Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days
Microsoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.
CVE search metadata
CVE search record: CVE-2026-85880. Severity: high. CVSS: 7.8. KEV: no. Product: Windows, Office 2016, SQL Server, SharePoint Server, Azure, Skype for Business, Exchange Server, Authenticator. Brief: Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-patch-tuesday/
CVE search record: CVE-2026-81963. Severity: high. CVSS: 7.8. KEV: no. Product: Windows, Office 2016, SQL Server, SharePoint Server, Azure, Skype for Business, Exchange Server, Authenticator. Brief: Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-patch-tuesday/
Microsoft's September 2026 Patch Tuesday release is a record-breaking update addressing 974 distinct vulnerabilities across its product ecosystem. Of critical concern are two zero-day vulnerabilities (CVE-2026-85880 and CVE-2026-81963) that are confirmed to be under active exploitation in the wild. Both flaws allow local attackers to escalate their privileges to System. Additionally, the release addresses 20 potentially wormable vulnerabilities that enable unauthenticated remote code execution (RCE) without user interaction, increasing the risk of widespread automated exploitation within enterprise networks.
The update covers a wide range of products including Windows, Office (specifically 2016), SQL Server, SharePoint Server, Azure, Skype for Business, and Exchange Server. Security teams are advised to prioritize remediation based on reachability and exposure, specifically for the 20 wormable RCE flaws and the two actively exploited zero-days.
Impact
Successful exploitation of the zero-day vulnerabilities allows local attackers to achieve System-level privilege escalation, granting full control over the compromised host. The 20 identified wormable vulnerabilities pose a significant threat to organizational integrity, as they allow for unauthenticated RCE, potentially facilitating the rapid spread of malware or ransomware across internal network segments without user intervention. The broad scope of affected products, including critical infrastructure components like Exchange and SharePoint, necessitates an urgent patching cadence to mitigate the elevated risk of unauthorized access and lateral movement.
Recommendation
- Prioritize immediate patching of the two exploited zero-days (CVE-2026-85880 and CVE-2026-81963) across all affected Windows endpoints.
- Review the 20 identified wormable RCE vulnerabilities for systems that are internet-facing or have high network exposure and apply security updates as the highest priority.
- Apply the latest Servicing Stack Updates (SSU) to Windows Server 2012, 2012 R2, Windows 10 (1607), and Windows Server 2016 immediately to ensure system integrity.
- Monitor logs for unusual process escalation attempts or unexpected updates to the Windows Update Stack components that could indicate exploitation of CVE-2026-81963.
Immediate actions
Deploy September 2026 Microsoft security updates immediately, prioritizing CVE-2026-85880 and CVE-2026-81963.
Mitigations
Patch Windows environments against CVE-2026-85880 and CVE-2026-81963.
CVE-2026-85880, CVE-2026-81963