On September 8, Microsoft released its September 2026 security updates. For enterprise IT teams, the most important question is not the headline number of fixes. It is whether actively exploited vulnerabilities are present in the environment—and whether updates have actually reached every affected device.
Start with the two vulnerabilities already exploited in the wild
Security vendors report slightly different total CVE counts because their counting methods differ. The priority signal is much clearer: Microsoft identifies two Windows elevation-of-privilege vulnerabilities as exploited in the wild.CVE-2026-81963: Windows Update Stack elevation of privilege
This link-following issue may allow an attacker who already has code execution on a device to elevate privileges to SYSTEM. Microsoft assigns a CVSS score of 7.8 and lists exploitation as detected.
CVE-2026-85880: Windows ALPC elevation of privilege
This vulnerability affects Windows Advanced Local Procedure Call. Successful exploitation may also provide SYSTEM-level privileges. It carries a CVSS score of 7.8 and has been observed in attacks.

Servers and core infrastructure need targeted review
The September release also includes high-impact issues affecting Windows DNS Server, Kerberos, Remote Desktop Services and on-premises Exchange Server.DNS and identity infrastructure
CVE-2026-69730 affects Windows DNS Server, has a CVSS score of 9.8 and is rated by Microsoft as exploitation more likely. Kerberos-related vulnerabilities should also be assessed against the organization’s domain architecture and exposure.Remote access services
Remote Desktop Services received fixes for multiple remote-code-execution issues. Internet-facing remote services should be checked first for version, exposure, access controls and successful patch installation.On-premises Exchange Server
Under specific conditions, CVE-2026-69380 may allow an authenticated low-privilege mailbox user to access other mailboxes and attachments, and to send or receive mail as another user.Hotpatch does not remove this month’s restart requirement
Microsoft’s September guidance says this month’s Windows security release is a baseline update, not a hotpatch update. Some security improvements affect components that cannot be replaced without restarting, so devices enrolled in Windows Hotpatch still need a restart to complete installation.“Deployed” is not the same as “effective.” IT teams should verify installation results, pending-restart status and failed devices—not only whether an update command was sent.
A practical enterprise patch plan for this week
- Complete an asset check. Confirm the versions and online status of Windows endpoints, servers, domain controllers, DNS servers, on-premises Exchange and remote-access systems.
- Create a representative pilot group. Validate drivers, VPN clients, printing, finance software and business-critical applications on a small set of devices first.
- Deploy in risk-based waves. Prioritize Windows devices affected by the exploited vulnerabilities, followed by internet-facing and identity-critical servers.
- Schedule maintenance and restarts. Notify employees and business owners before forced restarts interrupt meetings, open files or overnight workloads.
- Validate and track exceptions. Export compliance results, follow up on offline or failed devices, and document compensating controls for systems that must be deferred.
Three things employees need to do
- Do not install an “urgent patch” from an unfamiliar email link.
- Save work and restart promptly when the company announces a maintenance window.
- If a business application behaves abnormally after updating, record the time and error message and contact IT.
How Sinokap can help
Sinokap provides Microsoft 365, IT support, network and security, IT outsourcing, infrastructure and enterprise AI services. If your organization needs endpoint inventory, patch deployment, Microsoft environment maintenance or security-baseline reviews, contact Sinokap to discuss a practical approach.
Sources and further reading
- Microsoft Security Update Guide
- Microsoft Windows 11 Hotpatch baseline for September 8, 2026
- Microsoft Windows client images for September 2026
- Tenable Research: Microsoft September 2026 Patch Tuesday analysis
This article reflects information available on September 9, 2026. Total vulnerability counts may differ between sources because of counting methodology.

