Jump to section
Back after a hiatus the Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority blog. Last time I did this was Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority. This time around, I am doing two things differently. I am ranking every priority against CISA BOD 26-04. Interested? Read on!
Microsoft Patch Tuesday September 2026: Numbers/Highlights

If you read five roundups this morning chances are you see a different number – 966, 973, 974, 995, 996. However, Microsoft says 974. Though others are all not wrong as they are counting different things.
This is my breakdown based on the official number:
| Patch Tuesday CVEs | Listed in CISA KEV | Critical | Patches Released Earlier |
|---|---|---|---|
| 974 | 2 | 105 | 204 |
I broke this count down based on it’s impact. This is the visualization:

Microsoft Patch Tuesday September 2026: Known Exploited Vulnerabilities
There are two publicly known exploited vulnerabilities that are a part of the Microsoft Patch Tuesday September 2026 release. They are already in the CISA KEV list. These are the details:
| Field | CVE-2026-81963 | CVE-2026-85880 |
|---|---|---|
| Component | Windows Update Stack | Windows Advanced Local Procedure Call (ALPC) |
| Type | Elevation of Privilege (local to SYSTEM) | Elevation of Privilege (local to SYSTEM) |
| CWE | CWE-59 Link Following; CWE-284 Improper Access Control | CWE-122 Heap-based Buffer Overflow; CWE-908 Use of Uninitialized Resource |
| CVSS 3.1 (MS) | High (see MSRC advisory) | 7.8 High · AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CISA-ADP SSVC | Exploitation: active | Exploitation: active · Automatable: no · Technical Impact: total |
| On CISA KEV | Yes, added 2026-09-08 | Yes, added 2026-09-08 |
| KEV due date | 2026-09-22 (14 days) | 2026-09-22 (14 days) |
| Forensic triage (BOD 26-04) | No | No |
| Affected (NVD) | Windows 11 23H2, 24H2, 25H2, 26H1; Windows Server 2025 (incl. Server Core) | Windows 10 1607, 1809, 21H2, 22H2; Windows Server 2012, 2012 R2, 2016 |
Both are Windows local elevation of privilege and allow a threat actor SYSTEM privileges once exploited. CISA added both to the KEV catalogue on the release date, 2026-09-08, and set the same remediation due date of 2026-09-22. What’s more interesting is BOD-26-04 mentions “no forensic triage”. To me, this translates to a privilege escalation vulnerability on an asset as is not a MS17-010. But! Patch we must! Prioritize your domain controllers, jump hosts, and the admin workstations inside three days regardless of what the tier label says, and assume the older Server 2012 and 2016 boxes exposed to the ALPC bug are the ones a threat actor reaches first.
Microsoft Patch Tuesday September 2026: Patching Priority
Continuing based on the BOD-26-04 guidelines, these CVEs will be my patching priority:
| CVE | Component/type | E | K | A | I | Priority | Detect on |
|---|---|---|---|---|---|---|---|
| CVE-2026-72981 | IP Helper RCE (Critical) | maybe | no | maybe | total | Tier 2-3 | Anomalous IP Helper service behavior; unexpected listeners/child procs |
| CVE-2026-65772 | Dynamics 365 on-prem · RCE (Critical) | yes | no | maybe | total | Tier 2-3 | Web app server spawning shells; unexpected w3wp child processes |
| CVE-2026-62813 / 69524 / 69546 | AD Domain Services RCE | int | no | maybe | total | Tier 2 on DCs | DC process anomalies; unusual LDAP/RPC-driven execution |
| CVE-2026-85877 | Print Spooler RCE | adj | no | maybe | total | Tier 3 | spoolsv.exe child processes; DLL writes to spool\drivers |
| CVE-2026-83997 | Message Queuing (MSMQ) RCE | if 1801 | no | maybe | total | Tier 2 if exposed | mqsvc.exe anomalies; inbound TCP/1801 to unexpected hosts |
| CVE-2026-73006 / 73016 | DirectWrite RCE (Critical) | client | no | no | total | Tier 3-4 | fontdrvhost.exe crashes; document/web-borne font parsing |
| CVE-2026-72986 / 73018 / 77493 / 81955 | Graphics/Fonts RCE (Critical) | client | no | no | total | Tier 3-4 | Renderer crashes on crafted images/fonts; preview-pane triggers |
| CVE-2026-81959 / 81953 / 81952 | Excel/Word RCE | client | no | no | total | Tier 3-4 | Office apps spawning cmd/powershell/wscript; MoTW bypass attempts |
| CVE-2026-83998 | Remote Desktop Client RCE | client | no | no | total | Tier 4 | mstsc.exe connecting to untrusted hosts; malicious-server pattern |
| CVE-2026-62916 | Entra ID EoP/identity boundary (Critical) | cloud | no | n/a | total | Verify config | Server-side fixed; audit Entra sign-in and role-assignment logs |
Here, environment = local, exposure depends on host; int = internal service; adj = adjacent/print path; client = requires user interaction. K is confirmed against CISA KEV as of 2026-09-08.
A and I are my class-based inferred values, pending CISA Vulnrichment additions.
Microsoft Patch Tuesday September 2026: Detection Engineering Candidates
- CVE-2026-81963 (CWE-59): The exploit primitive is a symbolic link that points a privileged function to a target it should not touch. Windows does not log symlink or junction creation by default, so you need Sysmon
Event ID 11based telemetry to catch a low-privilege process planting a link in a path the Update Stack later resolves. This can then be mapped to ATT&CK T1068. - CVE-2026-85880 (CWE-122, CWE-908): Memory corruption vulnerabilities like these are best detected using behavioural monitoring. For example, a process that has no business holding SYSTEM privileges, suddenly gaining them, an unexpected parent and child lineage. Similar vulnerability classes including UAC-bypasses, where local IPC, token duplication, and COM elevation can be tested using something like a Atomic Red Team.