Microsoft Releases September 2026 Security Updates
Scheduled updates for Microsoft products address 974 vulnerabilities, including 2 zero-day vulnerabilities
Summary
Scheduled updates for Microsoft products address 974 vulnerabilities, including 2 zero-day vulnerabilities
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Multiple other Microsoft platforms including the following product families:
- Azure
- Developer Tools
- Exchange Server
- Office 2016
- SharePoint Server
- Skype for Business
- SQL
Please see Microsoft's September 2026 Security Updates guide for full details.
Threat details
Two zero-day vulnerabilities identified
Microsoft states that exploitation of CVE-2026-81963 and CVE-2026-85880 has been reported. NHS England National CSOC assess that future exploitation is highly likely.
Introduction
Microsoft has released security updates to address 974 vulnerabilities in Microsoft products, including the 2 zero-day vulnerabilities highlighted below. Both of the vulnerabilities below have been reported as exploited.
- CVE-2026-81963 - Windows Update Stack elevation of privilege vulnerability with a CVSSv3 base score of 7.8.
- CVE-2026-85880 - Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability with a CVSSv3 base score of 7.8
Remediation advice
Affected organisations are encouraged to review Microsoft's September 2026 Security Updates and apply the relevant updates as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 9 September 2026 10:55 am