Microsoft’s latest security update for September 2026 has unveiled a staggering 973 vulnerabilities across various products, with 113 classified as “critical.” Among these vulnerabilities, two have already been identified as actively exploited in the wild. The first, CVE-2026-81963, pertains to the Windows Update Stack and is characterized as an elevation of privilege vulnerability linked to improper link resolution before file access, boasting a CVSS base score of 7.8. The second, CVE-2026-85880, affects the Windows Advanced Local Procedure Call (ALPC) and is also an elevation of privilege vulnerability, associated with heap-based buffer overflow, carrying the same CVSS score of 7.8.
Critical Vulnerabilities and Their Implications
Out of the 113 critical vulnerabilities, a notable 82 are categorized as remote code execution (RCE) vulnerabilities. Microsoft has highlighted several vulnerabilities that it considers more likely to be exploited:
- CVE-2026-69676: A remote code execution vulnerability affecting Windows Kerberos, with a CVSS score of 8.8, linked to authentication bypass by capture-replay.
- CVE-2026-69852: This vulnerability affects Windows Routing and Remote Access Service (RRAS) and is associated with heap-based buffer overflow, scoring 7.5 on the CVSS scale.
- CVE-2026-72957: Another remote code execution vulnerability impacting Windows Deployment Services, with a CVSS score of 7.8.
- CVE-2026-69854: This elevation of privilege vulnerability in Spring Cloud Azure has a CVSS score of 9.0, linked to improper authentication.
- CVE-2026-83501: An information disclosure vulnerability affecting Windows Virtualization-Based Security (VBS), scoring 5.5.
- CVE-2026-69730: A critical remote code execution vulnerability in Windows DNS Server with a CVSS score of 9.8.
In contrast, Microsoft has identified certain vulnerabilities as less likely to be exploited, including:
- CVE-2026-69845: A remote code execution vulnerability in Windows DHCP Server, with a CVSS score of 9.8, associated with heap-based buffer overflow.
- CVE-2026-65772: This vulnerability affects Microsoft Dynamics 365 On-Premises and has a CVSS score of 8.8, linked to deserialization of untrusted data.
- CVE-2026-66302: A remote code execution vulnerability in Skype for Business, also scoring 9.8.
Additional Insights and Recommendations
Microsoft has also disclosed several other critical vulnerabilities, including:
- CVE-2026-62916: An elevation of privilege vulnerability in Microsoft Entra ID, with a CVSS score of 9.1.
- CVE-2026-83941: Another elevation of privilege vulnerability in Entra ID, scoring 9.9.
- CVE-2026-80098: This vulnerability affects Copilot Studio and has a CVSS score of 9.3, linked to improper verification of cryptographic signatures.
In response to these vulnerabilities, Talos is rolling out a new Snort ruleset designed to detect attempts to exploit some of the disclosed vulnerabilities. Users of Cisco Secure Firewall are encouraged to update their ruleset, while open-source Snort Subscriber Ruleset customers can access the latest rule pack available for purchase on Snort.org. The Snort 2 rule coverage includes SIDs 67011-67032 and 67036-67084, while Snort 3 rule coverage encompasses SIDs 301619-301629, 301632-301655, and 67046.