Microsoft Patch Tuesday for September 2026 , Snort rules and prominent vulnerabilities
Strategic summary
Microsoft's September 2026 Patch Tuesday includes 973 vulnerabilities, 113 of which are critical, including 82 remote code execution flaws. Two vulnerabilities are already exploited in the wild: CVE-2026-81963 and CVE-2026-85880, both with CVSS 7.8. For Joel Traber AG in the manufacturing sector and DACH region, timely prioritization and patching are strongly recommended.
Key findings
- 973 total vulnerabilities, 113 critical, 82 remote code execution.
- Two exploited in the wild: CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC), both CVSS 7.8.
- CVE-2026-69854 in Spring Cloud Azure has the highest CVSS 9.0 among the likely exploited vulnerabilities.
- Other likely exploited vulnerabilities affect Windows Kerberos (CVE-2026-69676), Azure Cosmos DB (CVE-2026-69857), and Windows RRAS (CVE-2026-69852).
Relevance for you
Microsoft Patch Tuesday September 2026 directly affects company's Windows Server 2022/2019 and Microsoft product stack; 2 CVEs already exploited in the wild (CVE-2026-81963, CVE-2026-85880) require urgent assessment.
Full text
[Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabi]
- Security Resources - [x]
Tuesday, September 8, 2026 18:16
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
**Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:**
_CVE-2026-81963_ affects Windows Update Stack. _CVE-2026-81963_ is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.
_CVE-2026-85880_ affects Windows Advanced Local Procedure Call (ALPC). _CVE-2026-85880_ is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.8.
Out of 113 "critical" vulnerabilities, 82 are remote code execution (RCE) vulnerabilities.
**Microsoft considers exploitation of the following vulnerabilities more likely:**
_CVE-2026-69676_ affects Windows Kerberos. _CVE-2026-69676_ is a remote code execution vulnerability associated with Authentication Bypass by Capture-replay and has a CVSS base score of 8.8.
_CVE-2026-69852_ affects Windows Routing and Remote Access Service (RRAS). _CVE-2026-69852_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.
_CVE-2026-72957_ affects Windows Deployment Services. _CVE-2026-72957_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8.
_CVE-2026-69854_ affects Spring Cloud Azure. _CVE-2026-69854_ is a elevation of privilege vulnerability associated with Improper Authentication and has a CVSS base score of 9.0.
_CVE-2026-83501_ affects Windows Virtualization-Based Security (VBS). _CVE-2026-83501_ is a information disclosure vulnerability associated with Out-of-bounds Read and has a CVSS base score of 5.5.
_CVE-2026-70585_ affects Windows Services for NFS ONCRPC XDR Driver. _CVE-2026-70585_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 7.0.
_CVE-2026-69857_ affects Azure Cosmos DB. _CVE-2026-69857_ is a spoofing vulnerability associated with Authorization Bypass Through User-Controlled Key and has a CVSS base score of 8.5.
**Microsoft considers exploitation of the following vulnerabilities less likely:**
_CVE-2026-69845_ and _CVE-2026-72979_ affect Windows DHCP Server. _CVE-2026-69845_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Improper Input Validation and has a CVSS base score of 9.8. _CVE-2026-72979_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.
_CVE-2026-58599_ affects HEVC Video Extensions. _CVE-2026-58599_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8.
_CVE-2026-65772_ affects Microsoft Dynamics 365 On-Premises. _CVE-2026-65772_ is a remote code execution vulnerability associated with Deserialization of Untrusted Data and has a CVSS base score of 8.8.
_CVE-2026-66302_ affects Skype for Business. _CVE-2026-66302_ is a remote code execution vulnerability associated with External Control of File Name or Path and has a CVSS base score of 9.8.
_CVE-2026-69590_ and _CVE-2026-72959_ affect Windows Routing and Remote Access Service (RRAS). _CVE-2026-69590_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8. _CVE-2026-72959_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-69601_ affects Microsoft Windows Media Foundation. _CVE-2026-69601_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-73009_ affects Windows Secure Socket Tunneling Protocol (SSTP). _CVE-2026-73009_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.
_CVE-2026-73017_ affects Graphics Kernel. _CVE-2026-73017_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.
_CVE-2026-83498_ affects Windows Virtualization-Based Security (VBS) Enclave. _CVE-2026-83498_ is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 7.8.
_CVE-2026-73018_ and _CVE-2026-72986_ affect Graphic Fonts. _CVE-2026-73018_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8. _CVE-2026-72986_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Integer Overflow or Wraparound and has a CVSS base score of 8.8.
_CVE-2026-70203_ affects Windows Media Player. _CVE-2026-70203_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-78439_ affects Microsoft Office Graphics Component. _CVE-2026-78439_ is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-81355_ affects Virtual Hard Disk (VHD) Miniport Driver. _CVE-2026-81355_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.
_CVE-2026-69649_ affects Raw Image Extension. _CVE-2026-69649_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-72983_ affects Internet Connection Sharing (ICS). _CVE-2026-72983_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.
_CVE-2026-69518_ affects Windows Remote Desktop. _CVE-2026-69518_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-69712_ affects Windows Key Distribution Center. _CVE-2026-69712_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.8.
**Microsoft considers exploitation of the following vulnerabilities unlikely:**
_CVE-2026-69769_ affects Windows HTTP Print Provider. _CVE-2026-69769_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 9.8.
_CVE-2026-69860_ affects Windows Imaging Component. _CVE-2026-69860_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-69874_ affects Windows ALPC. _CVE-2026-69874_ is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.2.
_CVE-2026-69890_ affects Windows Virtual Trusted Platform Module. _CVE-2026-69890_ is a elevation of privilege vulnerability associated with Use After Free and has a CVSS base score of 7.5.
_CVE-2026-72950_ affects Windows Routing and Remote Access Service (RRAS). _CVE-2026-72950_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-72954_ affects Windows Deployment Services. _CVE-2026-72954_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 7.5.
_CVE-2026-72960_ affects Windows Media Player. _CVE-2026-72960_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-72962_ affects Windows USB Video Driver. _CVE-2026-72962_ is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2.
_CVE-2026-72982_ affects Windows Netlogon. _CVE-2026-72982_ is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 9.8.
_CVE-2026-81949_ affects Microsoft Excel. _CVE-2026-81949_ is a remote code execution vulnerability associated with Integer Overflow or Wraparound and has a CVSS base score of 7.8.
_CVE-2026-81352_ affects Web Media Extensions. _CVE-2026-81352_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-81955_ affects Windows Graphics Component. _CVE-2026-81955_ is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
_CVE-2026-69858_ and _CVE-2026-69827_ affect Windows DNS Server. _CVE-2026-69858_ is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1. _CVE-2026-69827_ is a remote code execution vulnerability associated with Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and has a CVSS base score of 8.1.
_CVE-2026-70351_ affects Microsoft WebP Image Extension. _CVE-2026-70351_ is a remote code execution vulnerability associated with Integer Overflow or Wraparound and Heap-based Buffer Overflow and has a CVSS base score of 8.8.
**Other critical vulnerabilities:**
_CVE-2026-62916_ affects Microsoft Entra ID. _CVE-2026-62916_ is a elevation of privilege vulnerability associated with Authentication Bypass Using an Alternate Path or Channel and has a CVSS base score of 9.1.
_CVE-2026-65818_ affects Power Automate. _CVE-2026-65818_ is a elevation of privilege vulnerability associated with Server-Side Request Forgery (SSRF) and has a CVSS base score of 8.5.
_CVE-2026-80098_ affects Copilot Studio. _CVE-2026-80098_ is a elevation of privilege vulnerability associated with Improper Verification of Cryptographic Signature and has a CVSS base score of 9.3.
_CVE-2026-83711_ affects Microsoft Azure Active Directory B2C. _CVE-2026-83711_ is a elevation of privilege vulnerability associated with Authorization Bypass Through User-Controlled Key and has a CVSS base score of 10.0.
_CVE-2026-70352_ affects Azure AI Language. _CVE-2026-70352_ is a elevation of privilege vulnerability associated with Missing Authentication for Critical Function and has a CVSS base score of 10.0.
_CVE-2026-62906_ affects Microsoft Discovery Studio. _CVE-2026-62906_ is a information disclosure vulnerability associated with Improper Neutralization of Special Elements in Data Query Logic and has a CVSS base score of 7.4.
**Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"**
_CVE-2026-68876_: Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
_CVE-2026-69277_: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
_CVE-2026-69305_: Microsoft Windows Search Component Elevation of Privilege Vulnerability
_CVE-2026-69391_: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
_CVE-2026-69451_: Windows Management Instrumentation Elevation of Privilege Vulnerability
_CVE-2026-69459_: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
_CVE-2026-69478_: Windows Device Association Service Elevation of Privilege Vulnerability
_CVE-2026-69541_: Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
_CVE-2026-69585_: Microsoft Windows Search Component Elevation of Privilege Vulnerability
_CVE-2026-69600_: Microsoft Windows Search Component Elevation of Privilege Vulnerability
_CVE-2026-69714_: Windows Device Association Service Elevation of Privilege Vulnerability
_CVE-2026-69911_: Microsoft Windows Search Component Elevation of Privilege Vulnerability
_CVE-2026-70342_: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
_CVE-2026-77500_: Windows Device Association Service Elevation of Privilege Vulnerability
_CVE-2026-69460_: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
_CVE-2026-80093_: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
_CVE-2026-71343_: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its _update page_.
In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on _Snort.org_.
Snort 2 rule coverage: SIDs 67011-67032 and 67036-67084.
Snort 3 rule coverage: SIDs 301619-301629, 301632-301655, and 67046.
- * ###### Security Resources
- * ###### Media
- * ###### Support
- * ###### Company
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 15.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -3.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_SKIPPEDTTP mapping skipped (placeholder or aggregation article) −3
- Consensus penalty:
- −3.0
- Total penalty:
- −3.0