Microsoft September 2026 Patch Tuesday: Essential Update Fixes 966 Vulnerabilities, 2 Zero-Days Exploited

Microsoft September 2026 Patch Tuesday: Essential Update Fixes 966 Vulnerabilities, 2 Zero-Days Exploited

Microsoft September 2026 Patch Tuesday has arrived with one of the company’s largest-ever security updates, addressing 966 vulnerabilities across its products. More importantly, two of the vulnerabilities were already being actively exploited in the wild. Here’s what Windows users, IT administrators, and security professionals need to know.

Microsoft September 2026 Patch Tuesday

The Microsoft September 2026 Patch Tuesday update is particularly important for Windows users because two of the fixed vulnerabilities were already being actively exploited.

Microsoft released its September 2026 security updates on September 8, 2026, as part of its regular Patch Tuesday security cycle.

According to security researchers tracking the release, Microsoft addressed 966 vulnerabilities, including 105 vulnerabilities rated Critical. The release also includes fixes for two vulnerabilities that Microsoft says were being actively exploited.

That makes this month’s update particularly important—not simply because of the number of vulnerabilities, but because attackers were already taking advantage of some of them.

Microsoft’s own Security Update Guide is the primary source for vulnerability and update information, while Microsoft’s support documentation confirms the September 8 Windows security releases.


What Is Microsoft Patch Tuesday?

Before looking at this month’s vulnerabilities, it is important to understand what Patch Tuesday actually means.

Microsoft Patch Tuesday is the company’s regular monthly security-update release cycle. Security fixes for Windows, Microsoft Office, Windows Server, Exchange Server and other Microsoft products are generally released on the second Tuesday of each month.

For organizations, Patch Tuesday is an important part of vulnerability-management operations.

Security teams typically:

  1. Review Microsoft’s security advisories.
  2. Identify affected systems.
  3. Prioritize vulnerabilities based on severity and exploitability.
  4. Test updates where necessary.
  5. Deploy patches across endpoints and servers.
  6. Monitor systems for update failures or unexpected issues.

This predictable schedule allows enterprises to build patch-management processes around Microsoft’s monthly release cycle.


September 2026 Patch Tuesday at a Glance

Here are the most important numbers from this month’s release:

Security MetricSeptember 2026
Vulnerabilities fixed966
Critical vulnerabilities105
Actively exploited zero-days2
Release dateSeptember 8, 2026
Windows 11 security updateKB5124008

The 966 figure counts vulnerabilities addressed in Microsoft’s Patch Tuesday release itself. Some additional Microsoft vulnerabilities were fixed earlier in September and therefore are not necessarily included in that Patch Tuesday total.

The vulnerability categories reported for this release include elevation of privilege, remote code execution, information disclosure, denial of service, spoofing and security-feature bypass issues.


The Most Important Part: Two Zero-Day Vulnerabilities Were Exploited

The biggest reason users should pay attention to this month’s update is not the number 966.

It is the fact that two vulnerabilities were already being exploited.

A vulnerability becomes especially concerning when attackers are using it before most users have installed the available security fix.

These two vulnerabilities are:

1. CVE-2026-81963 — Windows Update Stack Elevation of Privilege

The first actively exploited vulnerability affects the Windows Update Stack.

It is classified as an Elevation of Privilege (EoP) vulnerability.

According to Microsoft’s description, improper link resolution before file access can allow an authorized attacker to elevate privileges locally.

In practical terms, exploitation could allow an attacker who has already obtained a foothold on a Windows system to increase their privileges and potentially obtain SYSTEM-level privileges.

This is important because Windows SYSTEM privileges are extremely powerful.

An attacker operating with such privileges may have significantly greater control over the operating system than a normal user account.


2. CVE-2026-85880 — Windows ALPC Elevation of Privilege

The second actively exploited zero-day affects Windows Advanced Local Procedure Call (ALPC).

Microsoft describes it as a heap-based buffer overflow that can allow an authorized attacker to elevate privileges locally.

The vulnerability was reportedly exploited to gain SYSTEM privileges. Researchers from Volexity and Proofpoint were credited in connection with the discovery.

Microsoft has not publicly provided detailed information about how these vulnerabilities were being exploited in real-world attacks.

That is common with actively exploited vulnerabilities because releasing detailed exploitation information too early can increase the risk to users who have not yet patched their systems.


What Does “Zero-Day” Actually Mean?

The term zero-day is frequently misunderstood.

A zero-day vulnerability is not necessarily a vulnerability that was discovered exactly zero days ago.

Instead, the term generally refers to a security vulnerability for which defenders had little or no time to prepare before exploitation or public disclosure.

In this month’s case, Microsoft identifies the two vulnerabilities as actively exploited.

That distinction matters.

There is a major difference between:

A vulnerability that exists

and

A vulnerability that attackers are already using.

The second situation creates a much greater immediate risk.


Why Elevation of Privilege Vulnerabilities Matter

At first glance, an elevation-of-privilege vulnerability may sound less dangerous than a remote code execution vulnerability.

That can be misleading.

Imagine an attacker gains access to a Windows computer through phishing, stolen credentials, malicious software or another vulnerability.

Initially, the attacker may have limited permissions.

The attacker then discovers an elevation-of-privilege vulnerability.

If successfully exploited, the attacker may move from:

Limited user → Administrator → SYSTEM

The higher the privilege level, the greater the attacker’s potential control over the machine.

This is why privilege escalation is an important part of modern attack chains.

A real-world attack does not always depend on a single vulnerability.

Attackers may chain multiple weaknesses together:

Initial Access → Execution → Privilege Escalation → Persistence → Credential Theft → Lateral Movement

A patched elevation-of-privilege vulnerability can therefore break an important part of that chain.


Microsoft September 2026 Patch Tuesday: Windows 11 Update

The Microsoft September 2026 Patch Tuesday update was released on September 8, 2026 for supported Windows 11 versions.

For Windows 11 versions 24H2 and 25H2, Microsoft lists KB5124008 as the September 8 security update.

Users should normally receive the update through Windows Update.

To manually check:

On Windows 11

Settings → Windows Update → Check for updates

If the September security update is available, install it and restart the computer if Windows requests a restart.

Microsoft’s release documentation also notes that some security improvements require a restart because certain components cannot be updated without restarting the system.


What About Windows 10?

Windows 10 requires additional attention because standard support for many Windows 10 editions has already ended.

Microsoft released KB5122878 for supported Windows 10 Enterprise LTSC 2021 and Windows 10 IoT Enterprise LTSC 2021 environments as part of the September servicing cycle.

For organizations still operating Windows 10 systems, administrators should verify:

  • The exact Windows edition
  • Current support status
  • Whether the system is enrolled in Extended Security Updates
  • Whether the latest servicing stack and cumulative updates are installed

Running an unsupported operating system without an appropriate security-update path creates unnecessary security exposure.


Why Are There So Many Vulnerabilities This Month?

The size of this month’s release is particularly interesting.

Security researchers counted 966 vulnerabilities addressed in Microsoft’s September Patch Tuesday release.

One factor behind increasingly large security releases is the growing use of automation and AI-assisted vulnerability discovery.

Microsoft has previously explained that AI-powered tools and automated security analysis are helping researchers identify additional issues in software that has already undergone extensive security review.

In a May 2026 MSRC update, Microsoft specifically discussed the growing role of AI-driven scanning and said advanced AI models were surfacing additional issues across previously studied code.

This does not necessarily mean Microsoft’s software suddenly became less secure.

There is another way to look at it:

The ability to discover vulnerabilities is becoming faster.

As defensive research tools improve, security teams can examine larger amounts of code and identify weaknesses that may previously have taken much longer to find.

Unfortunately, the same technological acceleration can also benefit attackers.

That is why rapid patching is becoming increasingly important.


Why You Shouldn’t Ignore a Large Security Update

Some users avoid large Windows updates because they are worried about:

  • Update failures
  • Compatibility problems
  • Performance issues
  • Driver problems
  • Application crashes

Those concerns are understandable, especially for enterprise environments.

However, delaying security updates indefinitely creates another problem.

If attackers are already exploiting a vulnerability, the risk of remaining unpatched can be greater than the inconvenience of installing the update.

For normal home users, installing supported security updates promptly is generally the safest approach.

For businesses, administrators should use a controlled deployment process rather than simply ignoring the updates.


What IT Administrators Should Do

For enterprise environments, the September Patch Tuesday release should trigger a structured vulnerability-management workflow.

1. Identify vulnerable systems

Inventory:

  • Windows endpoints
  • Windows Servers
  • Domain Controllers
  • Exchange Servers
  • Microsoft Office installations
  • Other Microsoft products

2. Prioritize actively exploited vulnerabilities

The two actively exploited zero-days should receive particularly high priority.

Do not treat every vulnerability equally.

A vulnerability that is merely theoretical is different from one that attackers are already exploiting.

3. Patch critical infrastructure carefully

Before deploying broadly, administrators should test updates against important applications and workloads.

Pay particular attention to:

  • Domain Controllers
  • Authentication infrastructure
  • File servers
  • Application servers
  • Business-critical endpoints

4. Monitor after deployment

Patching is not finished when the update installs.

Security teams should monitor:

  • Authentication failures
  • Unexpected restarts
  • Application crashes
  • Endpoint alerts
  • Suspicious privilege escalation
  • Unusual process activity

5. Verify that systems are actually patched

One of the most common mistakes in vulnerability management is assuming that an update was successfully deployed everywhere.

Use centralized management tools and vulnerability scanners to verify patch status.


What Active Directory Administrators Should Know

If you’re new to Microsoft’s identity infrastructure, our guide, “What Is Active Directory? 7 Essential Concepts for Beginners,” explains how Active Directory works and why it is important in enterprise Windows environments.

A compromised endpoint can become much more dangerous when an attacker is able to obtain privileged credentials and move toward domain-level resources.

This is why organizations should combine patch management with:

  • Least privilege
  • MFA
  • Privileged Access Management
  • Network segmentation
  • Credential protection
  • Endpoint Detection and Response
  • Strong Active Directory monitoring
  • Regular vulnerability scanning

Patching alone cannot eliminate every attack path.

But failing to patch known vulnerabilities can leave attackers with unnecessary opportunities.


How to Check Whether Your Windows PC Is Updated

You can check your Windows version and installed updates manually.

Method 1: Windows Update

Go to:

Settings → Windows Update → Update history

Look for the latest September 2026 security update.

Method 2: Winver

Press:

Windows + R

Then type:

winver

and press Enter.

This displays your Windows version and OS build.

Method 3: Installed Updates

Open:

Settings → Windows Update → Update history

Then check the quality/security updates installed on the machine.

For enterprise environments, administrators should use centralized management and reporting rather than relying on manual checks.


Should You Install the September 2026 Update Immediately?

For most supported Windows users, yes, the security update should not be unnecessarily delayed, particularly because this month’s release addresses two vulnerabilities that were already being exploited.

However, businesses running mission-critical systems should follow their normal change-management and testing procedures.

The key point is:

Do not ignore the update simply because the vulnerability count is large.

The two actively exploited vulnerabilities make this month’s release especially important.


What Happens If You Don’t Update?

If a vulnerable system remains unpatched, attackers may eventually be able to exploit publicly known or actively exploited vulnerabilities against it.

The exact impact depends on:

  • The vulnerability
  • System configuration
  • Existing attacker access
  • User privileges
  • Security controls
  • Network architecture

A vulnerable Windows workstation does not automatically mean that it will be compromised.

But leaving a known exploitable weakness unpatched increases the attack surface.

Cybersecurity is ultimately a risk-management game.

The objective is not to make a system magically impossible to attack.

The objective is to continuously reduce the opportunities attackers can exploit.


Patch Tuesday Is More Than Just a Windows Update

One of the biggest lessons from Microsoft’s September 2026 release is that cybersecurity cannot be reduced to antivirus software alone.

Modern attacks frequently involve multiple stages.

An attacker might first obtain access through phishing.

Then steal credentials.

Then exploit a local privilege-escalation vulnerability.

Then establish persistence.

Then move laterally through the network.

Then target sensitive systems.

A vulnerability patch can disrupt one or more stages of that attack chain.

This is why vulnerability management remains one of the most fundamental components of enterprise cybersecurity.

For organizations, the Microsoft September 2026 Patch Tuesday release should be treated as a high-priority security update.


Final Thoughts

Microsoft’s September 2026 Patch Tuesday is significant for two reasons.

First, it addresses 966 vulnerabilities, including 105 rated Critical.

Second—and more importantly—two vulnerabilities were already being actively exploited.

The vulnerabilities, CVE-2026-81963 and CVE-2026-85880, involve elevation of privilege in Windows and can potentially allow attackers to reach SYSTEM-level privileges after gaining local access.

For Windows users, the practical takeaway is simple:

Check Windows Update and install the latest supported security updates.

For system administrators, the message is broader:

Prioritize actively exploited vulnerabilities, verify patch deployment, monitor systems after installation, and do not rely on a single security control.

The growing size of Patch Tuesday releases also highlights a larger trend in cybersecurity: vulnerability discovery is becoming faster, more automated and increasingly AI-assisted.

As defenders become better at finding vulnerabilities, organizations must become equally disciplined at fixing them.

Because in cybersecurity, discovering a vulnerability is only half the battle.

The real race begins when attackers discover it too.


Frequently Asked Questions

What is Microsoft Patch Tuesday?

Microsoft Patch Tuesday is Microsoft’s regular monthly security-update release cycle, generally occurring on the second Tuesday of each month.

How many vulnerabilities did Microsoft fix in September 2026?

The September 2026 Patch Tuesday release addressed 966 vulnerabilities, according to vulnerability tracking of the Patch Tuesday release.

How many zero-days were actively exploited?

Two vulnerabilities were reported as actively exploited:

  • CVE-2026-81963
  • CVE-2026-85880

Both are Windows elevation-of-privilege vulnerabilities.

What is an elevation-of-privilege vulnerability?

It is a vulnerability that can allow an attacker to obtain higher permissions than they should normally have.

Should Windows users install the September 2026 update?

Supported Windows users should generally install security updates promptly. Organizations should follow their normal testing and change-management procedures.

What is the Windows 11 September 2026 update?

For Windows 11 24H2 and 25H2, Microsoft’s September 8 security update is KB5124008.

How can I check for the update?

Go to:

Settings → Windows Update → Check for updates

Where can security professionals find Microsoft’s official vulnerability information?

Microsoft’s Security Update Guide provides vulnerability and security-update information for Microsoft products.

The Microsoft September 2026 Patch Tuesday release is a reminder that timely security updates remain essential…


Disclaimer: This article is provided for cybersecurity awareness and educational purposes. Always verify the applicable update, product version, and deployment guidance against Microsoft’s official documentation before making changes to production systems.