Microsoft's September security update covers 974 CVEs and two exploited Windows flaws

Microsoft's September security update covers 974 CVEs and two exploited Windows flaws

Microsoft's September 2026 security release covers 974 CVEs, including two Windows privilege bugs Microsoft says are exploited.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Sep 09, 2026

Microsoft's September 2026 security release is unusually large, covering 974 Microsoft CVEs and calling out two Windows elevation of privilege vulnerabilities where exploitation has been detected. The update arrived on September 8 through the Microsoft Security Response Center's Security Update Guide, which lists Windows as the largest affected product family with 723 vulnerabilities addressed.

The two exploited issues are CVE-2026-85880, a Windows Advanced Local Procedure Call vulnerability, and CVE-2026-81963, a Windows Update Stack vulnerability. Microsoft rates both as Important and assigns each a CVSS base score of 7.8. The practical detail is that neither bug is described as a remote unauthenticated entry point. Both require an authorized attacker and both affect local privilege boundaries, which still matters because attackers often combine an initial foothold with a local privilege escalation to take fuller control of a machine.

Why this update deserves faster triage

Patch volume alone is not a perfect measure of risk, but it does change the work for administrators. Microsoft's release note groups the CVEs across Azure, Developer Tools, Exchange Server, Office, SharePoint Server, Skype for Business, SQL, Windows, and other products. That breadth means organizations should avoid treating this as a routine desktop only update. Windows endpoints are central, but server products and developer environments also need a pass through normal maintenance and exception queues.

The CyberOGZ read is straightforward: prioritize the exploited Windows flaws first, then sort the remaining September CVEs by exposed service, business criticality, and whether the vulnerable system is reachable from less trusted users. A local privilege bug on a locked down kiosk is not the same operational risk as the same class of bug on a shared developer workstation with admin tooling, cached credentials, and production access.

What to watch next

Microsoft says customer action is required for both exploited CVEs. For teams that stage Windows updates, the useful next step is to confirm which device groups receive the September cumulative update, then separately track any machines held back for compatibility testing. Exceptions should have owners and dates, not just a broad note that a patch is pending.

Readers should also expect follow on vendor advisories and exploit intelligence to refine prioritization over the next few days. The release note establishes the baseline: two exploited Windows privilege bugs and a very large CVE set. The decision value now sits in deployment discipline, especially on machines where ordinary user access can lead to sensitive administrative workflows.

Sources

Cover photo by cottonbro studio on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...