Skip to main content

Microsoft Releases September 2026 Security Updates

Scheduled updates for Microsoft products address 974 vulnerabilities, including 2 zero-day vulnerabilities

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products address 974 vulnerabilities, including 2 zero-day vulnerabilities


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

Multiple other Microsoft platforms including the following product families:

  • Azure
  • Developer Tools
  • Exchange Server
  • Office 2016
  • SharePoint Server
  • Skype for Business
  • SQL

Please see Microsoft's September 2026 Security Updates guide for full details. 

Threat details

Two zero-day vulnerabilities identified

Microsoft states that exploitation of CVE-2026-81963 and CVE-2026-85880 has been reported. NHS England National CSOC assess that future exploitation is highly likely.


Introduction

Microsoft has released security updates to address 974 vulnerabilities in Microsoft products, including the 2 zero-day vulnerabilities highlighted below. Both of the vulnerabilities below have been reported as exploited.

  • CVE-2026-81963 - Windows Update Stack elevation of privilege vulnerability with a CVSSv3 base score of 7.8.
  • CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability with a CVSSv3 base score of 7.8

Remediation advice

Affected organisations are encouraged to review Microsoft's September 2026 Security Updates and apply the relevant updates as soon as possible.



Last edited: 9 September 2026 10:55 am