Microsoft's September 2026 security updates address 973 newly disclosed vulnerabilities across Windows, Office, Exchange Server, Defender, Hyper V, Visual Studio, Skype for Business, and several cloud services.
The total is more than double the previous month's count and sets a new record for Microsoft's monthly security fixes. Of the 973 vulnerabilities, 113 are rated critical, including 83 remote code execution flaws.
Two Windows vulnerabilities are already being exploited in active attacks, increasing the importance of installing the latest updates promptly.
Windows accounts for more than 700 of the fixes
More than 700 of the September vulnerabilities affect supported versions of Windows 10, Windows 11, and Windows Server.
Two high risk Windows flaws have already been observed in the wild.
| Vulnerability | Affected area | Main risk |
|---|---|---|
| CVE 2026 81963 | Windows Update stack | Elevation of privilege |
| CVE 2026 85880 | Windows ALPC | Elevation of privilege |
| CVE 2026 69525 | Remote Desktop Service | Remote code execution |
| CVE 2026 69727 | Windows Hello | Privilege escalation over network |
| CVE 2026 73008 | Windows Hello | Personal data exposure |
| CVE 2026 55007 | Exchange Server | Remote code execution |
| CVE 2026 69355 | Exchange Server | Remote code execution |
CVE 2026 81963 affects the Windows Update stack and can allow an attacker to gain elevated system privileges when combined with another exploit.
CVE 2026 85880 affects Windows Advanced Local Procedure Call. The exploit reportedly needs to be embedded inside a document that a person then interacts with.
Microsoft has not disclosed how widespread attacks using either vulnerability currently are.
Remote Desktop and Windows Hello receive major fixes
Microsoft classified 77 Windows vulnerabilities as critical, including 56 remote code execution issues.
One of the more serious flaws is CVE 2026 69525 in Windows Remote Desktop Service. It is described as a use after free vulnerability that could allow an attacker to execute code remotely without authentication or user interaction.
Windows Hello also received a large set of security fixes.
Microsoft patched 64 vulnerabilities affecting the biometric service. Many follow similar patterns, including 56 buffer overflow issues.
Nine Windows Hello vulnerabilities are highlighted separately, with eight rated critical elevation of privilege flaws.
The scale of the fixes makes biometric authentication one of the more heavily patched Windows components this month.
Office receives 137 security fixes
Microsoft Office accounts for another 137 vulnerabilities in the September update.
Among them are 22 critical remote code execution flaws, including five affecting Excel.
Some critical Office vulnerabilities can reportedly be triggered through the preview pane, meaning a malicious document may not always need to be opened manually for exploitation to occur.
Other high risk Office flaws require a person to open a specially prepared file.
SharePoint also received 16 fixes, including six remote code execution vulnerabilities.
Exchange Server has nine high risk flaws
Microsoft patched nine vulnerabilities in Exchange Server, all rated high risk.
Two of them, CVE 2026 55007 and CVE 2026 69355, can enable remote code execution.

CVE 2026 55007 is particularly notable because an attacker may only need to send an email containing a malicious Visio file. The exploit can reportedly trigger while Exchange processes the message, without requiring the recipient to open or preview it.
Edge security updates are counted separately
Microsoft Edge also received security updates, but its Chromium based vulnerabilities are not included in the 973 flaw total.
Edge version 152.0.4191.66, released on September 4, addresses a separate zero day vulnerability along with additional Chromium security issues.
With two Windows flaws already under active exploitation and more than 100 critical vulnerabilities fixed across Microsoft's products, installing the September security updates is particularly important for supported Windows and Office systems.
Microsoft's next scheduled Patch Tuesday is October 13, 2026.



Discussion (0)
Be the first to comment.