← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 22:16via Cisco Talos

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Brief

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."

Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:

CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.

  • CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). CVE-2026-85880 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.
  • Out of 113 "critical" vulnerabilities, 82 are remote code execution (RCE) vulnerabilities.
Read more on Cisco Talos