Skip to content
Auto-CTI
Back to today
NEW HIGH B3

Microsoft Patch Tuesday for September 2026 , Snort rules and prominent vulnerabilities

B Cisco Talos Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Microsoft Patch Tuesday September 2026 directly affects company's Windows Server 2022/2019 and Microsoft product stack; 2 CVEs already exploited in the wild (CVE-2026-81963, CVE-2026-85880) require urgent assessment.

Description

Microsoft released 973 security updates in September 2026, including 113 marked as critical. Two vulnerabilities are already being actively exploited in the wild: CVE-2026-81963 (Windows Update Stack, privilege escalation, CVSS 7.8) and CVE-2026-85880 (Windows ALPC). Additionally, remote code execution flaws in Windows DNS Server are documented (CVE-2026-69858, CVE-2026-69827, both CVSS 8.1). Snort detection rules are available for these attack vectors.

Risk score

17
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC