Microsoft's September 2026 Patch Tuesday release addresses 973 vulnerabilities, with 113 rated critical and two already exploited in the wild, according to Cisco Talos. The actively exploited flaws are CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, both carrying a CVSS score of 7.8.
Among the critical issues, 82 are remote code execution vulnerabilities. Several are rated 9.8 on the CVSS scale, including flaws in Windows DNS Server (CVE-2026-69730), Windows DHCP Server (CVE-2026-69845 and CVE-2026-72979), Skype for Business (CVE-2026-66302), Windows Imaging Component (CVE-2026-70296), Windows RRAS (CVE-2026-69590), Windows SSTP (CVE-2026-73009), Microsoft Failover Cluster (CVE-2026-73010), and Windows Graphics Component (CVE-2026-77493).
Read more: Microsoft Fixes 421 Bugs in August Patch Tuesday Including Exploited Windows Zero-Day
Other notable fixes include a CVSS 9.0 elevation of privilege in Spring Cloud Azure (CVE-2026-69854) and a CVSS 9.6 SQL Server elevation of privilege (CVE-2026-65669). Azure Cosmos DB spoofing (CVE-2026-69857) and Windows Kerberos RCE (CVE-2026-69676) were also patched.
The release also covers multiple remote code execution flaws in Microsoft Excel (CVE-2026-81948, CVE-2026-81950, CVE-2026-81951, CVE-2026-81959, CVE-2026-81953) and an Outlook RCE (CVE-2026-78525). Additional fixes span Windows RRAS, RMCAST, DirectWrite, IP Helper, Media Foundation, Graphics Kernel, and other components.
This month's total of 973 vulnerabilities is a sharp increase from the 163 flaws Microsoft fixed in its April 2026 Patch Tuesday, as previously reported. The company's own AI system, MDASH, had identified 16 Windows vulnerabilities that were fixed in the May 2026 Patch Tuesday.












