Microsoft Patch Tuesday Fixes Record 974 Vulnerabilities

Microsoft Patch Tuesday Fixes Record 974 Vulnerabilities

Microsoft's September 2026 Patch Tuesday is exceptional even by the increasingly large standards of Microsoft's monthly security releases. Microsoft reports that the September security updates address 974 unique vulnerabilities, including more than one hundred rated Critical and two Windows vulnerabilities that were already being exploited before patches became available.

The key takeaway from September's record Patch Tuesday is not simply the number of vulnerabilities: two are already being exploited, while around twenty others could potentially allow unauthenticated, worm-like attacks without user interaction.

Two Windows Vulnerabilities Already Under Attack

The most immediate priorities are CVE-2026-81963, an elevation-of-privilege vulnerability in the Windows Update Stack, and CVE-2026-85880, an elevation-of-privilege vulnerability in Windows Advanced Local Procedure Call (ALPC). Both vulnerabilities have a CVSS score of 7.8 and were already being exploited in the wild when Microsoft released its patches.

CVE Component CVSS Risk
CVE-2026-81963 Windows Update Stack 7.8 Privilege escalation; actively exploited
CVE-2026-85880 Windows ALPC 7.8 Privilege escalation; actively exploited
CVE-2026-55007 Exchange Server Critical Unauthenticated remote code execution
CVE-2026-69525 Remote Desktop Services 9.8 Unauthenticated remote code execution

Neither of the two actively exploited vulnerabilities allows an unauthenticated attacker to remotely compromise a Windows system by itself. Instead, they can be used to escalate privileges after an attacker has gained an initial foothold, potentially providing SYSTEM-level privileges and extensive control over the compromised machine.

Their confirmed exploitation also demonstrates why CVSS scores should not be considered in isolation. A vulnerability rated 7.8 that attackers are already using may deserve greater immediate attention than a theoretical vulnerability carrying a higher numerical score.

Exchange and Remote Desktop Also Deserve Attention

Two vulnerabilities not known to be actively exploited at release may nevertheless be among the most concerning issues for administrators. CVE-2026-55007 affects Microsoft Exchange Server and can allow an unauthenticated remote attacker to achieve code execution by sending an email containing a malicious Visio attachment. The vulnerable server processes the message, meaning that the recipient does not need to open the attachment or even view it in the Preview Pane.

CVE-2026-69525 affects Remote Desktop Services and has a CVSS score of 9.8. The use-after-free vulnerability can allow a remote, unauthenticated attacker with network access to execute arbitrary code on an affected system. Organizations using Remote Desktop Services should therefore give the vulnerability a high patching priority.

Twenty Potentially Wormable Vulnerabilities

Beyond the two vulnerabilities already being exploited, the Zero Day Initiative identified 20 vulnerabilities in Microsoft's September release that could potentially be considered wormable. In these cases, a remote and unauthenticated attacker could potentially achieve code execution without requiring user interaction.

Many affect fundamental Windows infrastructure, including DNS Server, DHCP Server, Active Directory Domain Services, Netlogon, Message Queuing and other network services. CVE-2026-69730, for example, is a critical Windows DNS Server remote-code-execution vulnerability with a CVSS score of 9.8.

The term "wormable" does not mean that worms exploiting these vulnerabilities currently exist. Rather, the combination of remote access, no authentication and no required user interaction creates the conditions that could allow malware to propagate automatically between vulnerable systems. Organizations should therefore prioritize the two vulnerabilities already under active exploitation, followed closely by exposed systems and critical infrastructure affected by these remote-code-execution flaws.

Check Whether Windows Has the September Update

Windows administrators can quickly check whether a system has received Microsoft's September security update. For Windows 11 24H2 and 25H2, the September cumulative security update is KB5124008, bringing Windows 11 24H2 to build 26100.9445 and Windows 11 25H2 to 26200.9445.

$os = Get-ComputerInfo

[PSCustomObject]@{
    Windows = $os.WindowsProductName
    Version = $os.WindowsVersion
    Build   = "$($os.OsBuildNumber).$((Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion').UBR)"
    SeptemberUpdate = if (Get-HotFix -Id KB5124008 -ErrorAction SilentlyContinue) {
        "Installed"
    } else {
        "Not detected"
    }
}

On Windows 11 24H2 or 25H2, an Installed result indicates that KB5124008 is present. Administrators should also check the reported build number, as a later cumulative update will supersede the September update. Windows 11 23H2 and supported Windows Server releases use different updates and should be checked against Microsoft's Security Update Guide.

Keeping Track with BaseFortify

September's Patch Tuesday demonstrates why vulnerability management cannot depend solely on reading lists of CVEs. 974 vulnerabilities is a data-management problem as much as it is a patching problem. What matters to an organization is determining which vulnerabilities correspond to products actually present in its environment and which of those require immediate attention.

With BaseFortify, organizations can maintain a component list containing the software products and technologies they use. Newly published vulnerabilities can then be matched against those components, allowing users to receive an immediate warning when a relevant CVE appears.

For example, organizations using affected Microsoft products may encounter CPEs such as:

cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

These CPEs can be useful starting points when adding components to a BaseFortify inventory. The exact CPE should always correspond to the product and platform actually deployed; for example, separate ARM64 CPEs exist for supported Windows 11 releases.

BaseFortify also provides annotated CVE reports, vulnerability Q&A and an AI assistant to help users investigate individual vulnerabilities. During an unusually large release such as September's Patch Tuesday, this helps turn a list of hundreds of CVEs into a much more useful question: which of these vulnerabilities actually affect us?

Resources