresponsive volume controls and failures of multichannel or 3D-audio features, in addition to complete loss of sound from affected USB devices.

Microsoft is investigating a permanent correction and has not provided a release date. Some users have reportedly restored basic audio by changing a multichannel configuration to standard two-channel output, though that is a limited workaround rather than a fix.

For IT teams, this adds another client-side validation point before broad rollout of the September updates. Organizations using USB headsets, audio interfaces, conferencing peripherals, or specialized multichannel audio equipment should test affected Windows 11 builds, retain an alternative audio path for critical users, and avoid removing the security updates solely to address the issue.


Update: KB5124008 reportedly linked to boot, VPN and backup failures (September 12, 2026)​

Pasquale Pillitteri reports that Windows 11 cumulative update KB5124008 is also being associated with boot failures, corporate VPN authentication problems and File History backup disruptions. The report says some affected devices show a black screen after sign-in, while others enter reboot loops with Secure Boot-related error 0xc0430001.

According to the outlet, the boot issue appears concentrated on some HP laptops with undersized Windows Recovery Environment partitions, while virtual desktop, Citrix, FSLogix and Remote Desktop environments may be more vulnerable to the reported post-login black-screen behavior. It also reports domain-trust failures for some Windows 11 25H2 clients connecting through VPN, including error 1786, plus certificate-authentication failures affecting Always On VPN.

The same report lists File History backups to external drives among the additional problems. These claims have not been independently corroborated here, but they add further reason for administrators to use staged deployment for KB5124008, verify recovery-partition capacity, and test VPN, virtual-desktop and backup workflows before fleet-wide rollout.

Where systems are already failing to boot or cannot support critical business access, the report says uninstalling the update may restore service. That should be treated as a temporary, risk-managed rollback: removing it would also remove fixes for the actively exploited Windows elevation-of-privilege vulnerabilities covered in this article.


Update: RDS failures reportedly tied to specific Server 2019, 2022 and 2025 updates (September 13, 2026)​

gHacks reports that the Remote Desktop Services disruption is affecting Windows Server 2019 after KB5122876, Windows Server 2022 after KB5122882, and Windows Server 2025 after KB5122871. Administrators reportedly see RDS work normally for several hours after installation before sessions begin to hang, fail to log off, or prevent new users from connecting.

The report adds that restarting a server may not restore access in every case; affected environments have reportedly required a hard reset or removal of the September cumulative update. gHacks says Microsoft is aware of the reports and investigating, but has not confirmed a root cause or provided a fix timeline.

Some administrators have suggested a deadlock involving Remote Desktop and the Local Session Manager during session logoff, but this remains unconfirmed. For RDS and terminal-server operators, the delayed onset means post-deployment checks should extend beyond a basic reboot and initial connection test. Monitor logoffs, reconnects, and multi-user session behavior for at least a full business cycle.

Rolling back may restore service, but it also removes September’s security fixes, including protections for the actively exploited elevation-of-privilege vulnerabilities discussed above.


Update: Reports add microphone failures to the USB Audio issue (September 14, 2026)​

Gigazine reports that some Windows 11 users affected by the September update’s USB Audio Class 1.0 problem are also experiencing microphone failures, citing reports shared by Windows Latest. This is not yet a separately confirmed Microsoft-known issue, but it broadens the possible impact beyond lost speaker or headset output.

For organizations relying on USB conferencing headsets, desktop microphones, or audio interfaces, testing should now include both playback and microphone capture after deployment of KB5124008. Verify Teams, Zoom, softphone, recording, and voice-authentication workflows—not only Windows volume controls and Device Manager status.

The reported workaround of switching affected devices to standard two-channel audio may restore playback in some cases, but it should not be assumed to restore microphone functionality.


Update: Isolated AMD Radeon instability report lacks a confirmed KB5124008 link (September 14, 2026)​

Windows Report says one user has reported severe AMD Radeon driver timeouts, display signal loss and system freezes on two AMD-based PCs after installing Windows 11 KB5124008 and the KB5126052 .NET update.

The report is not yet evidence of a confirmed Windows update compatibility issue. The affected user reportedly saw the instability persist after removing both September updates and reverting AMD driver versions, making a direct connection to either KB difficult to establish. Microsoft and AMD had not acknowledged the problem at publication.

Disabling AMD audio drivers reportedly reduced full-system crashes but did not eliminate driver timeout warnings or instability. Administrators supporting Radeon-equipped Windows 11 systems should treat this as an isolated report for now, while monitoring for corroborating cases and testing graphics, display and conferencing-audio workflows during staged deployment.


Update: Microsoft confirms Excel paste failures after September security updates (September 14, 2026)​

Microsoft has added an Office-side compatibility issue to the September patch fallout: pasting can fail silently in Excel 2016, Excel 2019, Excel 2021, and Excel 2024 after installation of security updates. As reported by The Register, the source content can remain selected while the destination cell or range is unchanged, with no error message or other visible warning.

This is operationally significant because a silent failure can compromise spreadsheet-based workflows without being immediately noticed. Finance, reporting, data-entry, and administrative teams should validate copy-and-paste behavior in affected Excel installations, particularly where users rely on manual transfer of values between workbooks or into business systems.

Microsoft has not published a workaround or fix timeline. Reports of removing and reinstalling Office or uninstalling the relevant security update are not a universal remedy and should be treated cautiously: removing the update also withdraws the Excel security fixes it delivered.

The newly confirmed Excel issue is separate from the already documented Remote Desktop Services and USB Audio Class 1.0 problems. Administrators should add Office application testing to staged deployment plans and communicate the potential paste failure to affected user groups while monitoring Microsoft’s update channels for remediation.


Update: Microsoft reportedly offers Known Issue Rollback mitigation for RDS disruption (September 14, 2026)​

Contrary to earlier reports that administrators had no self-service mitigation beyond removing the September updates, Petri reports that Microsoft has published Known Issue Rollback policies for the Remote Desktop Services problem. The policies are intended to help enterprise customers mitigate the instability while Microsoft investigates a permanent correction.

According to Petri, affected servers can experience delayed RDS failures after appearing healthy post-installation: existing sessions may hang, users may be unable to disconnect, and new RDP connections can fail. Microsoft’s acknowledged symptoms also include sign-in problems, stalls during Remote Desktop Configuration, and unresponsive management tools.

For virtual machines that become inaccessible, Microsoft reportedly says that stopping and restarting the affected VM may temporarily restore connectivity. That is a recovery measure rather than a resolution, and administrators should still monitor session lifecycle behavior after service returns.

Organizations should review the applicable Known Issue Rollback policy before broadly uninstalling security updates. Update removal may restore RDS availability, but it also withdraws September’s protections, including fixes for the actively exploited Windows elevation-of-privilege vulnerabilities covered in this article.


Update: Microsoft issues out-of-band updates for September patch disruptions (September 14, 2026)​

Microsoft has released emergency out-of-band cumulative updates to address several September Patch Tuesday compatibility problems, Neowin reports. The releases target the Remote Desktop Services disruption, failures affecting Hyper-V-managed Linux virtual machines and shared folders, and the Windows 11 USB Audio Class 1.0 issue.

For Windows 11, the new packages are KB5129194 for version 26H1 and KB5129195 for versions 25H2 and 24H2; hotpatch-eligible 25H2 and 24H2 devices can use KB5129241 without a restart. The updates are available through Windows Update, Windows Update for Business, the Microsoft Update Catalog, and WSUS synchronization.

Microsoft has also issued corresponding packages for Windows Server 2025, Server 2022, Server 2019, Server 2016, Server 2012 R2 and Server 2012, alongside Windows 10 and LTSC releases. Windows 11 23H2 and Windows 10 22H2 ESU devices reportedly receive the remediation as an optional non-security update.

This supersedes the earlier position that administrators might need Known Issue Rollback policies or update removal to address RDS instability. Organizations should test and deploy the applicable out-of-band package promptly, particularly on RDS hosts, Windows 11 systems using WSL or HCS-managed virtual machines, and endpoints reliant on affected USB audio hardware.


Update: KB5129195 reportedly does not resolve Windows 11 secure-channel domain failures (September 15, 2026)​

Neowin reports that the out-of-band update KB5129195 does not fix all domain-authentication problems linked to Windows 11 KB5124008. Administrators reportedly continue to see broken secure-channel trust relationships on Windows 11 25H2 domain-joined PCs, including ERROR_NO_TRUST_LSA_SECRET during Netlogon checks. Reports include environments using both Windows Server 2019 and Windows Server 2022 domain controllers.

This narrows the earlier rollout guidance: deploying the out-of-band update may address the documented RDS, virtual-machine sharing, and USB Audio failures, but it should not be assumed to remediate Secure Channel or VPN-related domain-login issues. Neowin says affected organizations restored operation by removing KB5124008 and repairing or rejoining devices to the domain.

The report also points to Machine Identity Isolation, a Credential Guard-related setting, as a possible contributor. Some administrators reportedly avoided uninstalling KB5124008 by disabling that feature through Group Policy and then repairing the secure channel. Microsoft had not acknowledged this issue at publication, so IT teams should treat the workaround as environment-specific, validate its security implications before broad use, and continue staged testing of domain authentication, VPN access, and Netlogon health after applying either KB5124008 or KB5129195.

 

References

  1. Microsoft Fixes 974 Flaws in Record Patch Tuesday - TechRepublic TechRepublic 2026-09-09T15:12:40+00:00
  2. Microsoft patches a record 974 flaws, and two are already under attack - The Next Web The Next Web 2026-09-10T17:29:00+00:00