September 2026 Patch Tuesday is a record-scale Microsoft release, but your first move is simple: patch the two exploited zero-days, CVE-2026-81963 and CVE-2026-85880. Then move to internet-facing servers and potentially wormable remote-code-execution bugs, especially Exchange Server and Remote Desktop Services. Don’t chase the biggest CVE number first. Chase reachable risk.
September 2026 Patch Tuesday: why the “record” is messy
Microsoft’s September 2026 Patch Tuesday landed on September 8, 2026, and security vendors quickly called it the largest Patch Tuesday release on record. The exact count depends on who’s counting and what they include. Reports cited 966, 972, 974, or as many as 997 vulnerabilities when Chromium, external, or non-Microsoft CVEs are folded into the total.
That sounds like a bookkeeping argument. It isn’t. If your dashboard says “974 CVEs” and your team tries to treat every one as equal, you’ve already lost the week.
CrowdStrike reported 972 Microsoft CVEs, including 113 Critical vulnerabilities, while the Zero Day Initiative counted 114 Critical items when external or Chromium-documented issues were included. SecurityWeek reported Microsoft fixed 723 Windows flaws, 222 Office suite bugs, 62 SQL bugs, 22 Developer Tools bugs, 16 SharePoint Server bugs, 12 Azure bugs, 10 Skype for Business bugs, and 9 Exchange Server bugs in the September 2026 release.
The useful question is narrower: which flaws are already exploited, externally reachable, unauthenticated, or likely to become mass-exploitation targets? September’s release is huge, but only two Microsoft zero-days were confirmed or reported as exploited on release day. That’s the triage anchor.
Fix these two exploited zero-days first
The first tier for September 2026 Patch Tuesday is not negotiable: CVE-2026-81963 and CVE-2026-85880. CISA added both to its Known Exploited Vulnerabilities catalog and set a September 22, 2026 remediation deadline for U.S. federal civilian agencies. Even if you’re not a federal agency, KEV listing is a useful signal because it points to observed exploitation, not theoretical severity.
CVE-2026-81963 is a Windows Update Stack elevation-of-privilege vulnerability with a CVSS 3.1 score of 7.8. The attack vector is local, low privileges are required, and no user interaction is needed. In plain terms, it’s not usually the first foothold; it’s the kind of bug an attacker wants after landing on a machine.
CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC, and is also rated CVSS 7.8. It has been described as a heap-based buffer overflow that can allow local privilege elevation. Again, local does not mean low-risk. A phishing payload, stolen VPN account, malicious installer, or exposed service exploit can give an attacker the starting position they need.
Here’s the pitfall many patch summaries skip: elevation-of-privilege bugs become more dangerous when your endpoint estate has weak containment. If standard users can write into risky locations, run unsigned tools, or reach admin tooling from compromised workstations, a “local” bug can become the bridge from one infected laptop to domain pain. If you need a broader model for reducing that blast radius, this site’s guide to Zero Trust verification is a useful companion to patch prioritization.
Priority table: what to patch before the weekend
Security teams need an order of operations. Not a 900-line CVE dump. The table below uses the September 2026 facts that matter most: exploitation status, reachability, likely operational exposure, and the consequences of delay.
| Priority | Area | 2026 examples | Why it comes here |
|---|---|---|---|
| 1 | Exploited Microsoft zero-days | CVE-2026-81963, CVE-2026-85880 | Already exploited; CISA KEV deadline set for 2026-09-22 |
| 2 | Internet-facing server RCE | Exchange Server CVE-2026-55007; RDS CVE-2026-69525 | Remote exploitation can hit exposed infrastructure before endpoints are touched |
| 3 | Potentially wormable services | DNS, DHCP, MSMQ, NFS, SSTP VPN, Netlogon, Kerberos, RRAS | ZDI counted 20 bugs as potentially wormable due to remote, unauthenticated RCE with no user interaction |
| 4 | Externally reachable collaboration systems | SharePoint Server, Exchange, Skype for Business where still deployed | High-value entry points with broad identity and document access |
| 5 | Workstation and application exposure | Office, Outlook, Word, Excel, PowerPoint, Edge-Chromium, Acrobat/Reader | User workflows, preview panes, browsers, and document handling create common execution paths |
A concrete calculation helps. Suppose you manage 2,000 Windows endpoints, 35 Windows servers, two internet-facing Exchange servers, one Remote Desktop Services gateway, and 250 Office-heavy finance and legal workstations. Patching 2,000 laptops first may make the completion graph look better, but the four externally reachable mail and remote-access systems probably reduce more immediate attack surface per hour spent.
Internet-facing and wormable RCEs deserve tier-two urgency
After the exploited zero-days, your next focus should be exposed remote-code-execution paths. ZDI reported 20 September 2026 Microsoft vulnerabilities as potentially wormable because they allow remote, unauthenticated code execution with no user interaction. That phrase should change the tone in the room.
Exchange Server CVE-2026-55007 is the standout. ZDI and SecurityWeek both highlighted it as a high-priority server-side fix, with an attack path involving email carrying a malicious Visio attachment that Exchange content indexing processes without user interaction. You don’t need a user to click. The server does the dangerous work.
Remote Desktop Services CVE-2026-69525 is another urgent item. ZDI highlighted it as CVSS 9.8 and remotely exploitable by an unauthenticated attacker on affected systems. If RDS is exposed directly to the internet, honestly, that design only makes sense under very tight compensating controls, and even then it deserves uncomfortable scrutiny.
CrowdStrike also flagged unauthenticated, network-reachable RCE vulnerabilities across at least 17 CVEs in DNS, DHCP, MSMQ, NFS, and SSTP VPN. Add identity-adjacent services such as Netlogon and Kerberos, plus RRAS, Failover Cluster, and externally reachable SharePoint. These are the systems where a bad patch weekend is still better than a bad breach month.
Supply-chain and update-channel integrity matter here, too. Patch deployment assumes the path from vendor to endpoint can be trusted, but routing and update infrastructure have been abused before; for background, see the analysis of how BGP hijacking can poison software updates.
Use asset context, not raw CVE volume
Raw CVE count is now a weak triage signal. September 2026 Patch Tuesday proves the point: record-size release, inconsistent counting, only two confirmed exploited Microsoft zero-days, and a large spread across Windows, Office, SQL, Exchange, SharePoint, Azure, and developer tools.
Tenable’s view, quoted by SecurityWeek, was blunt in the right way: AI-assisted vulnerability discovery is creating larger haystacks. More findings are arriving faster, but the needle is still defined by applicability, reachability, exploitability, and business context.
Use a short decision filter before assigning emergency work:
- Is the affected product actually present in your environment in 2026?
- Is the vulnerable component internet-facing, reachable from partner networks, or reachable from ordinary workstations?
- Does exploitation require authentication, user interaction, or a special configuration?
- Is there active exploitation, public proof-of-concept code, KEV listing, or credible vendor emphasis?
- Would compromise of that system expose identity, email, file shares, backups, or administrative tooling?
That filter beats severity sorting. A Critical bug in software you don’t run is noise; a “moderate-looking” local privilege bug on every helpdesk workstation might be part of a real intrusion chain.
Detection should influence sequencing as well. If you can’t reliably see exploitation attempts against Exchange, RDS, or identity services, patch sooner. If you use centralized logging, the practical angle is covered in this guide to SIEM-driven threat detection.
Don’t ignore Office, browsers, and adjacent September threats
Desktop exposure comes after exploited zero-days and exposed server RCEs, but it’s not optional. CrowdStrike reported 135 Microsoft Office patches in the September 2026 release, while SecurityWeek’s broader count listed 222 Office suite bugs. CrowdStrike also reported 22 Critical Office patches, including 12 exploitable through Preview Pane or Reading Pane.
That last detail matters. Many organizations still treat “user interaction required” as a comforting phrase, but preview and reading panes blur the line between opening a file and merely handling normal mail. For finance, legal, HR, executive assistants, and anyone who opens unsolicited documents all day, desktop patching is part of front-line defense.
Browsers need separate attention because September was busy outside Microsoft, too. Google patched CVE-2026-85046, a Chrome V8 zero-day with known exploitation on September 3, 2026, and The Register later flagged uncertainty about Microsoft Edge advisory coverage. If Edge-Chromium exposure is part of your fleet, track browser versioning directly rather than assuming the monthly rollup tells the whole story. The move to faster browser patching is explained in the site’s piece on Chrome’s two-week update cycle.
Adobe also complicated September operations. ZDI reported Adobe released 10 September 2026 bulletins addressing 172 CVEs across Commerce, Campaign Classic, ColdFusion, Experience Manager, Acrobat/Reader, Photoshop, Illustrator, Animate, and Photoshop Mobile. Separately, Adobe issued an out-of-band advisory on September 7, 2026 for CVE-2026-75650, known as StyleSmuggler, a CVSS 10.0 Adobe Commerce/Magento flaw exploited in the wild.
One more edge case: Microsoft Authenticator CVE-2026-80097, reported by ZDI, could expose authentication tokens after a malicious Android app and a user-completed authentication sequence. It won’t be the first item in most Windows patch plans, but mobile identity apps are now part of enterprise attack surface. Treat them that way.
Build a 72-hour patch plan that survives reality
For the first 24 hours after September 2026 Patch Tuesday, validate inventory and deploy fixes for CVE-2026-81963 and CVE-2026-85880 to high-risk Windows systems, privileged-user workstations, jump boxes, and servers. Don’t wait for every lab permutation if you already have active exploitation plus rollback plans.
During the next 24 hours, hit exposed Exchange, RDS, DNS, DHCP, VPN, SharePoint, and identity-related services. If a system is internet-facing and appears in the tier-two group, it gets priority over back-office endpoints. Segment or temporarily restrict access where patching can’t happen fast enough.
The third day should close gaps on Office, Outlook, browser, Acrobat/Reader, SQL Server, developer tooling, and high-risk user groups. Developer systems deserve special attention because they often combine source access, credentials, package managers, and admin rights. Recent attacks involving malicious Git repositories targeting AI coding agents show why dev workstations can’t be treated like ordinary desktops.
Microsoft Defender also drew separate attention in September because CrowdStrike reported a newly disclosed proof-of-concept zero-day called ShieldCrash, discussed apart from Microsoft’s Patch Tuesday fixes. Don’t confuse “not part of the main rollup” with “not relevant.” Track it as a separate exposure item until your vendor guidance is clear.
September’s uncomfortable lesson is that patch management is no longer a monthly checklist. It’s risk operations. The teams that do best won’t be the ones that read every CVE first; they’ll be the ones that know what they run, what’s reachable, and where compromise would hurt most.
FAQ
What was fixed in September 2026 Patch Tuesday?
Microsoft’s September 2026 Patch Tuesday addressed a record-scale set of vulnerabilities, with reported totals ranging from 966 to 997 depending on counting method. The release included two exploited Microsoft zero-days: CVE-2026-81963 and CVE-2026-85880.
Which September 2026 Microsoft zero-days should I patch first?
Patch CVE-2026-81963 and CVE-2026-85880 first. Both were reported as exploited, both were added to CISA’s Known Exploited Vulnerabilities catalog, and CISA set a September 22, 2026 remediation deadline for federal civilian agencies.
Why do different sources report different Microsoft CVE counts?
Counts vary because sources include or exclude Chromium, external, duplicate, or non-Microsoft-documented CVEs differently. For operations, the exact headline number matters less than exploit status, product exposure, and whether the vulnerable component is reachable in your environment.
Is CVE-2026-55007 Exchange Server dangerous without user clicks?
Yes. ZDI and SecurityWeek highlighted CVE-2026-55007 because the reported path involves Exchange content indexing processing an email with a malicious Visio attachment, without user interaction.
Should workstations wait until all servers are patched?
No, but sequence them intelligently. Patch exploited zero-days and internet-facing RCE paths first, then prioritize Office, Outlook, browsers, Acrobat/Reader, and high-risk user groups where document and preview workflows create real exposure.


