Microsoft's September 2026 security update revealed 973 vulnerabilities, with 113 classified as critical. Two actively exploited vulnerabilities are CVE-2026-81963 (Windows Update Stack, elevation of privilege, CVSS 7.8) and CVE-2026-85880 (Windows ALPC, elevation of privilege, CVSS 7.8). Among the 113 critical vulnerabilities, 82 are remote code execution (RCE) vulnerabilities. Notable vulnerabilities include:
- CVE-2026-69676: RCE in Windows Kerberos, CVSS 8.8, authentication bypass.
- CVE-2026-69852: RCE in Windows RRAS, CVSS 7.5, heap-based buffer overflow.
- CVE-2026-72957: RCE in Windows Deployment Services, CVSS 7.8.
- CVE-2026-69854: Elevation of privilege in Spring Cloud Azure, CVSS 9.0, improper authentication.
- CVE-2026-83501: Information disclosure in Windows VBS, CVSS 5.5.
- CVE-2026-69730: RCE in Windows DNS Server, CVSS 9.8.
Less likely to be exploited vulnerabilities include:
- CVE-2026-69845: RCE in Windows DHCP Server, CVSS 9.8, heap-based buffer overflow.
- CVE-2026-65772: Vulnerability in Microsoft Dynamics 365 On-Premises, CVSS 8.8, deserialization of untrusted data.
- CVE-2026-66302: RCE in Skype for Business, CVSS 9.8.
Additional critical vulnerabilities include:
- CVE-2026-62916: Elevation of privilege in Microsoft Entra ID, CVSS 9.1.
- CVE-2026-83941: Elevation of privilege in Entra ID, CVSS 9.9.
- CVE-2026-80098: Vulnerability in Copilot Studio, CVSS 9.3, improper verification of cryptographic signatures.
Talos is releasing a new Snort ruleset to detect attempts to exploit these vulnerabilities, with specific SIDs for Snort 2 and Snort 3 rule coverage.