• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • About Me
  • Privacy Policy
  • Media Mentions

PenTestIT.com

Your source for Detection Engineering, Security Research and Adversary Simulation

  • Search Engine Dorks
  • RSS feed
You are here: Home / Cyber Threat Intelligence / Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Posted: Sep 9, 2026 by Mayuresh @pentestit 4 min read
Updated: Sep 12, 2026

Jump to section
  1. Microsoft Patch Tuesday September 2026: Numbers/Highlights
  2. Microsoft Patch Tuesday September 2026: Known Exploited Vulnerabilities
  3. Microsoft Patch Tuesday September 2026: Patching Priority
  4. Microsoft Patch Tuesday September 2026: Detection Engineering Candidates

Back after a hiatus the Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority blog. Last time I did this was Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority. This time around, I am doing two things differently. I am ranking every priority against CISA BOD 26-04. Interested? Read on!

Microsoft Patch Tuesday September 2026: Numbers/Highlights

Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority
Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

If you read five roundups this morning chances are you see a different number – 966, 973, 974, 995, 996. However, Microsoft says 974. Though others are all not wrong as they are counting different things.

This is my breakdown based on the official number:

Patch Tuesday CVEsListed in CISA KEVCriticalPatches Released Earlier
9742105204

I broke this count down based on it’s impact. This is the visualization:

Microsoft Patch Tuesday September 2026: Vulnerabilities by impact type
Microsoft Patch Tuesday September 2026: Vulnerabilities by impact type

Microsoft Patch Tuesday September 2026: Known Exploited Vulnerabilities

There are two publicly known exploited vulnerabilities that are a part of the Microsoft Patch Tuesday September 2026 release. They are already in the CISA KEV list. These are the details:

FieldCVE-2026-81963CVE-2026-85880
ComponentWindows Update StackWindows Advanced Local Procedure Call (ALPC)
TypeElevation of Privilege (local to SYSTEM)Elevation of Privilege (local to SYSTEM)
CWECWE-59 Link Following; CWE-284 Improper Access ControlCWE-122 Heap-based Buffer Overflow; CWE-908 Use of Uninitialized Resource
CVSS 3.1 (MS)High (see MSRC advisory)7.8 High · AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADP SSVCExploitation: activeExploitation: active · Automatable: no · Technical Impact: total
On CISA KEVYes, added 2026-09-08Yes, added 2026-09-08
KEV due date2026-09-22 (14 days)2026-09-22 (14 days)
Forensic triage (BOD 26-04)NoNo
Affected (NVD)Windows 11 23H2, 24H2, 25H2, 26H1; Windows Server 2025 (incl. Server Core)Windows 10 1607, 1809, 21H2, 22H2; Windows Server 2012, 2012 R2, 2016

Both are Windows local elevation of privilege and allow a threat actor SYSTEM privileges once exploited. CISA added both to the KEV catalogue on the release date, 2026-09-08, and set the same remediation due date of 2026-09-22. What’s more interesting is BOD-26-04 mentions “no forensic triage”. To me, this translates to a privilege escalation vulnerability on an asset as is not a MS17-010. But! Patch we must! Prioritize your domain controllers, jump hosts, and the admin workstations inside three days regardless of what the tier label says, and assume the older Server 2012 and 2016 boxes exposed to the ALPC bug are the ones a threat actor reaches first.

Microsoft Patch Tuesday September 2026: Patching Priority

Continuing based on the BOD-26-04 guidelines, these CVEs will be my patching priority:

CVEComponent/typeEKAIPriorityDetect on
CVE-2026-72981IP Helper RCE (Critical)maybenomaybetotalTier 2-3Anomalous IP Helper service behavior; unexpected listeners/child procs
CVE-2026-65772Dynamics 365 on-prem · RCE (Critical)yesnomaybetotalTier 2-3Web app server spawning shells; unexpected w3wp child processes
CVE-2026-62813 / 69524 / 69546AD Domain Services RCEintnomaybetotalTier 2 on DCsDC process anomalies; unusual LDAP/RPC-driven execution
CVE-2026-85877Print Spooler RCEadjnomaybetotalTier 3spoolsv.exe child processes; DLL writes to spool\drivers
CVE-2026-83997Message Queuing (MSMQ) RCEif 1801nomaybetotalTier 2 if exposedmqsvc.exe anomalies; inbound TCP/1801 to unexpected hosts
CVE-2026-73006 / 73016DirectWrite RCE (Critical)clientnonototalTier 3-4fontdrvhost.exe crashes; document/web-borne font parsing
CVE-2026-72986 / 73018 / 77493 / 81955Graphics/Fonts RCE (Critical)clientnonototalTier 3-4Renderer crashes on crafted images/fonts; preview-pane triggers
CVE-2026-81959 / 81953 / 81952Excel/Word RCEclientnonototalTier 3-4Office apps spawning cmd/powershell/wscript; MoTW bypass attempts
CVE-2026-83998Remote Desktop Client RCEclientnonototalTier 4mstsc.exe connecting to untrusted hosts; malicious-server pattern
CVE-2026-62916Entra ID EoP/identity boundary (Critical)cloudnon/atotalVerify configServer-side fixed; audit Entra sign-in and role-assignment logs

Here, environment = local, exposure depends on host; int = internal service; adj = adjacent/print path; client = requires user interaction. K is confirmed against CISA KEV as of 2026-09-08.

A and I are my class-based inferred values, pending CISA Vulnrichment additions.

Microsoft Patch Tuesday September 2026: Detection Engineering Candidates

  1. CVE-2026-81963 (CWE-59): The exploit primitive is a symbolic link that points a privileged function to a target it should not touch. Windows does not log symlink or junction creation by default, so you need Sysmon Event ID 11 based telemetry to catch a low-privilege process planting a link in a path the Update Stack later resolves. This can then be mapped to ATT&CK T1068.
  2. CVE-2026-85880 (CWE-122, CWE-908): Memory corruption vulnerabilities like these are best detected using behavioural monitoring. For example, a process that has no business holding SYSTEM privileges, suddenly gaining them, an unexpected parent and child lineage. Similar vulnerability classes including UAC-bypasses, where local IPC, token duplication, and COM elevation can be tested using something like a Atomic Red Team.

Share this post on:
Twitter Facebook LinkedIn Reddit Hacker News WhatsApp
← Previous PostClaude Skill: cve-checkNext Post →Claude Skill: threat-report-killchain

Part 2 of 2 in the series: Microsoft Patch Tuesday

  1. 1. Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority
  2. 2. Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Related Posts

  • Vulnerability Management

    Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority

    This blog is my interpretation of the Microsoft Patch Tuesday March 2026 Exploitability and Patching Priority.

    4 min · Mar 11, 2026
  • Detection Engineering

    “Severity” or “Expected Severity” for Prioritization?

    In one of my last post - Prioritizing a Threat Detection Backlog , I talked about prioritizing your threat detection backlog. It is true…

    5 min · Apr 26, 2026
  • Detection Engineering

    Essential Detection Engineering Metrics

    You have prioritized your threat detection backlog , but now want to quantify the progress. Throughout my career leading multiple threat detection engineering teams,…

    7 min · Sep 1, 2026

Filed UnderCyber Threat Intelligence Vulnerability Management Tagged WithMicrosoft Patch Tuesday

About Mayuresh

Seasoned cybersecurity pioneer with over 15 years building and mentoring elite security research teams. I help drive world-class vulnerability detection and remediation initiatives, delivering patented innovations. A purple-teamer by choice, I transform threat intelligence into actionable protection engineering strategies, actively contributing to the MITRE ATT&CK framework and collaborating with industry evaluators. Passionate about strengthening enterprise cyber resilience, I unite global stakeholders to proactively reduce risk and outpace adversaries in dynamic threat landscapes.

Primary Sidebar

Add PenTestIT as a preferred source on Google

Categories

  • Adversary Emulation
  • Cyber Threat Intelligence
  • Detection Engineering
  • Offensive Security
  • Open Source
  • Penetration Testing
  • Tools
  • Vulnerability Management
  • Vulnerability Research
  • Web Application Security

Archives

  • September 2026
  • April 2026
  • March 2026
  • February 2026
  • August 2022
  • July 2020

Copyright © 2026 - PenTestIT.com | Information shared to be used for LEGAL purposes only!

(opens in a new tab)