Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Brief
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.
- CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). CVE-2026-85880 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.
- Out of 113 "critical" vulnerabilities, 82 are remote code execution (RCE) vulnerabilities.
