started · updated
Microsoft releases record September security updates
Microsoft has issued its largest security update on record for September 2026, addressing approximately 974 vulnerabilities across its software ecosystem. The release includes 104 critical and 860 important security patches. A significant portion of these fixes, totaling 723, targets the Windows operating system, while 222 address the Microsoft Office suite. Other affected products include SQL Server, Exchange Server, SharePoint, and Azure.
Of particular concern are two zero-day vulnerabilities that were already being actively exploited in the wild: CVE-2026-81963, located in the Windows Update Stack, and CVE-2026-85880, affecting the Windows Advanced Local Procedure Call (ALPC). Both flaws are local elevation-of-privilege vulnerabilities that could allow an attacker with an existing foothold to gain SYSTEM-level privileges. Additionally, researchers identified roughly 20 potentially wormable vulnerabilities capable of spreading across networks without user interaction.
Separately, Microsoft disclosed CVE-2026-69836, a remote code execution flaw in its Entra ID cloud identity service with a maximum CVSS score of 10.0. This vulnerability was mitigated server-side by Microsoft, meaning no direct action is required from customers, though security teams are advised to monitor for anomalous identity-plane behavior.
Entities
.NET · Adobe · CISA · Entra ID · Google · Microsoft · Windows · Zero Day Initiative · windows
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 13 SOURCES] The release addresses two zero-day vulnerabilities that were being exploited in the wild. cybernoz.com · www.malwarebytes.com · pureinfotech.com · thecyberwire.com · www.scworld.com · +7 more
- [DISPUTED] Microsoft released patches for 974 CVEs in September 2026. cybernoz.com · www.malwarebytes.com · www.scworld.com · www.ct.nl · world-today-journal.com · +11 more
- [○ 1 SOURCE] Retail versions of .NET 10.0.12, 9.0.20, and 8.0.31 each received eight security fixes. www.deskmodder.de
- [DISPUTED] The update includes 104 critical and 860 important security patches. cybernoz.com · www.malwarebytes.com
- [● 8 SOURCES] The zero-day vulnerabilities are local elevation-of-privilege flaws. www.malwarebytes.com · pureinfotech.com · www.scworld.com · www.ct.nl · www.techrepublic.com · +3 more
- [○ 1 SOURCE] Vulnerability CVE-2026-69522 affects multiple versions of .NET Framework. www.deskmodder.de
- [● 5 SOURCES] 723 of the vulnerabilities affect the Windows operating system. www.ct.nl · pureinfotech.com · kulturegeek.fr · www.t-online.de · www.it-daily.net
- [● 13 SOURCES] The two actively exploited zero-days are CVE-2026-81963 and CVE-2026-85880. www.ct.nl · pureinfotech.com · www.scworld.com · www.ad-hoc-news.de · www.igorslab.de · +7 more
- [○ 1 SOURCE] CVE-2026-69836 is a remote code execution flaw in Entra ID. algeriatech.news
- [○ 1 SOURCE] The Entra ID flaw was mitigated server-side with no customer action required. algeriatech.news
- [● 2 SOURCES] The update includes 20 potentially wormable vulnerabilities. www.it-daily.net · kulturegeek.fr