< Back to situation

[REVISION HISTORY]

Microsoft Windows security update cycle

Updated 3 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-10 11:54 UTC → 2026-09-11 05:47 UTC · added removed

Microsoft announced that Windows devices enrolled in hotpatching programs will undergo forced restarts during September and October 2026. This requirement stems from technical needs for security component fixes in the September update and the quarterly hotpatching cycle in October. Microsoft advised IT administrators to manage maintenance windows to avoid business disruptions. In September 2026, Microsoft released a record-breaking security update addressing between 964 and 974 vulnerabilities, including 104 critical and 860 important patches. A significant portion of these fixes, approximately 723, target the Windows operating system, including Windows 11, 10, and various Server versions. The release addressed two zero-day vulnerabilities that were being actively exploited, specifically local elevation-of-privilege flaws: CVE-2026-81963, affecting the Windows Update Stack, and CVE-2026-85880, affecting the Windows Advanced Local Procedure Call (ALPC). Both could allow attackers to gain SYSTEM-level privileges. The updates also covered high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, alongside patches for Exchange Server, SharePoint, SQL Server, Office, and .NET. Industry analysts have suggested that the surge in vulnerability discovery may be driven by the rise of “AI-assisted bug hunting tools,” noting a trend of record-breaking patch volumes that places increased pressure on IT administrators to prioritize remediation. Additionally, security researchers identified approximately 20 vulnerabilities that are potentially “wormable,” meaning they could spread across networks without user interaction. Following the discovery of the two exploited zero-days, CISA added them to its Known Exploited Vulnerabilities list, establishing a deadline for federal agencies to apply the necessary patches. Beyond the Windows ecosystem, Microsoft disclosed CVE-2026-69836, a remote code execution flaw in its Entra ID cloud identity service with a maximum CVSS score of 10.0. Microsoft has mitigated this vulnerability server-side, requiring no direct action from customers, though security teams are advised to monitor for anomalous identity-plane behavior.

Versions

  1. 2026-09-11 05:47 UTC Microsoft Windows security update cycle
  2. 2026-09-10 11:54 UTC Microsoft Windows security update cycle
  3. 2026-09-09 19:42 UTC Microsoft Windows security update cycle
  4. 2026-09-09 10:37 UTC Microsoft Windows security update cycle

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.