Microsoft’s September 2026 Patch Tuesday: Priority Fixes
974 Microsoft vulnerabilities this month, including two actively exploited zero-days now on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline.
First Seen: September 8, 2026
Affected Platforms: Microsoft Windows Advanced Local Procedure Call (ALPC), Microsoft Windows Update Stack, Microsoft Windows Deployment Services, Microsoft Windows NTFS, Microsoft Windows DHCP Client, Microsoft Windows DNS Server, Microsoft Windows Remote Desktop Services, Microsoft Windows Services for NFS ONCRPC XDR Driver, Microsoft Windows Routing and Remote Access Service (RRAS), Microsoft Windows Kerberos, Microsoft Azure Cosmos DB, Spring Cloud Azure, Microsoft Malware Protection Engine (Microsoft Defender)
Impact: Information Disclosure, Denial of Service, Remote Code Execution, Elevation of Privilege, Security Feature Bypass, Spoofing, Tampering
Exploitable CVEs
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Windows 10 v1809; Windows Server 2019, 2022, 2016, 2012; Windows 10 v21H2 | Yes | Yes | Yes |
CVE-2026-81963 | Microsoft Windows Link Following Vulnerability | Windows 11 v23H2, 24H2, 25H2; Windows Server 2025 | Yes | Yes | Yes |
CVE-2026-72957 | Windows Deployment Services Remote Code Execution Vulnerability | Windows 10 v1607, 1809; Windows Server 2012, 2016, 2025, 2022, 2019 | No | No | Yes |
CVE-2026-71329 | Windows NTFS Remote Code Execution Vulnerability | Windows 11 v25H2, 22H2, 26H1, 24H2, 23H2; Windows Server 2012, 2016, 2025, 2022, 2019; Windows 10 v1607, 1809 | No | No | Yes |
CVE-2026-69777 | Windows DHCP Client Elevation of Privilege Vulnerability | Windows 11 v26H1, 24H2, 25H2 | No | No | Yes |
CVE-2026-69730 | Windows DNS Server Remote Code Execution Vulnerability | Windows Server 2025, 2012, 2016; Windows 10 v1607 | No | No | Yes |
CVE-2026-69525 | Remote Desktop Services Remote Code Execution Vulnerability | Windows 11 v23H2, 24H2, 25H2, 26H1; Windows 10 v22H2; Windows Server 2012, 2016, 2025; Windows 10 v1607, 1809 | No | No | Yes |
CVE-2026-68833 | Windows NTFS Remote Code Execution Vulnerability | Windows Server 2012, 2016, 2025, 2022, 2019; Windows 10 v1607; Windows 11 v26H1, 24H2, 23H2, 25H2 | No | No | Yes |
CVE-2026-83501 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | Windows 11 v26H1, 24H2, 23H2, 25H2; Windows Server 2025 | No | No | Yes |
CVE-2026-70585 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Windows Server 2019, 2022, 2025, 2016, 2012 | No | No | Yes |
CVE-2026-69857 | Azure Cosmos DB Spoofing Vulnerability | Azure Cosmos DB | No | No | Yes |
CVE-2026-69854 | Spring Cloud Azure Elevation of Privilege Vulnerability | Spring Cloud Azure | No | No | Yes |
CVE-2026-69852 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Windows Server 2012, 2016, 2025, 2022, 2019; Windows 10 v1607, 1809, 22H2, 21H2; Windows 11 v26H1, 24H2, 23H2, 25H2 | No | No | Yes |
CVE-2026-69676 | Windows Kerberos Remote Code Execution Vulnerability | Windows 10 v1607, 1809, 22H2, 21H2; Windows Server 2012, 2016, 2025; Windows 11 v26H1, 24H2, 23H2, 25H2; Windows Server 2022, 2019 | No | No | Yes |
CVE-2026-69414 | ShieldBreak (Microsoft Defender Elevation of Privilege Vulnerability) | Microsoft Malware Protection Engine | No | No | Yes |
Vulnerability Details
CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call that permits an authorized local attacker to escape a low-privilege AppContainer sandbox and elevate to SYSTEM with no additional user interaction. CVE-2026-81963 is an improper link resolution flaw in the Windows Update Stack that allows a local attacker to cause the update mechanism to follow a malicious link and overwrite a legitimate system component with an attacker-controlled substitute, again yielding SYSTEM.CVE-2026-69730), Windows Remote Desktop Services (CVE-2026-69525), Windows Routing and Remote Access Service (CVE-2026-69852), Windows Kerberos (CVE-2026-69676), Windows Deployment Services (CVE-2026-72957), and the Windows Services for NFS ONCRPC XDR Driver (CVE-2026-70585).CVE-2026-71329 and CVE-2026-68833), local privilege escalation in the Windows DHCP Client (CVE-2026-69777), a spoofing flaw in Azure Cosmos DB (CVE-2026-69857), and an elevation of privilege flaw in Spring Cloud Azure (CVE-2026-69854).CVE-2026-69414 warrants separate treatment because its remediation status is contested. Publicly tracked as ShieldBreak, the flaw affects Microsoft Defender and was reported in August 2026. Microsoft addressed it in Microsoft Malware Protection Engine version 1.1.26080.3, delivered through the automatic definition and engine update channel, requiring no customer action. On September 9, 2026, a proof-of-concept named ShieldCrash asserted that Microsoft failed to properly patch ShieldBreak — several changes were made to prevent re-exploitation, but one path was missed and the original condition can still be triggered under specific circumstances. The published proof-of-concept demonstrates arbitrary file read in the SYSTEM context, and all supported versions of the desktop operating system are reported to be impacted. Because the bypass is public and no vendor fix for it has been announced, the effective risk for this component should be treated as live rather than remediated.Recommendations
Conduct an extensive service exposure evaluation to identify any vulnerable services that may be publicly accessible. Take immediate and decisive action to address any identified vulnerabilities, either by installing essential patches or adopting security measures.
Keep your systems up to date by implementing the most recent security updates. To avoid the introduction of new vulnerabilities, follow security rules adapted to unique devices, and thoroughly review the configurations of devices and apps exposed to the internet.
Prioritize patching the actively exploited vulnerabilities CVE-2026-85880 and CVE-2026-81963. These vulnerabilities pose significant exploitation risks and should be addressed urgently.
Implement network segmentation to restrict unauthorized access and reduce the impact of potential attacks. This can be especially effective in scenarios where network adjacency is a factor.
Adhere to the idea of “least privilege” by giving users only the essential permissions they need for their tasks. This strategy reduces the effects of vulnerabilities related to privilege escalation.
Potential MITRE ATT&CK TTPs
References
- msrc.microsoft.com — September 2026 release notes
- msrc.microsoft.com — Vulnerability guide
- github.com — ShieldCrash proof-of-concept
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
