Microsoft Addresses 973 Vulnerabilities in September Patch Tuesday Update
Microsoft's September 2026 Patch Tuesday update has been released, addressing 973 vulnerabilities across various products. Among them, 113 are marked as 'critical.' Two of these vulnerabilities have been exploited in the wild, including CVE-2026-81963, which affects the Windows Update Stack and has a CVSS base score of 7.8. The other is CVE-2026-85880, affecting the Windows Advanced Local Procedure Call (ALPC) with a similar CVSS base score.
Out of the 113 critical vulnerabilities, 82 are remote code execution (RCE) vulnerabilities. Microsoft considers exploitation of CVE-2026-69676, which affects Windows Kerberos and has a CVSS base score of 8.8, more likely than others. This vulnerability is associated with Authentication Bypass by Capture-replay.
The update also includes fixes for several other critical and high-risk vulnerabilities. Microsoft advises users to apply the necessary patches as soon as possible to prevent potential exploitation.