Microsoft September 2026 Updates Fix a Record 973 Security Vulnerabilities

news
Microsoft September 2026 Updates Fix a Record 973 Security Vulnerabilities

Microsoft's September 2026 security updates address 973 newly disclosed vulnerabilities across Windows, Office, Exchange Server, Defender, Hyper V, Visual Studio, Skype for Business, and several cloud services.

The total is more than double the previous month's count and sets a new record for Microsoft's monthly security fixes. Of the 973 vulnerabilities, 113 are rated critical, including 83 remote code execution flaws.

Two Windows vulnerabilities are already being exploited in active attacks, increasing the importance of installing the latest updates promptly.

Windows accounts for more than 700 of the fixes

More than 700 of the September vulnerabilities affect supported versions of Windows 10, Windows 11, and Windows Server.

Two high risk Windows flaws have already been observed in the wild.

VulnerabilityAffected areaMain risk
CVE 2026 81963Windows Update stackElevation of privilege
CVE 2026 85880Windows ALPCElevation of privilege
CVE 2026 69525Remote Desktop ServiceRemote code execution
CVE 2026 69727Windows HelloPrivilege escalation over network
CVE 2026 73008Windows HelloPersonal data exposure
CVE 2026 55007Exchange ServerRemote code execution
CVE 2026 69355Exchange ServerRemote code execution

CVE 2026 81963 affects the Windows Update stack and can allow an attacker to gain elevated system privileges when combined with another exploit.

CVE 2026 85880 affects Windows Advanced Local Procedure Call. The exploit reportedly needs to be embedded inside a document that a person then interacts with.

Microsoft has not disclosed how widespread attacks using either vulnerability currently are.

Remote Desktop and Windows Hello receive major fixes

Microsoft classified 77 Windows vulnerabilities as critical, including 56 remote code execution issues.

One of the more serious flaws is CVE 2026 69525 in Windows Remote Desktop Service. It is described as a use after free vulnerability that could allow an attacker to execute code remotely without authentication or user interaction.

Windows Hello also received a large set of security fixes.

Microsoft patched 64 vulnerabilities affecting the biometric service. Many follow similar patterns, including 56 buffer overflow issues.

Nine Windows Hello vulnerabilities are highlighted separately, with eight rated critical elevation of privilege flaws.

The scale of the fixes makes biometric authentication one of the more heavily patched Windows components this month.

Office receives 137 security fixes

Microsoft Office accounts for another 137 vulnerabilities in the September update.

Among them are 22 critical remote code execution flaws, including five affecting Excel.

Some critical Office vulnerabilities can reportedly be triggered through the preview pane, meaning a malicious document may not always need to be opened manually for exploitation to occur.

Other high risk Office flaws require a person to open a specially prepared file.

SharePoint also received 16 fixes, including six remote code execution vulnerabilities.

Exchange Server has nine high risk flaws

Microsoft patched nine vulnerabilities in Exchange Server, all rated high risk.

Two of them, CVE 2026 55007 and CVE 2026 69355, can enable remote code execution.

CVE 2026 55007 is particularly notable because an attacker may only need to send an email containing a malicious Visio file. The exploit can reportedly trigger while Exchange processes the message, without requiring the recipient to open or preview it.

Edge security updates are counted separately

Microsoft Edge also received security updates, but its Chromium based vulnerabilities are not included in the 973 flaw total.

Edge version 152.0.4191.66, released on September 4, addresses a separate zero day vulnerability along with additional Chromium security issues.

With two Windows flaws already under active exploitation and more than 100 critical vulnerabilities fixed across Microsoft's products, installing the September security updates is particularly important for supported Windows and Office systems.

Microsoft's next scheduled Patch Tuesday is October 13, 2026.

Discover: News

Discussion (0)

Be the first to comment.