Microsoft Fixes More Than 100 Critical Vulnerabilities in September Patch Tuesday

Microsoft's latest update fixes hundreds of security issues, but several high-severity flaws affecting Exchange and other products are likely to draw the most attention from security teams.

Windows update hero image

Key Takeaways:

  • Microsoft addressed 974 vulnerabilities in its September 2026 Patch Tuesday release.
  • The update includes fixes for 114 Critical vulnerabilities across Windows and Microsoft enterprise products.
  • High-severity flaws affecting Exchange Server, SharePoint, SQL Server, and Remote Desktop Services are among the most notable fixes.

Microsoft has released the September 2026 Patch Tuesday Updates for all supported versions of Windows 11 and Windows 10. This month, the company rolled out 974 patches to address several vulnerabilities in Windows, Office, Azure, Active Directory, Exchange Server, Remote Desktop Client and Server, SQL Server, Windows Hello, Microsoft Defender, and other components.

Microsoft has already fixed 2,760 vulnerabilities this year, which is more than double the number from 2025. On the quality and experience update front, Microsoft has released several improvements for Windows 11 versions 26H1 as well as 25H2 and 24H2.

974 vulnerabilities fixed in the September 2026 Patch Tuesday updates

According to the Zero Day Initiative, Microsoft has fixed 114 security flaws rated as “Critical,” with the rest being rated Important in terms of severity. Here’s a list of the most notable vulnerabilities Microsoft addressed in September:

  • CVE-2026-85880: This is an elevation of privilege bug in Windows Advanced Local Procedure Call (ALPC). This security vulnerability could be exploited by attackers to gain SYSTEM privileges.
  • CVE-2026-81963: This is a privilege escalation vulnerability in the Windows Update Stack with a CVSS score of 7.8. Microsoft has warned that this flaw could allow attackers to gain SYSTEM-level access.
  • CVE-2026-55007: This is one of the nine Exchange Server vulnerabilities disclosed this month. An unauthenticated attacker could achieve remote code execution on an affected Exchange Server by sending an email with a malicious Visio attachment.
  • CVE-2026-69465: This is an authorization vulnerability in Microsoft SharePoint that carries a CVSS score of 8.8. Cybercriminals could exploit this flaw to execute code over an enterprise network.
  • CVE-2026-65669: This is a 9.6-rated injection vulnerability in SQL Server that allows an unauthorized attacker to elevate privileges over a network. It could be exploited by hackers when a user submits instructions through SQL Copilot.
  • CVE-2026-69525: This remote execution bug in Remote Desktop Services carries a CVSS score of 9.8.

You can find the full list of CVEs addressed in the September 2026 Patch Tuesday Updates below:

Product FamilyUpdates per Product/VersionVulnerabilities AddressedDistinct UpdatesType of Update
Azure12915Individual
Defender121Cumulative
Developer Tools12736Cumulative
Edge1161Cumulative
Exchange Server184Cumulative
Office19911Cumulative (except 2016)
Office 201619918Individual
Other194Individual
SharePoint Server1303Cumulative
Windows124032Cumulative

Quality and experience updates

Microsoft released the KB5124008 update for PCs running Windows 11 versions 26H1 and 25H2/24H2. This release brings additionalhigh-confidencee device targeting data, which increases coverage of devices eligible to automatically receive new Secure Boot certificates. Microsoft will continue certificate deployment through Windows updates across supported PCs and non-managed business devices in the next few months.

The KB5124008 update enhances the diagnostics logging experience for the OMA-DM client. It provides additional information to help troubleshoot device management server connection issues. Microsoft has also fixed a bug that could cause Microsoft Outlook and Teams to unexpectedly close on Arm64-based PCs.

Windows Update testing and best practices

Microsoft advises organizations to perform thorough testing to confirm that updates do not compromise the stability of their production systems. However, it is crucial to deploy Patch Tuesday updates to proactively address potential threats.

Additionally, IT administrators must prioritize backing up their systems before applying updates, utilizing the built-in backup features of Windows and Windows Server. These features allow for the restoration of specific files and folders or entire systems as required.

Last but not least, organizations should consistently monitor their systems for anomalies or unexpected behaviors. Regular monitoring is essential for staying vigilant against emerging risks and adopting appropriate security measures.