start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

Microsoft's September 2026 Patch Tuesday, released on September 8, is the largest single security update the company has ever shipped — and the story this month is not just scale, its urgency. Both of this month's MSRC-designated zero-days were already being exploited in attacks before a fix existed. Microsoft has not published technical details of either in-the-wild attack, but both let a local or sandboxed attacker walk away with full SYSTEM privileges, and CISA added both to its Known Exploited Vulnerabilities catalog the same day the patches shipped.

Microsoft addressed 973 CVEs this month (industry trackers report a range of 964–974 depending on methodology) - surpassing July's 621-CVE release. Of those 973, 113 vulnerabilities are rated “Critical” and 860 “Important”. This cycle also includes roughly 20 vulnerabilities Microsoft flags as potentially wormable — but the two flaws that should top every patch team's list this week are the zero-days.

September 2026 Patch Tuesday at a Glance

Category Detail
Total CVEs 973
Critical 113
Important 860
Zero-Days (Exploited in the Wild) 2
Zero-Days (Publicly Disclosed) 0
Top Affected Products Windows (723 CVEs), Microsoft Office (222 CVEs, including 111 in Office 2016), Windows Update Stack, Windows ALPC, SQL Server, Exchange Server
Immediate Priority Windows Update Stack (all supported Windows Client/Server versions); Windows ALPC (all supported versions, plus ESU-covered Windows Server 2012/2012 R2 and legacy Windows 10 1607/1809 builds)

Vulnerabilities Analysis in the September 2026 Patch Tuesday Release 

This month's release fixes two MSRC-designated zero-day vulnerabilities, both local elevation-of-privilege flaws in core Windows components, and both already being exploited in the wild before Microsoft shipped a fix. That is a change from August, when one of the two zero-days was exploited and the other was merely publicly disclosed. Microsoft has not released technical details on how either flaw was used in attacks, which is typical while exploitation is still being tracked or when early disclosure could accelerate copy-cat activity. Both flaws let an attacker who already has some foothold on a device — a low-privileged local account or a sandboxed application — escalate straight to SYSTEM, with no user interaction required. CISA added both CVE-2026-81963 and CVE-2026-85880 to its Known Exploited Vulnerabilities catalog the same day Microsoft published the fixes, setting a September 22 remediation deadline for federal agencies.

Windows Update Stack – Elevation of Privilege:

CVE-2026-81963 is an Elevation of Privilege vulnerability in the Windows Update Stack — the set of components responsible for downloading and installing Windows updates — on every currently supported version of Windows. It was assigned a CVSS score of 7.8 and rated “Important.” Microsoft describes the root cause as improper link resolution before file access (“link following,” CWE-59) combined with improper access control (CWE-284): an authenticated local attacker can exploit the flaw to elevate privileges to SYSTEM with no user interaction required. Microsoft credited Romain Deperne and its own Microsoft Threat Intelligence Center (MSTIC) with the discovery and has not disclosed how the flaw is being used in active attacks. Seven Windows Update Stack elevation-of-privilege vulnerabilities have been patched since 2022, but CVE-2026-81963 is the first of those to have been exploited in the wild as a zero-day.

HCL BigFix remediates CVE-2026-81963 through the standard cumulative security update fixlets published for every actively supported Windows Client and Server version in the Patches for Windows (English) site, since the Windows Update Stack ships as part of the core operating system rather than a separately serviced component. Because this flaw sits inside the update mechanism itself, patch teams should confirm the fixlet applies cleanly on affected endpoints and that subsequent Windows Update / WSUS / BigFix-delivered patch cycles continue to install without disruption afterward.

Windows Advanced Local Procedure Call (ALPC) – Elevation of Privilege:

CVE-2026-85880 is an Elevation of Privilege vulnerability in Windows Advanced Local Procedure Call (ALPC), assigned a CVSS score of 7.8 and rated “Important.” Microsoft describes the flaw as a heap-based buffer overflow combined with use of an uninitialized resource: the ALPC subsystem does not sufficiently validate input data lengths before copying them into fixed-size heap buffers. An attacker able to execute code inside a low-privilege AppContainer sandbox can exploit the flaw to escape that sandbox and gain SYSTEM privileges, with no additional user interaction required. Microsoft credited Volexity, along with Mark Kelly, David Galazin, and Jeremy Hedges of Proofpoint, with reporting the flaw and has not disclosed technical details of the in-the-wild exploitation. This is the first ALPC vulnerability included in a Patch Tuesday release in more than three years — the last was April 2023 — and only the second ALPC zero-day exploited in the wild since CVE-2023-21674 in January 2023.

The advisory lists a wide affected-version footprint spanning Windows 10 versions 1607, 1809, 21H2, and 22H2, alongside Windows Server 2012, 2012 R2, 2016, 2019, and 2022 — notably reaching back to Windows Server 2012 / 2012 R2 builds that are now supported only under a paid Extended Security Updates (ESU) program. HCL BigFix delivers the ALPC fix through the same cumulative Windows security update fixlets, published for every actively supported Windows Client and Server version. Organizations still running Windows Server 2012 / 2012 R2 or other end-of-support builds under ESU should confirm they are subscribed to the matching HCL BigFix ESU-specific External Site or fixlet source, since those builds do not receive fixes through the mainstream Patches for Windows content.

Broken Down by Vulnerability Type, This Month’s Release Looks Like:

Vulnerability type Count What it means
Remote Code Execution 257 Attackers execute code remotely — highest priority class
Elevation of Privilege 438 Moves the attacker from limited access to the SYSTEM level
Information Disclosure 175 Exposes sensitive data — audit and compliance exposure
Denial of Service 56 Disrupts services — assess business impact per environment
Security Feature Bypass 18 Disables controls compliance frameworks require to be active
Spoofing 16 Identity and authentication risk
Tampering 13 Attacker modifies data, files, configurations, or system behavior without authorization.

HCL BigFix’s Patch team published fixlets for every actively supported Windows Client and Server version as soon as Microsoft releases them, covering the zero-days addressed this cycle alongside the rest of September’s Windows, .NET, Office, and SharePoint Server updates. 

Additional remediation content for third-party Windows software is available through the HCL BigFix “Updates for Windows Applications” External Site. The full list of fixlets for this month's security updates is available in the HCL BigFix Forum 

Compliance Risks from September 2026 Patch Tuesday Vulnerabilities 

This month's compliance exposure is sharper than usual because both zero-days were already being exploited before a fix existed, and CISA's Known Exploited Vulnerabilities catalog entry sets an explicit, public remediation deadline — September 22, 2026. Many commercial compliance programs and cyber-insurance underwriters increasingly benchmark “reasonable remediation time” against KEV deadlines even outside federal environments, so treating September 22 as an internal SLA rather than only a federal requirement is the more defensible posture under frameworks such as NIST 800-53, SOC 2, and ISO 27001.

Because both CVE-2026-81963 and CVE-2026-85880 grant local privilege escalation to SYSTEM, they are directly relevant to the least-privilege and access-control requirements in those same frameworks: an attacker who lands on an endpoint with even sandboxed or low-privileged access can use either flaw to fully bypass the privilege boundary those controls assume is intact. The ALPC flaw's reach into out-of-mainstream-support Windows Server 2012 / 2012 R2 builds adds a second compliance dimension — organizations still running ESU-covered legacy servers should confirm that both ESU entitlement and patch coverage are current, since a KEV-listed, actively exploited flaw on an unpatched legacy server is difficult to defend during an audit.

Conclusion

September 2026 Patch Tuesday is Microsoft's largest release ever, but the number that matters most for triage is two: both of this month's zero-days were already in attackers' hands before a fix shipped, and both hand a local or sandboxed attacker full SYSTEM privileges. The Windows Update Stack flaw sits inside the update mechanism itself, and the ALPC flaw reaches back to Windows Server 2012 R2 and Windows 10 version 1607 — meaning fleets with a long tail of legacy or ESU-covered systems can't treat this as a current-OS-only problem. Organizations that can push the CVE-2026-81963 and CVE-2026-85880 fixes fleet-wide before CISA's September 22 KEV deadline, including to ESU-covered legacy servers, are best positioned to close the gap attackers are already using. HCL BigFix is built for exactly that turnaround.

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.

August 2026 Patch Tuesday: North Korea’s Lazarus Group Weaponized a Windows Zero-Day Before Microsoft Could Patch It
  |  八月 12, 2026
August 2026 Patch Tuesday: North Korea’s Lazarus Group Weaponized a Windows Zero-Day Before Microsoft Could Patch It
Microsoft's August 2026 Patch Tuesday fixes 421 CVEs, led by a Lazarus-exploited Windows AFD.sys zero-day and two publicly disclosed flaws. See how HCL BigFix remediates them.
July 2026 Patch Tuesday: Microsoft's Largest-Ever Release Brings Two Exploited Zero-Days
  |  七月 15, 2026
July 2026 Patch Tuesday: Microsoft's Largest-Ever Release Brings Two Exploited Zero-Days
Microsoft's July 2026 Patch Tuesday – the largest release on record. Remediate 569 vulnerabilities, including two exploited and one publicly disclosed zero-day, with HCL BigFix.