Site icon Sinokap

Microsoft September 2026 Security Update: Two Exploited Zero-Days Require Immediate Enterprise Action

Microsoft September 2026 security update

Microsoft September 2026 security update

On September 8, Microsoft released its September 2026 security updates. For enterprise IT teams, the most important question is not the headline number of fixes. It is whether actively exploited vulnerabilities are present in the environment—and whether updates have actually reached every affected device.

Executive priority: Patch the two exploited Windows elevation-of-privilege vulnerabilities first, then verify high-risk servers, restart completion and deployment exceptions.

Start with the two vulnerabilities already exploited in the wild

Security vendors report slightly different total CVE counts because their counting methods differ. The priority signal is much clearer: Microsoft identifies two Windows elevation-of-privilege vulnerabilities as exploited in the wild.

CVE-2026-81963: Windows Update Stack elevation of privilege

This link-following issue may allow an attacker who already has code execution on a device to elevate privileges to SYSTEM. Microsoft assigns a CVSS score of 7.8 and lists exploitation as detected.

CVE-2026-85880: Windows ALPC elevation of privilege

This vulnerability affects Windows Advanced Local Procedure Call. Successful exploitation may also provide SYSTEM-level privileges. It carries a CVSS score of 7.8 and has been observed in attacks.

Windows endpoint protected against exploited zero-day vulnerabilities in an enterprise environment
Concept illustration of exploited Windows vulnerabilities and endpoint protection; not an official Microsoft screenshot.

Servers and core infrastructure need targeted review

The September release also includes high-impact issues affecting Windows DNS Server, Kerberos, Remote Desktop Services and on-premises Exchange Server.

DNS and identity infrastructure

CVE-2026-69730 affects Windows DNS Server, has a CVSS score of 9.8 and is rated by Microsoft as exploitation more likely. Kerberos-related vulnerabilities should also be assessed against the organization’s domain architecture and exposure.

Remote access services

Remote Desktop Services received fixes for multiple remote-code-execution issues. Internet-facing remote services should be checked first for version, exposure, access controls and successful patch installation.

On-premises Exchange Server

Under specific conditions, CVE-2026-69380 may allow an authenticated low-privilege mailbox user to access other mailboxes and attachments, and to send or receive mail as another user.

Hotpatch does not remove this month’s restart requirement

Microsoft’s September guidance says this month’s Windows security release is a baseline update, not a hotpatch update. Some security improvements affect components that cannot be replaced without restarting, so devices enrolled in Windows Hotpatch still need a restart to complete installation.
“Deployed” is not the same as “effective.” IT teams should verify installation results, pending-restart status and failed devices—not only whether an update command was sent.

A practical enterprise patch plan for this week

Concept illustration of pilot validation and staged enterprise patch deployment; not an official Microsoft screenshot.
  1. Complete an asset check. Confirm the versions and online status of Windows endpoints, servers, domain controllers, DNS servers, on-premises Exchange and remote-access systems.
  2. Create a representative pilot group. Validate drivers, VPN clients, printing, finance software and business-critical applications on a small set of devices first.
  3. Deploy in risk-based waves. Prioritize Windows devices affected by the exploited vulnerabilities, followed by internet-facing and identity-critical servers.
  4. Schedule maintenance and restarts. Notify employees and business owners before forced restarts interrupt meetings, open files or overnight workloads.
  5. Validate and track exceptions. Export compliance results, follow up on offline or failed devices, and document compensating controls for systems that must be deferred.
Why this matters: Enterprise security updates are not a single click. The full process is asset identification, risk prioritization, pilot validation, staged deployment, restart completion and exception follow-up. Speed matters when exploitation is already occurring. A deployment must also be controlled, traceable and verifiable. A stable patch cadence reduces emergency firefighting whenever a serious vulnerability appears.

Three things employees need to do

  • Do not install an “urgent patch” from an unfamiliar email link.
  • Save work and restart promptly when the company announces a maintenance window.
  • If a business application behaves abnormally after updating, record the time and error message and contact IT.

How Sinokap can help

Sinokap provides Microsoft 365, IT support, network and security, IT outsourcing, infrastructure and enterprise AI services. If your organization needs endpoint inventory, patch deployment, Microsoft environment maintenance or security-baseline reviews, contact Sinokap to discuss a practical approach.

Sources and further reading

This article reflects information available on September 9, 2026. Total vulnerability counts may differ between sources because of counting methodology.

Exit mobile version